A vulnerability described as critical has been identified in Apache NiFi up to 2.9.0. Affected is an unknown function. Executing a manipulation can lead to missing authentication.
This vulnerability is registered as CVE-2026-44914. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability was found in picklescan up to 0.0.27. It has been declared as critical. This affects the function torch.utils._config_module.load_config. Executing a manipulation can lead to deserialization.
This vulnerability is handled as CVE-2025-71348. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in MISP up to 2.5.41. This affects an unknown part. Executing a manipulation can lead to session fixiation.
This vulnerability is tracked as CVE-2026-56425. The attack can be launched remotely. No exploit exists.
A patch should be applied to remediate this issue.
A vulnerability categorized as critical has been discovered in IBM Engineering Workflow Management up to 7.0.2/7.0.3/7.1. Affected by this vulnerability is an unknown functionality of the component HTTP Header Handler. The manipulation results in improper neutralization of http headers for scripting syntax.
This vulnerability is reported as CVE-2024-51454. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in Angular up to 18.2.14. This affects an unknown function of the component Element Attribute Handler. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-50557. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability classified as problematic has been found in Angular up to 18.2.14. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-52725. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Microsoft 365 Copilot CVE-2026-47645 Microsoft 365 and classified as problematic. This affects an unknown part. This manipulation causes open redirect.
The identification of this vulnerability is CVE-2026-47645. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as critical was found in vLLM up to 0.12.x. This impacts an unknown function of the component prompt-embeds Feature. Executing a manipulation can lead to out-of-bounds read.
This vulnerability appears as CVE-2026-56340. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability labeled as problematic has been found in vLLM up to 0.8.x. Impacted is an unknown function of the file vllm/lora/utils.py of the component OpenAI-compatible Serving Chat Endpoint. The manipulation results in inefficient regular expression complexity.
This vulnerability is cataloged as CVE-2025-71379. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in X.org libXpm up to 3.5.4. The affected element is the function xpmNextWord. The manipulation leads to out-of-bounds read.
This vulnerability is listed as CVE-2026-4367. The attack must be carried out from within the local network. There is no available exploit.
You should upgrade the affected component.
A vulnerability has been found in Node.js up to 22.22.3/24.16.0/26.3.0 and classified as problematic. This impacts an unknown function. Performing a manipulation results in resource consumption.
This vulnerability is reported as CVE-2026-48619. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Node.js up to 22.22.3/24.16.0/26.3.0. It has been classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2026-48928. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Node.js up to 22.22.3/24.16.0/26.3.0. It has been declared as critical. Affected by this issue is some unknown functionality. The manipulation results in improper access controls.
This vulnerability is known as CVE-2026-48930. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in Node.js up to 22.22.3/24.16.0/26.3.0. It has been rated as problematic. This affects the function subtle.encrypt. This manipulation causes integer overflow.
This vulnerability is handled as CVE-2026-48933. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in Node.js up to 22.22.3/24.16.0/26.3.0. This affects an unknown function. Such manipulation leads to improper handling of unicode encoding.
This vulnerability is documented as CVE-2026-48618. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in Node.js up to 22.22.3/24.16.0/26.3.0 and classified as problematic. Affected is an unknown function of the component Error Message Handler. Executing a manipulation can lead to exposure of private personal information to an unauthorized actor.
This vulnerability appears as CVE-2026-48615. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in ip-address 1.11.7/1.12/1.12.3/1.12.4/1.13.0. It has been rated as problematic. The impacted element is an unknown function. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-42338. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.