A vulnerability described as critical has been identified in Vexa-ai vexa. The affected element is an unknown function of the component HTTP POST Request Handler. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-25883. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in GFI HelpDesk up to 4.99.8. Impacted is the function Controller_Step.InsertSubmit of the component Troubleshooter Module. Performing a manipulation of the argument subject results in cross site scripting.
This vulnerability is identified as CVE-2026-23756. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability identified as critical has been detected in Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6. This vulnerability affects unknown code. This manipulation causes stack-based buffer overflow.
The identification of this vulnerability is CVE-2026-26951. The attack can only be executed locally. There is no exploit available.
A vulnerability categorized as critical has been discovered in stm32duino Arduino_Core_STM32 up to 1.6.x. This affects the function pwm_start. The manipulation results in memory corruption.
This vulnerability was named CVE-2026-26399. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability was found in Doorman 0.1.0/1.0.2. It has been rated as critical. Affected by this issue is the function manage_users of the file /platform/user/. The manipulation of the argument role leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-30269. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Buffalo Link Station 1.85-0.01. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /nasapi. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2025-66954. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in mborgerding kissfft. It has been classified as critical. Affected is the function kiss_fftndr_alloc of the file kiss_fftndr.c. Performing a manipulation results in integer overflow.
This vulnerability is known as CVE-2026-41445. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in OpenMage magento-lts up to 20.16.x and classified as critical. This impacts an unknown function of the component Dataflow Module. Such manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-25525. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Vexa-ai vexa and classified as critical. This affects an unknown function of the file /internal/transcripts/. This manipulation of the argument meeting_id causes missing authentication.
This vulnerability appears as CVE-2026-25058. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in OpenMage magento-lts up to 20.16.x. The impacted element is an unknown function of the component Download Endpoint. The manipulation of the argument sharing_code results in missing authorization.
This vulnerability is reported as CVE-2026-40098. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Dell PowerProtect Data Domain 8.5/8.6. The affected element is an unknown function. The manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-22761. The attack needs to be performed locally. There is not any exploit available.
A vulnerability classified as critical was found in Dell PowerProtect Data Domain 8.5/8.6. Impacted is an unknown function. Executing a manipulation can lead to os command injection.
This vulnerability is registered as CVE-2026-26942. The attack needs to be launched locally. No exploit is available.
A vulnerability classified as critical has been found in Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6. This issue affects some unknown processing. Performing a manipulation results in os command injection.
This vulnerability is cataloged as CVE-2026-26943. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability described as problematic has been identified in PHPGurukul Apartment Visitors Management System 1.1. This vulnerability affects unknown code of the file visitors-form.php. Such manipulation of the argument visname leads to cross site scripting.
This vulnerability is listed as CVE-2026-39112. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as critical has been reported in PHPGurukul Apartment Visitors Management System 1.1. This affects an unknown part of the file forgot-password.php. This manipulation of the argument email causes sql injection.
This vulnerability is tracked as CVE-2026-39111. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability labeled as critical has been found in PHPGurukul Apartment Visitors Management System 1.1. Affected by this issue is some unknown functionality of the file forgot-password.php of the component Forgot Password Handler. The manipulation of the argument contactno results in sql injection.
This vulnerability is identified as CVE-2026-39110. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as critical has been detected in PHPGurukul Apartment Visitors Management System 1.1. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument Username leads to sql injection.
This vulnerability is referenced as CVE-2026-39109. Remote exploitation of the attack is possible. No exploit is available.