A vulnerability marked as critical has been reported in Linux Kernel. This impacts an unknown function of the component XFRM ESP-in-TCP Subsystem. Performing a manipulation results in write-what-where condition.
This vulnerability is identified as CVE-2026-46300. The attack is only possible with local access. Additionally, an exploit exists.
A vulnerability, which was classified as problematic, has been found in GitLab Community Edition and Enterprise Edition up to 18.9.6/18.10.5/18.11.2. This affects an unknown function. The manipulation leads to allocation of resources.
This vulnerability is listed as CVE-2026-8280. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in GitLab Community Edition and Enterprise Edition up to 18.9.6/18.10.5/18.11.2. The impacted element is an unknown function of the component Private Group Handler. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-8144. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. The affected element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-7481. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. Impacted is an unknown function. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-7471. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. This issue affects some unknown processing of the component Analytics Dashboard. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-7377. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as problematic has been found in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. This vulnerability affects unknown code of the component Merge Request Handler. The manipulation results in missing authorization.
This vulnerability was named CVE-2026-6883. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in GitLab Community Edition and Enterprise Edition up to 18.11.2. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-6335. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. Affected by this issue is some unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-6073. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component Merge Request Handler. Performing a manipulation results in authorization bypass.
This vulnerability is known as CVE-2026-6063. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in LEONT Crypt::Argon2 up to 0.030 on Perl. It has been classified as problematic. Affected by this issue is the function argon2_verify. This manipulation of the argument length causes buffer over-read.
The identification of this vulnerability is CVE-2026-8463. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.12.77/6.18.18/6.19.8. It has been classified as critical. This issue affects the function set_access_flags. Performing a manipulation results in infinite loop.
This vulnerability was named CVE-2026-43486. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability identified as problematic has been detected in multiparty up to 4.2.3/4.2.x. This impacts an unknown function. The manipulation leads to inefficient regular expression complexity.
This vulnerability is uniquely identified as CVE-2026-8159. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability has been found in Apache Tomcat up to 8.5.100/9.0.117/10.0.27/10.1.54/11.0.21 and classified as critical. Affected is an unknown function. The manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2026-41293. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.