North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance. [...]
A vulnerability marked as critical has been reported in orval up to 7.19.x/8.0.2. This affects the function getMockScalar of the file packages/mock/src/faker/getters/scalar.ts of the component MSW Handler. This manipulation causes command injection.
This vulnerability appears as CVE-2026-24132. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability labeled as problematic has been found in Totolink X5000R up to 9.1.0cu_2415_B20250515. Affected is the function setDiagnosisCfg of the file /usr/sbin/lighttpd. Executing a manipulation of the argument ip can lead to resource consumption.
The identification of this vulnerability is CVE-2025-70327. The attack may be launched remotely. There is no exploit available.
A vulnerability described as critical has been identified in Traccar up to 6.11.1. Affected by this issue is some unknown functionality of the component Device Image Handler. The manipulation of the argument uniqueId results in path traversal.
This vulnerability is identified as CVE-2026-23521. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as critical has been found in Traccar up to 6.11.1. This affects an unknown part of the file /api/socket of the component Websocket Connection Handler. This manipulation causes missing origin validation in websockets.
This vulnerability is tracked as CVE-2025-68930. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability, which was classified as problematic, was found in Traccar 6.11.1. This affects an unknown function of the component SVG File Parser. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-25648. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Traccar up to 6.11.1 and classified as problematic. Affected is an unknown function. Such manipulation of the argument redirect_uri leads to open redirect.
This vulnerability is documented as CVE-2026-25649. The attack can be executed remotely. There is not any exploit available.
A vulnerability categorized as critical has been discovered in Totolink X6000R up to 9.4.0cu.1498_B20250826. This impacts the function NTPSyncWithHost of the file /usr/sbin/shttpd. Executing a manipulation of the argument host_time can lead to os command injection.
This vulnerability appears as CVE-2025-70328. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as problematic has been detected in Jeff Starr Simple Ajax Chat Plugin up to 20251121 on WordPress. Affected is an unknown function. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is traded as CVE-2026-3075. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in GCOM EPON 1GE ONU C00R371V00B01 and classified as critical. This affects an unknown function. Such manipulation leads to manage user sessions.
This vulnerability is listed as CVE-2025-71056. The attack may be performed from remote. There is no available exploit.
A vulnerability labeled as problematic has been found in Bludit up to 3.16.2. This vulnerability affects unknown code. Such manipulation of the argument post content leads to cross site scripting.
This vulnerability is traded as CVE-2026-27742. The attack may be launched remotely. There is no exploit available.
A vulnerability described as problematic has been identified in Tencent iOA App up to 210.9.28693.621001 on Windows. Impacted is an unknown function. Executing a manipulation can lead to race condition.
This vulnerability is handled as CVE-2025-63945. It is possible to launch the attack on the local host. There is not any exploit available.
A vulnerability classified as problematic has been found in Tencent PC Manager App up to 17.10.28554.205 on Windows. The affected element is an unknown function. The manipulation leads to race condition.
This vulnerability is uniquely identified as CVE-2025-63946. Local access is required to approach this attack. No exploit exists.
A vulnerability was found in Bludit up to 3.16.1. It has been declared as problematic. This affects an unknown part. The manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2026-27741. The attack may be launched remotely. There is no exploit available.
A vulnerability marked as problematic has been reported in saitoha libsixel 1.8.7. This affects an unknown function of the file malloc_stub.c. Performing a manipulation results in memory leak.
This vulnerability is identified as CVE-2025-61146. The attack can only be performed from the local network. There is not any exploit available.
ShinyHunters hackers leak 2 million records from Dutch telecom Odido after ransom refusal, claiming up to 21 million customer records were stolen in the breach.
A vulnerability categorized as critical has been discovered in Owl opds up to 2.2.0.4. Affected by this issue is some unknown functionality of the component Network Request Handler. Executing a manipulation can lead to incorrect permission assignment.
The identification of this vulnerability is CVE-2026-26096. The attack may be launched remotely. There is no exploit available.