A vulnerability classified as problematic was found in microsoft kiota-typescript up to 1.0.0-prev. Affected is an unknown function of the component Request Header Handler. Such manipulation leads to improper handling of case sensitivity.
This vulnerability is referenced as CVE-2026-49336. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in wpgmaps WP Go Maps Plugin up to 10.1.01 on WordPress. This impacts the function CRUD-backed of the component Database Table Handler. This manipulation of the argument phpClass causes missing authorization.
The identification of this vulnerability is CVE-2026-12238. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in urllib3 Brotli up to 2.6.x. Affected by this vulnerability is the function read of the file response.py of the component HTTP Handler. Performing a manipulation results in resource consumption.
This vulnerability is identified as CVE-2026-9375. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Red Hat Ansible Automation Platform 2. It has been classified as critical. This issue affects some unknown processing of the component Trusted GitHub API Endpoint. This manipulation of the argument pull_request.statuses_url causes server-side request forgery.
This vulnerability is registered as CVE-2026-12726. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability, which was classified as critical, was found in sentriz gonic up to 0.20.x. Affected by this issue is some unknown functionality. Executing a manipulation of the argument ID can lead to path traversal.
This vulnerability is tracked as CVE-2026-49339. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in sentriz gonic up to 0.20.x and classified as critical. This vulnerability affects unknown code of the file /rest/deletePlaylist.view of the component Subsonic API. The manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-49338. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability identified as problematic has been detected in Grafana Enterprise Traces and Tempo. This affects an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-27878. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in sentriz gonic up to 0.20.x. This impacts an unknown function. The manipulation results in path traversal.
This vulnerability is known as CVE-2026-49340. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability classified as critical has been found in lsegal yard up to 0.9.43. Affected by this issue is some unknown functionality of the file yard-cache-secret.html. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-49342. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in sourcentis mercator up to 2025.05.18. It has been classified as problematic. The impacted element is the function QueryController::execute of the file /admin/queries/execute. Performing a manipulation of the argument hidden results in exposure of private personal information to an unauthorized actor.
This vulnerability is cataloged as CVE-2026-49344. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in sourcentis mercator up to 2025.05.18. It has been declared as critical. This affects the function testProvider of the file /admin/config/parameters. Executing a manipulation can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-49345. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in moby buildkit up to 0.28.0. This vulnerability affects unknown code of the component Image Parser. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-33747. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
A vulnerability marked as problematic has been reported in OpenSSL up to 3.6.1. Affected by this vulnerability is the function CMS_decrypt of the component CMS KeyTransportRecipientInfo Handler. Performing a manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-28390. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in GNU C Library up to up to 2.43. It has been declared as problematic. This impacts the function iconv. Executing a manipulation can lead to reachable assertion.
This vulnerability is registered as CVE-2026-4046. It is possible to launch the attack remotely. No exploit is available.
A vulnerability labeled as problematic has been found in OpenSSL up to 3.6.1. Affected is the function CMS_decrypt of the component CMS EnvelopedData Message Handler. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2026-28389. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability was found in OpenSSL up to 3.0.19/3.3.6/3.4.4/3.5.5/3.6.1. It has been declared as problematic. The affected element is the function RSA_public_encrypt of the component RSA KEM RSASVE Encapsulation. Executing a manipulation can lead to uninitialized pointer.
This vulnerability is registered as CVE-2026-31790. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in OpenSSL up to 3.0.19/3.3.6/3.4.4/3.5.5/3.6.1. Affected by this issue is some unknown functionality of the component Hexadecimal Conversion Handler. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is handled as CVE-2026-31789. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in OpenSSL up to 3.6.1 on x86-64. It has been rated as problematic. The impacted element is an unknown function of the component AES-CFB-128 Handler. The manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-28386. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in OpenSSL up to 3.6.1. This affects an unknown function of the component DANE Client Code. The manipulation results in use after free.
This vulnerability is reported as CVE-2026-28387. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.