A vulnerability classified as critical has been found in Fortinet FortiWeb up to 7.0.11/7.2.11/7.4.9/7.6.4/8.0.1. Affected is an unknown function of the component HTTP Handler. This manipulation causes relative path traversal.
This vulnerability is registered as CVE-2025-64446. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability was found in Mattermost up to 10.11.10/11.2.2/11.3.0 and classified as problematic. Impacted is an unknown function of the component Websocket Message Handler. Executing a manipulation can lead to improper validation of specified type of input.
The identification of this vulnerability is CVE-2026-2454. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Apache Airflow up to 3.1.7. This impacts an unknown function of the component HTTP Request Header Handler. The manipulation results in exposure of resource.
This vulnerability is known as CVE-2026-28779. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.19.5. Impacted is the function getxattr of the file /tmp/test of the component audit. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-23241. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.19.5. This issue affects the function fchmodat2 of the component audit. This manipulation causes privilege escalation.
This vulnerability is registered as CVE-2025-71239. The attack requires access to the local network. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability described as critical has been identified in Canonical Ubuntu Linux up to 2.75.0. This affects an unknown function of the file /tmp of the component snapd. Executing a manipulation can lead to privilege chaining.
This vulnerability is registered as CVE-2026-3888. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability labeled as critical has been found in GNOME libsoup. The affected element is an unknown function. Such manipulation leads to use after free.
This vulnerability is listed as CVE-2026-4271. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Apache Airflow up to 3.1.7. It has been rated as problematic. This vulnerability affects unknown code of the file /ui/dependencies. The manipulation leads to incorrect permission assignment.
This vulnerability is referenced as CVE-2026-28563. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in GNOME libsoup. It has been declared as critical. The affected element is an unknown function of the component Hostname Handler. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-3632. The attack can be launched remotely. No exploit exists.
A vulnerability was found in GNOME libsoup. It has been rated as problematic. The impacted element is an unknown function of the component HTTP Request Handler. The manipulation leads to crlf injection.
This vulnerability is listed as CVE-2026-3633. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as critical has been discovered in GNOME libsoup. This affects an unknown function of the component Content-Type Header Handler. The manipulation results in http response splitting.
This vulnerability is cataloged as CVE-2026-3634. The attack may be launched remotely. There is no exploit available.
WorldLeaks group hit Los Angeles and its Metro system, forcing a shutdown, while two Bay Area cities declared emergencies after ransomware attacks. WorldLeaks group hit Los Angeles and its Metro, forcing a shutdown, while two Bay Area cities declared emergencies after ransomware attacks. This week, local media reported that an unauthorized activity hit Metro’s internal […]
The Trivy vulnerability scanner was compromised in a supply-chain attack by threat actors known as TeamPCP, which distributed credential-stealing malware through official releases and GitHub Actions. [...]
A vulnerability labeled as critical has been found in Linux Kernel up to 6.10.13/6.11.2. The affected element is the function xe_gsc of the component HDCP. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2024-49990. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.54/6.10.13/6.11.2. Impacted is the function 0010:__slab_free+0x152/0x2f0 of the component AMD Display. The manipulation leads to double free.
This vulnerability is uniquely identified as CVE-2024-49989. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.