DINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government's encrypted messaging platform. [...]
Google fixed a new Chrome zero-day, tracked as CVE-2026-11645, in the V8 JavaScript engine, which is already being exploited in the wild. Google released emergency updates to address a new Chrome zero-day vulnerability, tracked as CVE-2026-11645, that has been exploited in the wild. This flaw is the fifth Chrome zero-day that is being exploited in […]
A vulnerability has been found in Red Hat Ansible Automation Platform 2 and classified as critical. Affected by this issue is some unknown functionality of the component YAML File Handler. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-52902. The attack needs to be performed locally. There is not any exploit available.
A vulnerability, which was classified as critical, was found in Dell iDRAC Tools 11.3.0.0. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to link following.
This vulnerability is registered as CVE-2026-28262. The attack needs to be launched locally. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as very critical, has been found in Siemens SINEC INS up to 1.0 SP2 Update 5. Affected is an unknown function. Performing a manipulation results in execution with unnecessary privileges.
This vulnerability is cataloged as CVE-2026-46748. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in Skilja Vinna Process Monitor up to 4.0.5. This impacts an unknown function of the component Access Token Handler. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-41031. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Siemens SINEC INS up to 1.0 SP2 Update 5. This affects an unknown function of the file /api/sftp/uploadFiles. This manipulation causes path traversal: '/dir/../filename'.
This vulnerability is tracked as CVE-2026-46747. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability marked as critical has been reported in Nemon Trade Energy and Trade Energy CRM 2.95.55. The affected element is an unknown function. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-10731. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as problematic has been found in wpmessiah Prime Elementor Addons Plugin up to 1.3.3 on WordPress. Impacted is the function wp_kses_post. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-8677. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in Systerel S2OPC up to 1.7.2. This issue affects some unknown processing. Performing a manipulation results in improper check for certificate revocation.
This vulnerability was named CVE-2026-6899. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in ETHER Catalyst::Plugin::Authentication up to 0.10_026 on Perl. This vulnerability affects unknown code of the component Session ID Cookie Handler. Such manipulation leads to session fixiation.
This vulnerability is uniquely identified as CVE-2009-10007. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.