A vulnerability identified as critical has been detected in Mikado-Themes Hendon Plugin up to 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is referenced as CVE-2025-67937. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Mikado-Themes Curly Plugin up to 3.3 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2025-67936. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in zozothemes Corpkit Plugin up to 2.0 on WordPress. It has been rated as critical. Affected is an unknown function. Performing a manipulation results in improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability was named CVE-2025-67925. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Mikado-Themes Optimize Plugin up to 2.4 on WordPress. It has been declared as critical. This impacts an unknown function. Such manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is uniquely identified as CVE-2025-67935. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in Elated-Themes Neo Ocular Plugin up to 1.2 on WordPress. It has been classified as critical. This affects an unknown function. This manipulation causes improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2025-67920. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Mikado-Themes Wellspring Plugin up to 2.8 on WordPress and classified as critical. The impacted element is an unknown function. The manipulation results in improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is known as CVE-2025-67934. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability has been found in QantumThemes Typify Plugin up to 3.0.2 on WordPress and classified as critical. The affected element is an unknown function. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is traded as CVE-2025-22712. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in ThemeMove Moody Plugin up to 2.7.3 on WordPress. Impacted is an unknown function. Executing a manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability appears as CVE-2025-22707. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as critical, has been found in TMRW-studio Atlas Plugin up to 2.1.0 on WordPress. This issue affects some unknown processing. Performing a manipulation results in improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is reported as CVE-2025-22509. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability classified as critical was found in ThemeMove Mitech Plugin up to 2.3.4 on WordPress. This vulnerability affects unknown code. Such manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is documented as CVE-2025-22708. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in Project-MONAI MONAI up to 1.5.1. It has been declared as critical. Affected by this vulnerability is the function _download_from_ngc_private. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-21851. It is possible to launch the attack remotely. No exploit is available.
A patch should be applied to remediate this issue.
A vulnerability identified as critical has been detected in pnpm up to 10.0.0. Impacted is an unknown function of the component Environment Variable Handler. The manipulation leads to command injection.
This vulnerability is documented as CVE-2025-69262. The attack needs to be performed locally. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in REDAXO up to 5.20.1. The impacted element is an unknown function of the component Backup Handler. The manipulation of the argument EXPDIR results in path traversal: '../filedir'.
This vulnerability is cataloged as CVE-2026-21857. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic has been found in CoreShop up to 4.1.7. This affects an unknown part. This manipulation causes sql injection hibernate.
This vulnerability is registered as CVE-2026-22242. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in zauberzeug nicegui up to 3.4.x. Affected by this issue is the function ui.navigate.history.push/ui.navigate.history.replace. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-21871. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in n8n-io n8n up to 2.2.1. Affected by this vulnerability is an unknown functionality of the component Webhook Endpoint. The manipulation leads to authentication bypass by spoofing.
This vulnerability is listed as CVE-2026-21894. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in SUSE neuvector up to 5.4.7. Affected is an unknown function of the component OpenID Connect. Executing a manipulation can lead to improper certificate validation.
This vulnerability is tracked as CVE-2025-66001. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.