A vulnerability described as critical has been identified in OWASP-BLT BLT up to 2.1.1. Affected by this issue is the function pull_request_target of the file github/workflows/pre-commit-fix.yaml. The manipulation results in code injection.
This vulnerability is reported as CVE-2026-42603. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in Meari Alibaba OSS Hosted. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-33359. The attack can be initiated remotely. There is not any exploit available.
This product is a managed service, so users are unable to manage vulnerability countermeasures on their own.
A vulnerability labeled as critical has been found in pyLoad up to 0.5.0b3.dev100. Affected is the function set_config_value of the file src/pyload/core/api/__init__.py of the component HTTP Call Handler. Executing a manipulation can lead to unintended intermediary.
This vulnerability is registered as CVE-2026-42313. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in pyLoad. This impacts an unknown function of the file /web/. Performing a manipulation results in information exposure through error message.
This vulnerability is cataloged as CVE-2026-44226. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in pyLoad. This affects the function set_package_data. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-42315. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability was found in pyLoad. It has been rated as critical. The impacted element is the function set_config_value of the file src/pyload/core/api/__init__.py. This manipulation causes improper certificate validation.
This vulnerability is tracked as CVE-2026-42312. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability was found in Meari com.meari.sdk. It has been declared as problematic. The affected element is an unknown function of the file libmrplayer.so of the component SDK Image Handler. The manipulation results in inadequate encryption strength.
This vulnerability is identified as CVE-2026-33361. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in flash-attention training framework up to 2025-13-04. It has been classified as critical. Impacted is the function load_checkpoint of the file checkpoint.py of the component Pickle Module. The manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-31253. The attack needs to be initiated within the local network. No exploit is available.
A vulnerability was found in CosyVoice up to 2025-30-21 and classified as critical. This issue affects the function torch.load of the component Pickle Module. Executing a manipulation can lead to deserialization.
The identification of this vulnerability is CVE-2026-31252. The attack needs to be done within the local network. There is no exploit available.
A vulnerability has been found in CosyVoice up to 2025-30-21 and classified as critical. This vulnerability affects the function torch.load of the component Pickle Module. Performing a manipulation results in deserialization.
This vulnerability was named CVE-2026-31251. The attack needs to be approached within the local network. There is no available exploit.
A vulnerability, which was classified as critical, was found in CosyVoice up to 2025-30-21. This affects the function torch.load of the file average_model.py of the component Pickle Module. Such manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2026-31250. The attack can only be initiated within the local network. No exploit exists.
A vulnerability, which was classified as critical, has been found in CosyVoice up to 2025-30-21. Affected by this issue is the function torch.load of the file make_parquet_list.py of the component Pickle Module. This manipulation causes deserialization.
This vulnerability is handled as CVE-2026-31249. The attack can only be done within the local network. There is not any exploit available.
A vulnerability classified as problematic was found in Azure kafka-sink-azure-kusto up to 5.2.2. Affected by this vulnerability is an unknown functionality of the component Connector Configuration Handler. The manipulation results in improper neutralization of special elements in data query logic.
This vulnerability is known as CVE-2026-42316. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in pyLoad. Affected is an unknown function of the component Package Folder Name Handler. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-42314. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in Wikimedia MediaWiki up to 1.43.6/1.44.3/1.45.1. This impacts an unknown function of the file includes/Actions/ActionEntryPoint.Php. Executing a manipulation can lead to basic cross site scripting.
This vulnerability appears as CVE-2026-34095. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in Wikimedia MediaWiki up to 1.43.6/1.44.3/1.45.1. This affects an unknown function of the file includes/Page/Article.Php. Performing a manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-34094. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability labeled as problematic has been found in Wikimedia MediaWiki up to 1.43.6/1.44.3/1.45.1. The impacted element is an unknown function of the file includes/Specials/SpecialUserRights.Php. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-34093. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in flash-attention project up to 2025-13-04. The affected element is the function eval. This manipulation causes code injection.
This vulnerability is registered as CVE-2026-31254. Remote exploitation of the attack is possible. No exploit is available.