A vulnerability, which was classified as critical, was found in BerriAI LiteLLM up to 1.83.6. Affected by this issue is some unknown functionality of the file /mcp-rest/test/connection of the component Endpoint. Such manipulation of the argument command/args/env leads to command injection.
This vulnerability is referenced as CVE-2026-42271. It is possible to launch the attack remotely. Furthermore, an exploit is available.
You should upgrade the affected component.
A vulnerability was found in ZKTeco ZKBioSecurity 3.0.1.0_R_230. It has been declared as critical. The affected element is an unknown function of the file authLoginAction!login.do of the component User Account Handler. The manipulation of the argument Username results in incorrect behavior order: authorization before parsing and canonicalization.
This vulnerability is identified as CVE-2016-20030. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as critical has been detected in ZKTeco ZKBioSecurity 3.0.1.0_R_230. This impacts an unknown function of the component Configuration File Handler. Performing a manipulation results in incorrect default permissions.
This vulnerability is cataloged as CVE-2016-20029. The attack must be initiated from a local position. There is no exploit available.
A vulnerability labeled as problematic has been found in ZKTeco ZKAccess Security System 5.3.12252. Affected is an unknown function of the component Request Handler. Executing a manipulation of the argument holiday_name/memo can lead to cross site scripting.
This vulnerability is registered as CVE-2016-20032. It is possible to launch the attack remotely. No exploit is available.
A vulnerability described as critical has been identified in ZKTeco ZKBioSecurity 3.0.1.0_R_230. Affected by this issue is the function getClientIp of the file visLogin.jsp. The manipulation results in hard-coded credentials.
This vulnerability is reported as CVE-2016-20031. The attack requires a local approach. No exploit exists.
A vulnerability described as critical has been identified in LiteSpeed OpenLiteSpeed and LSWS Enterprise. This affects an unknown part. Such manipulation leads to os command injection.
This vulnerability is listed as CVE-2026-31386. The attack may be performed from remote. There is no available exploit.
A vulnerability classified as critical has been found in thermalright TR-VISION HOME up to 2.0.4 on Windows. This impacts an unknown function. This manipulation causes inclusion of functionality from untrusted control sphere.
This vulnerability is tracked as CVE-2026-4255. The attack is restricted to local execution. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Dassault Systèmes SOLIDWORKS Desktop 2025/2026. This affects an unknown function. Such manipulation leads to code injection.
This vulnerability is referenced as CVE-2026-3476. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as problematic has been found in Samba. This issue affects some unknown processing of the component Group Policy Handler. The manipulation leads to insufficient verification of data authenticity.
This vulnerability is traded as CVE-2026-3012. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability has been found in Samba and classified as critical. The impacted element is an unknown function of the component samba-dcerpcd Service. Performing a manipulation results in os command injection.
This vulnerability is reported as CVE-2026-4408. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability, which was classified as critical, was found in ARM Trusted Firmware 1.3. This issue affects some unknown processing of the component MT_EXECUTE_NEVER Protection. Such manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2017-7563. The attack can be launched remotely. No exploit exists.
A vulnerability has been found in ARM Trusted Firmware up to 1.3 and classified as problematic. Impacted is an unknown function of the component Debug Interface. Performing a manipulation results in improper input validation.
This vulnerability was named CVE-2017-7564. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as critical has been discovered in Open XDMoD up to 7.5.0. This vulnerability affects unknown code of the file pass_reset.php of the component Password Reset. Such manipulation leads to weak password recovery (MD5).
This vulnerability is traded as CVE-2018-16988. The attack may be launched remotely. There is no exploit available.
A vulnerability identified as problematic has been detected in Linaro Trusted Firmware-M up to 1.3.0. The impacted element is the function abort of the component Cryptographic Library. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2021-32032. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to install a patch to address this issue.
A vulnerability has been found in Clerk Plugin up to 3.x on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component API Request Handler. This manipulation causes observable timing discrepancy.
The identification of this vulnerability is CVE-2022-3907. The attack needs to be done within the local network. There is no exploit available.
The affected component should be upgraded.
A vulnerability labeled as critical has been found in Pointsharp ID Server up to 8.x. This affects an unknown part of the component Configuration Handler. Executing a manipulation can lead to authorization bypass.
This vulnerability is handled as CVE-2026-3999. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.