A vulnerability classified as critical has been found in Linux Kernel up to 6.12.83/6.18.24/7.0.1. The affected element is the function ipc_validate_msg of the file smb2pdu.c of the component ksmbd. Performing a manipulation results in integer overflow.
This vulnerability is reported as CVE-2026-31707. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.74/6.18.15/6.19.5. This affects an unknown part of the component DAI Linksmachine Driver. The manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-43137. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
A vulnerability identified as critical has been detected in APScheduler 4.0.0a5. Affected by this issue is the function unmarshal_object of the component JSONSerializer/CBORSerializer. Performing a manipulation results in deserialization.
This vulnerability is known as CVE-2026-31072. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as critical has been found in LalanaChami Pharmacy Management System. This affects an unknown part of the file /api/user/signup of the component Registration Handler. Executing a manipulation of the argument role can lead to improper access controls.
This vulnerability is handled as CVE-2026-31070. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as problematic was found in LalanaChami Pharmacy Management System. The affected element is an unknown function of the file /api/user/getUserData of the component API Endpoint. Such manipulation leads to password hash with insufficient computational effort.
This vulnerability is referenced as CVE-2026-31071. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as critical, was found in hitarth-gg Zenshin up to 2.6.x. This affects an unknown function of the file /stream-to-vlc of the component Parameter Handler. Executing a manipulation of the argument url can lead to os command injection.
This vulnerability is tracked as CVE-2026-37281. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability classified as critical was found in BillaBear. This impacts the function sprintf. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2026-31069. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in Tenable Terrascan up to 1.18.3 and classified as critical. This issue affects some unknown processing of the file /v1/{iac}/{iacVersion}/{cloud}/local/file/scan of the component File Scan Endpoint. Performing a manipulation of the argument webhook_url results in server-side request forgery.
This vulnerability is identified as CVE-2026-47356. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in Tenable Terrascan up to 1.18.3 and classified as critical. Impacted is the function remote_type of the file /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan of the component Remote Directory Scan Endpoint. Executing a manipulation of the argument remote_url can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-47357. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Tenable Terrascan up to 1.18.3. It has been classified as critical. The affected element is the function AWS::CloudFormation::Stack of the component Remote Scan Endpoint. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-47358. The attack may be initiated remotely. There is no available exploit.
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month.
Project Glasswing is a defensive effort launched by the artificial intelligence (AI) company to secure critical global software
A vulnerability labeled as critical has been found in Mozilla Firefox up to 150. Affected is an unknown function of the component Audio/Video. Such manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2026-8972. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in F5 NGINX JavaScript up to 0.9.8. Impacted is the function ngx.fetch of the component HTTP Handler. Such manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2026-8711. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
A vulnerability has been found in ModelScope 1.25.0 and classified as critical. The affected element is an unknown function of the component Module Handler. Performing a manipulation results in code injection.
This vulnerability is cataloged as CVE-2025-51427. The attack must originate from the local network. There is no exploit available.
A vulnerability was found in Portrait Dell Color Management Application up to 3.6.x. It has been classified as critical. This affects an unknown function of the file CCFLFamily_07Feb11.edr of the component Link Handler. The manipulation leads to symlink following.
This vulnerability is documented as CVE-2026-34883. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.