A vulnerability identified as problematic has been detected in NaturalIntelligence fast-xml-parser up to 5.5.5. Affected is the function replaceEntitiesValue. Performing a manipulation results in xml entity expansion.
This vulnerability is identified as CVE-2026-33036. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in alexcrichton tar-rs up to 0.4.44. This impacts an unknown function. Performing a manipulation results in type confusion.
This vulnerability is reported as CVE-2026-33055. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in pydicom up to 3.0.1. This impacts an unknown function of the component DICOM File Parser. Executing a manipulation can lead to path traversal.
This vulnerability appears as CVE-2026-32711. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as critical was found in Microsoft Windows. Impacted is an unknown function of the component Kernel. Executing a manipulation can lead to race condition.
This vulnerability is handled as CVE-2025-62215. It is possible to launch the attack on the local host. Additionally, an exploit exists.
It is advisable to implement a patch to correct this issue.
A vulnerability was found in VMware Spring AI up to 1.0.3/1.1.2. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component AbstractFilterExpressionConverter. This manipulation causes injection.
This vulnerability is registered as CVE-2026-22729. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in VMware Spring AI up to 1.0.3/1.1.2. Affected by this issue is some unknown functionality of the component MariaDBFilterExpressionConverter. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-22730. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability has been found in Yoast Duplicate Post Plugin up to 4.5 on WordPress and classified as critical. Affected is the function clone_bulk_action_handler/republish_request of the component Republish Feature. The manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-1217. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in WebberZone Contextual Related Posts Plugin up to 4.2.1 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation results in missing authorization.
This vulnerability is identified as CVE-2026-32565. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.