A vulnerability classified as critical has been found in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the file /sbin/jdcweb_rpc. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2026-11413. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, has been found in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks of the component Blocks Plugin. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-11434. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID leads to sql injection.
This vulnerability is traded as CVE-2026-11435. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Mage AI up to 0.9.79 and classified as problematic. This impacts the function useMutation of the file mage_ai/frontend/components/Sessions/SignForm/index.tsx of the component Sign-in Flow. Performing a manipulation of the argument query.redirect_url results in cross site scripting.
This vulnerability is known as CVE-2026-11436. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in perfree go-fastdfs-web up to 1.3.7 and classified as critical. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2026-11437. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, has been found in Google Chrome on Windows. This affects an unknown function of the component ANGLE. Performing a manipulation results in integer overflow.
This vulnerability is reported as CVE-2026-10999. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability has been found in Google Chrome and classified as problematic. Affected is an unknown function of the component Payments. The manipulation leads to clickjacking.
This vulnerability is traded as CVE-2026-11001. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability was found in theonedev onedev up to 15.0.5. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromId leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-11438. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability identified as critical has been detected in Google Chrome. Impacted is an unknown function of the component Autofill. The manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-11002. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Google Chrome. This issue affects some unknown processing of the component Dawn. Executing a manipulation can lead to out-of-bounds read.
The identification of this vulnerability is CVE-2026-11006. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability has been found in Google Chrome and classified as problematic. This affects an unknown part of the component ANGLE. This manipulation causes out-of-bounds read.
This vulnerability appears as CVE-2026-11004. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability was found in Google Chrome on Android and classified as critical. The impacted element is an unknown function of the component WebShare. Such manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-11010. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Google Chrome on Android. This affects an unknown part of the component Serial. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-11012. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in Google Chrome on Windows. It has been declared as critical. This affects an unknown part of the component USB. Such manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-11009. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in theonedev onedev up to 15.0.5. It has been declared as critical. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. The manipulation of the argument project.parentId results in improper authorization.
This vulnerability was named CVE-2026-11439. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Open vSwitch 3.6.90. It has been declared as problematic. Affected by this issue is the function udpif_set_threads. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2026-36499. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as critical, has been found in Microsoft 365 Copilot. The impacted element is an unknown function. Performing a manipulation results in command injection.
This vulnerability is cataloged as CVE-2026-42824. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.
A vulnerability was found in theonedev onedev up to 15.0.5. It has been rated as critical. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the argument project.defaultBranch causes improper authorization.
The identification of this vulnerability is CVE-2026-11440. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.