A vulnerability classified as problematic has been found in CoreDNS up to 1.14.2. This impacts an unknown function of the component DNS Message Handler. Performing a manipulation results in resource consumption.
This vulnerability is reported as CVE-2026-32936. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in sandboxie-plus Sandboxie up to 1.17.2 on Windows. This impacts an unknown function. Such manipulation of the argument NAMED_PIPE_OPEN_REQ leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2026-34464. The attack must be carried out locally. There is no available exploit.
The affected component should be upgraded.
A vulnerability was found in xwiki-contrib macro-plantuml up to 2.4.0. It has been rated as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation of the argument server results in server-side request forgery.
This vulnerability was named CVE-2026-42140. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in sandboxie-plus Sandboxie up to 1.17.2 on Windows. The impacted element is an unknown function of the component Password Hash Handler. The manipulation results in use of weak hash.
This vulnerability is identified as CVE-2026-34527. The attack is only possible with local access. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in Prometheus up to 3.5.2/3.11.2. This issue affects the function client_secret of the file storage/remote/azuread of the component HTTP API Endpoint. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-42151. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
A vulnerability labeled as problematic has been found in Prometheus up to 3.5.2/3.11.2. Impacted is an unknown function of the file /api/v1/read of the component Remote Read Endpoint. The manipulation results in resource consumption.
This vulnerability is cataloged as CVE-2026-42154. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in Tunnelblick up to 9.0beta01. Affected by this issue is some unknown functionality. The manipulation results in symlink following.
This vulnerability is known as CVE-2026-31893. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.
A vulnerability described as critical has been identified in sandboxie-plus Sandboxie up to 1.17.2 on Windows. Affected by this vulnerability is an unknown functionality of the file UpdUtil.exe of the component SandMan Interface. Executing a manipulation can lead to time-of-check time-of-use.
This vulnerability is registered as CVE-2026-34596. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.18.9. It has been declared as critical. Affected by this issue is the function skb_push of the component wifi. Executing a manipulation can lead to privilege escalation.
This vulnerability is tracked as CVE-2025-71222. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.18.9. The affected element is the function mmp_pdma_residue of the component dmaengine. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2025-71221. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.123/6.12.69/6.18.9. Affected by this vulnerability is the function parse_durable_handle_context of the component smb. The manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2025-71204. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 5.15.199/6.1.162/6.6.123/6.12.69/6.18.9. Impacted is the function ksmbd_session_rpc_close of the component smb. Performing a manipulation results in privilege escalation.
This vulnerability is known as CVE-2025-71220. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.18.6. It has been declared as critical. This affects the function vfree of the component IOMMU Interface. The manipulation results in privilege escalation.
This vulnerability is reported as CVE-2025-71202. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.