A vulnerability identified as critical has been detected in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldName results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-8087. The attack must be initiated from a local position. Furthermore, there is an exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON Object Handler. The manipulation of the argument condition leads to sql injection.
This vulnerability is documented as CVE-2026-8114. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor confirms (translated from Chinese): "It should have been fixed; a batch of issues were recently resolved."
A vulnerability classified as problematic was found in net-http-httputil up to 1.25.9/1.26.2 on Go. This impacts the function Rewrite of the component Query Parameter Handler. Executing a manipulation can lead to http request smuggling.
This vulnerability is tracked as CVE-2026-39825. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability has been found in cmd-go up to 1.25.9/1.26.2 on Go and classified as critical. Affected by this issue is some unknown functionality of the file /tmp. This manipulation causes insecure temporary file.
This vulnerability is registered as CVE-2026-39819. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability classified as problematic has been found in net-mail up to 1.25.9/1.26.2 on Go. Affected by this vulnerability is an unknown functionality of the component Email Address Handler. The manipulation leads to inefficient algorithmic complexity.
This vulnerability is referenced as CVE-2026-42499. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability identified as problematic has been detected in path-to-regexp up to 8.3.x. This vulnerability affects unknown code. This manipulation causes resource consumption.
The identification of this vulnerability is CVE-2026-4926. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.74/6.18.15/6.19.5. This affects the function most_register_interface. The manipulation results in allocation of resources.
This vulnerability is known as CVE-2025-71272. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.15/6.19.5. Impacted is the function setup_bdev_super of the component New Mount Api. The manipulation leads to allocation of resources.
This vulnerability is documented as CVE-2025-71271. The attack requires being on the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in path-to-regexp up to 8.3.x. This affects an unknown part. The manipulation results in inefficient regular expression complexity.
This vulnerability was named CVE-2026-4923. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in cure53 DOMPurify up to 3.3.x. This affects an unknown part. Executing a manipulation can lead to permissive list of allowed inputs.
This vulnerability is tracked as CVE-2026-41240. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability classified as problematic has been found in cure53 DOMPurify up to 3.3.x. Impacted is an unknown function. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-41239. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability has been found in cure53 DOMPurify up to 3.3.1 and classified as problematic. Affected is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-41238. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
The ShinyHunters extortion gang has breached education technology giant Instructure again, this time exploiting another vulnerability to deface Canvas login portals for hundreds of colleges and universities. [...]
A vulnerability categorized as critical has been discovered in Apple iOS up to 7.1.2. Affected is an unknown function of the component Data Detectors. The manipulation results in improper access controls.
This vulnerability is reported as CVE-2013-6835. The attack can be launched remotely. Moreover, an exploit is present.
It is advisable to upgrade the affected component.