A vulnerability classified as problematic was found in FastNetMon Community Edition up to 1.2.9. This issue affects the function grpc::InsecureServerCredentials of the file src/fastnetmon.cpp of the component gRPC API. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-48692. The attack requires being on the local network. There is not any exploit available.
A vulnerability classified as problematic has been found in FastNetMon Community Edition up to 1.2.9. This vulnerability affects unknown code of the file src/netflow_plugin/netflow_v9_collector.cpp of the component NetFlow v9 Data Flowset Processor. This manipulation causes out-of-bounds read.
This vulnerability is registered as CVE-2026-48683. The attack requires access to the local network. No exploit is available.
A vulnerability described as problematic has been identified in ONLYOFFICE DocSpace up to 3.2.0. This affects an unknown part of the component REST API. The manipulation results in improper control of resource identifiers.
This vulnerability is cataloged as CVE-2026-38587. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in FastNetMon Community Edition up to 1.2.9/4.3. Affected by this issue is the function parse_raw_bgp_attribute of the file src/bgp_protocol.hpp. The manipulation leads to out-of-bounds read.
This vulnerability is listed as CVE-2026-48685. The attack must be carried out from within the local network. There is no available exploit.
A vulnerability labeled as critical has been found in FastNetMon Community Edition up to 1.2.9. Affected by this vulnerability is the function _log of the file src/juniper_plugin/fastnetmon_juniper.php. Executing a manipulation of the argument msg can lead to os command injection.
This vulnerability is tracked as CVE-2026-48687. The attack is only possible within the local network. No exploit exists.
A vulnerability identified as problematic has been detected in Apache Flink Kubernetes Operator up to 1.14.x. Affected is an unknown function. Performing a manipulation results in files or directories accessible.
This vulnerability is identified as CVE-2026-40564. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in GitLab Community Edition and Enterprise Edition. This vulnerability affects unknown code of the component Snippet Description Handler. The manipulation results in denial of service.
This vulnerability is known as CVE-2022-2592. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in TEM FLEX-1085 1.6.0. It has been classified as critical. The affected element is an unknown function of the file /sistema/flash/reboot. The manipulation leads to denial of service.
This vulnerability is listed as CVE-2022-2591. The attack may be initiated remotely. In addition, an exploit is available.
It is recommended to apply restrictive firewalling.
A vulnerability classified as problematic was found in Meks Easy Social Share Plugin up to 1.2.7 on WordPress. The impacted element is an unknown function of the component Setting Handler. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2022-2574. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A threat actor using the alias sxcfox claims to have leaked a database allegedly belonging to ManoMano, a major French online marketplace for DIY, home improvement, and gardening.
The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026.
The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial services, and professional services, per the Threat Hunter Team from Symantec and Carbon Black.
A vulnerability categorized as problematic has been discovered in Google Chrome. This issue affects some unknown processing of the component ServiceWorker. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.
This vulnerability appears as CVE-2026-9116. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Google Chrome on Linux. Impacted is an unknown function of the component GFX. The manipulation leads to type confusion.
This vulnerability is traded as CVE-2026-9117. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability was found in Google Chrome. It has been rated as problematic. This vulnerability affects unknown code of the component Service Worker. Performing a manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is reported as CVE-2026-9115. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability described as problematic has been identified in Google Chrome on macOS. This affects an unknown function of the component GPU. Such manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-9113. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Google Chrome. This impacts an unknown function of the component QUIC. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-9114. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Google Chrome on Linux. It has been declared as critical. This affects an unknown part of the component WebRTC. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-9111. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.