A vulnerability identified as critical has been detected in Samsung Devices. The impacted element is an unknown function of the component FactoryCamera. The manipulation leads to incorrect default permissions.
This vulnerability is documented as CVE-2026-21015. The attack needs to be performed locally. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Bytello Share. The affected element is an unknown function of the component Installer. Executing a manipulation can lead to uncontrolled search path.
This vulnerability is registered as CVE-2026-44612. The attack needs to be launched locally. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Hitachi Vantara Pentaho Data Integration and Analytics up to 10.x. It has been declared as problematic. This issue affects some unknown processing of the component JDBC Driver. Such manipulation leads to dependency on vulnerable third-party component.
This vulnerability is listed as CVE-2025-11159. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Gerrit 2.12; 0. It has been classified as problematic. This vulnerability affects unknown code of the component Submission Handler. This manipulation causes incorrect authorization.
This vulnerability is tracked as CVE-2026-2725. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in beardev JoomSport Plugin up to 5.7.7 on WordPress and classified as critical. This affects an unknown part. The manipulation of the argument sortf results in sql injection.
This vulnerability is identified as CVE-2026-6929. The attack can be executed remotely. There is not any exploit available.
A vulnerability has been found in themeum Tutor LMS Plugin up to 3.9.9 on WordPress and classified as critical. Affected by this issue is the function get_course_id_by. The manipulation of the argument course leads to authorization bypass.
This vulnerability is referenced as CVE-2026-6965. Remote exploitation of the attack is possible. No exploit is available.
Google on Tuesday unveiled a new opt-in Android feature called Intrusion Logging for storing forensic logs to better analyze sophisticated spyware attacks.
Intrusion Logging, available as part of Advanced Protection Mode, enables "persistent and privacy-preserving forensics logging to allow for investigation of devices in the event of a suspected compromise," the company said.
The feature, it
A vulnerability, which was classified as problematic, was found in ghera74 ilGhera Support System for WooCommerce Plugin up to 1.3.0 on WordPress. Affected by this vulnerability is the function get_ticket_content_callback. Executing a manipulation can lead to authorization bypass.
The identification of this vulnerability is CVE-2025-14033. The attack may be launched remotely. There is no exploit available.