A vulnerability was found in carazo Import and Export Users and Customers Plugin up to 1.29.7 on WordPress. It has been classified as critical. Affected by this vulnerability is the function save_extra_user_profile_fields. The manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-3629. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability was found in Red Hat Keycloak. It has been rated as critical. This affects an unknown part of the component Client Configuration Handler. This manipulation causes server-side request forgery.
This vulnerability appears as CVE-2026-4366. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in nicolargo glances up to 4.5.1 and classified as problematic. This affects an unknown part of the component REST API. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2026-32596. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability identified as critical has been detected in lxc incus-os up to 20260314. The impacted element is an unknown function. The manipulation of the argument PCR7 leads to insufficiently protected credentials.
This vulnerability is traded as CVE-2026-32606. It is possible to launch the attack on the physical device. There is no exploit available.
You should upgrade the affected component.
A vulnerability described as problematic has been identified in CraftCMS azure-blob up to 2.1.0. This affects the function actionLoadContainerData. Executing a manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2026-32268. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as problematic was found in Get Use APIs Plugin up to 2.0.9 on WordPress. This issue affects some unknown processing. The manipulation results in cross site scripting.
This vulnerability was named CVE-2025-15363. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability has been found in alhadeff Writeprint Stylometry Plugin up to 0.1 on WordPress and classified as problematic. The impacted element is the function bjl_wprintstylo_comments_nav of the component GET Parameter Handler. Performing a manipulation of the argument p results in cross site scripting.
This vulnerability is identified as CVE-2026-3512. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability labeled as problematic has been found in Dahua NVR2-4KS3, XVR4232AN-I, T and XVR1B16H-I. This vulnerability affects unknown code. Executing a manipulation can lead to authentication bypass by primary weakness.
This vulnerability appears as CVE-2025-31703. The physical device can be targeted for the attack. There is no available exploit.
A vulnerability classified as critical has been found in Kanboard up to 1.2.50. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in sql injection.
This vulnerability was named CVE-2026-33058. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in nicolargo glances up to 4.5.1. This vulnerability affects the function secure_popen. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-32608. Local access is required to approach this attack. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.15.167/6.1.112/6.6.54/6.10.13/6.11.2. It has been rated as critical. This vulnerability affects the function mlx5e_tir_builder_alloc. Performing a manipulation results in null pointer dereference.
This vulnerability is known as CVE-2024-50000. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as critical was found in Linux Kernel up to 6.10.13/6.11.2. This issue affects the function afs_wait_for_operation. The manipulation results in excessive iteration.
This vulnerability is cataloged as CVE-2024-49999. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in Linux Kernel up to 6.11.2. Impacted is the function skb_put_padto of the component Ethernet Frame Handler. The manipulation results in buffer overflow.
This vulnerability is identified as CVE-2024-49997. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability has been found in Linux Kernel up to 6.10.13/6.11.2 and classified as problematic. The impacted element is the function dev_get_drvdata. Performing a manipulation results in race condition.
This vulnerability is reported as CVE-2024-49998. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.