A vulnerability, which was classified as critical, has been found in Daylight Studio FuelCMS 1.5.2. Affected is an unknown function of the component Password Reset Handler. Performing a manipulation results in weak password recovery.
This vulnerability is identified as CVE-2026-30458. The attack can be initiated remotely. There is not any exploit available.
A vulnerability classified as problematic was found in farisc0de Uploady up to 3.1.1. This impacts an unknown function of the component Filename Handler. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-33653. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in ory polis up to 26.1.x. This affects an unknown function. This manipulation causes improper neutralization of alternate xss syntax.
The identification of this vulnerability is CVE-2026-33506. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in staffwiki 7.0.1.19219. The impacted element is an unknown function of the file wff_cols_pref.css.aspx. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-29969. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as critical has been reported in PinchTab up to 0.8.3. The affected element is an unknown function of the file /tasks. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-33619. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability labeled as problematic has been found in PrestaShop up to 8.2.4/9.0.x. Impacted is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-33673. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Lychee up to 7.5.0. This issue affects the function Photo::fromUrl. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-33537. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Grafana OSS up to 11.6.14/12.1.10/12.2.8/12.3.6/12.4.1. This vulnerability affects unknown code. Such manipulation leads to uncontrolled memory allocation.
This vulnerability is traded as CVE-2026-33375. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Automated Logout up to 1.6.x/2.0.1 on Drupal. It has been rated as problematic. This affects an unknown part. This manipulation causes cross-site request forgery.
This vulnerability appears as CVE-2026-4393. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability was found in Calculation Fields up to 1.0.3 on Drupal. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-3528. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in TP-Link TL-WR841N -/0.9.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component UPnP. The manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-3622. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Unpublished Node Permissions up to 1.6.x on Drupal and classified as critical. Affected is an unknown function. Executing a manipulation can lead to incorrect authorization.
This vulnerability is registered as CVE-2026-4933. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Grafana Tempo 2.10.3 and classified as problematic. This impacts an unknown function of the file /status/config. Performing a manipulation results in missing encryption of sensitive data.
This vulnerability is cataloged as CVE-2026-28377. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in File Access Fix up to 1.1.x on Drupal. This affects an unknown function. Such manipulation leads to incorrect authorization.
This vulnerability is listed as CVE-2026-3526. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in File Access Fix up to 1.1.x on Drupal. The impacted element is an unknown function. This manipulation causes incorrect authorization.
This vulnerability is tracked as CVE-2026-3525. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in PrestaShop up to 8.2.4/9.0.x. The affected element is an unknown function. The manipulation results in improper use of validation framework.
This vulnerability is identified as CVE-2026-33674. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Google Analytics GA4 up to 1.1.13 on Drupal. Impacted is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-3529. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in PinchTab up to 0.8.5. This issue affects some unknown processing of the file /wait. Executing a manipulation can lead to code injection.
The identification of this vulnerability is CVE-2026-33622. The attack may be launched remotely. There is no exploit available.
A vulnerability marked as critical has been reported in OpenID Connect OAuth client up to 1.4.x on Drupal. This vulnerability affects unknown code. Performing a manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-3530. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.