PTC Inc. is warning of a critical vulnerability in Windchill and FlexPLM, widely used product lifecycle management (PLM) solutions, that could allow remote code execution. [...]
A vulnerability, which was classified as problematic, has been found in samtools htslib up to 1.21.0/1.22.1/1.23. This issue affects some unknown processing. Performing a manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2026-31964. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability described as problematic has been identified in samtools htslib up to 1.21.0/1.22.1/1.23. This issue affects the function cram_decode_seq. Such manipulation leads to out-of-bounds read.
This vulnerability is listed as CVE-2026-31966. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability classified as problematic has been found in samtools htslib up to 1.21.0/1.22.1/1.23. Impacted is the function cram_decode_slice. Performing a manipulation results in out-of-bounds read.
This vulnerability is cataloged as CVE-2026-31967. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in samtools htslib up to 1.21.0/1.22.1/1.23 and classified as critical. Affected is the function bgzf_index_load_hfile of the component GZI File Parser. Such manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-31970. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability classified as critical has been found in samtools htslib up to 1.21.0/1.22.1/1.23. This affects the function cram_byte_array_stop_decode_char. The manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2026-31969. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in SAMtools up to 1.21.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-31972. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability labeled as problematic has been found in samtools htslib up to 1.21.0/1.22.1/1.23. This affects the function cram_decode_slice. The manipulation results in out-of-bounds read.
This vulnerability is identified as CVE-2026-31965. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in samtools htslib up to 1.21.0/1.22.1/1.23. This vulnerability affects unknown code. This manipulation causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-31968. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability marked as critical has been reported in Python CPython up to 3.14.x. Affected by this vulnerability is the function pkgutil.get_data. The manipulation of the argument resource leads to path traversal.
This vulnerability is listed as CVE-2026-3479. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Google Chrome. The impacted element is an unknown function of the component Skia. Such manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-3909. The attack can be executed remotely. Additionally, an exploit exists.
You should upgrade the affected component.
The U.K. government will try out various social media restrictions on certain families as part of a pilot program as it mulls a potential social media ban for teens.
The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI and claiming to have stolen data from hundreds of thousands of devices during the attack. [...]
A vulnerability was found in Mozilla Firefox up to 148. It has been declared as critical. Affected is an unknown function of the component Canvas2D. Such manipulation leads to memory corruption.
This vulnerability is documented as CVE-2026-4685. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 148. Impacted is an unknown function of the component WebRender. Performing a manipulation results in use after free.
This vulnerability is identified as CVE-2026-4684. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-4538. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The project was informed of the problem early through a pull request but has not reacted yet.
A vulnerability classified as critical has been found in Apple Safari, macOS, visionOS, iOS and iPadOS up to 26.2. This impacts an unknown function. This manipulation causes enforcement of behavioral workflow.
This vulnerability appears as CVE-2026-20660. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.