A vulnerability labeled as critical has been found in Apache MINA up to 2.1.11/2.2.6. Impacted is the function AbstractIoBuffer.resolveClass. The manipulation results in deserialization.
This vulnerability is reported as CVE-2026-42779. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in SharpCompress up to 0.20.x and classified as critical. Impacted is an unknown function of the component Extraction. Executing a manipulation with the input ../ as part of ZIP Archive can lead to path traversal (Zip-Slip).
This vulnerability is tracked as CVE-2018-1002206. The attack is restricted to local execution. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability identified as critical has been detected in Copeland XWEB 300D PRO, XWEB 500D PRO and XWEB 500B PRO up to 1.12.1. The impacted element is an unknown function of the component Firmware Update Handler. This manipulation of the argument Devices causes os command injection.
This vulnerability is handled as CVE-2026-20910. The attack can be initiated remotely. There is not any exploit available.
A vulnerability classified as critical was found in Copeland XWEB 300D PRO, XWEB 500D PRO and XWEB 500B PRO up to 1.12.1. Affected by this issue is some unknown functionality. The manipulation of the argument Devices results in os command injection.
This vulnerability is identified as CVE-2026-25109. The attack can be executed remotely. There is not any exploit available.
A vulnerability categorized as critical has been discovered in Python CPython up to 3.14.x. This vulnerability affects the function ElementDeclHandler of the component Expat Parser. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is registered as CVE-2026-4224. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Intrado 911 Emergency Gateway 5.x/6.x/7.x and classified as critical. This affects an unknown function of the component EGW Management Interface. The manipulation results in path traversal: '.../...//'.
This vulnerability is reported as CVE-2026-6074. The attack can be launched remotely. No exploit exists.
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.74/6.18.15/6.19.5. Impacted is the function devm_kmemdup of the component wifi. Executing a manipulation can lead to memory leak.
This vulnerability is handled as CVE-2025-71273. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability identified as critical has been detected in Siemens Simcenter Femap up to 2512.2. This issue affects some unknown processing of the component IPT File Handler. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is known as CVE-2025-12659. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Jupyter notebook up to 4.5.6. The affected element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-42557. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability described as problematic has been identified in GitHub copilot-cli up to 1.0.42. The impacted element is an unknown function. Executing a manipulation can lead to incorrect behavior order.
The identification of this vulnerability is CVE-2026-45033. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Anthropic claude-code up to 1.0.120. It has been classified as problematic. This vulnerability affects unknown code of the file ~/.ssh/known_hosts of the component Graphical Interface. The manipulation leads to certificate with host mismatch.
This vulnerability is documented as CVE-2026-44467. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability described as critical has been identified in Anthropic claude-code up to 1.3834.0 on Windows. Affected is an unknown function of the component Graphical Interface. The manipulation results in link following.
This vulnerability was named CVE-2026-44470. The attack needs to be approached locally. There is no available exploit.
Upgrading the affected component is recommended.