A vulnerability categorized as problematic has been discovered in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgbmp Utility. Executing a manipulation can lead to out-of-bounds read.
This vulnerability appears as CVE-2026-9530. The attack requires local access. In addition, an exploit is available.
It is advisable to implement a patch to correct this issue.
A vulnerability was found in GNU LibreDWG up to 0.14. It has been rated as problematic. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2026-9529. The attack requires a local approach. Moreover, an exploit is present.
A vulnerability was found in itsourcecode Electronic Judging System 1.0. It has been declared as critical. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to sql injection.
This vulnerability is documented as CVE-2026-9528. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability was found in itsourcecode Electronic Judging System 1.0. It has been classified as problematic. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes cross site scripting.
This vulnerability is registered as CVE-2026-9527. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability was found in itsourcecode Electronic Judging System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id results in sql injection.
This vulnerability is cataloged as CVE-2026-9526. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in itsourcecode Electronic Judging System 1.0 and classified as critical. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql injection.
This vulnerability is listed as CVE-2026-9525. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as critical, was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection.
This vulnerability is tracked as CVE-2026-9524. The attack can be launched remotely. No exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of the file /SubstationWEBV2/app/..;/calc/getCalcmeterDetailDayListTree. Performing a manipulation of the argument sort results in sql injection.
This vulnerability is identified as CVE-2026-9523. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical was found in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input.
This vulnerability is referenced as CVE-2026-9521. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the component Sign-in. This manipulation of the argument Next causes cross site scripting.
The identification of this vulnerability is CVE-2026-9520. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.