A vulnerability classified as problematic was found in Arista Edge Threat Management up to 17.4.0. The affected element is an unknown function of the component Web User Interface. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-25624. The attack can be launched remotely. No exploit exists.
A vulnerability classified as critical has been found in jxxghp MoviePilot up to 2.13.3. Impacted is an unknown function of the component Remote Cloud Storage API. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-11416. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in shd101wyy Markdown Preview Enhanced and crossnote. This issue affects the function window.eval. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code.
This vulnerability is registered as CVE-2026-11422. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Altium Enterprise Server up to 8.1.0. This vulnerability affects unknown code of the component Vault Service. Performing a manipulation results in hard-coded credentials.
This vulnerability is cataloged as CVE-2026-11414. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Altium Enterprise Server and 365 up to 8.1.0. This affects an unknown part of the component GraphQL Service. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-11424. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in haxtheweb haxcms-php up to 26.0.0. Affected by this issue is some unknown functionality. This manipulation causes cryptographically weak prng.
This vulnerability is tracked as CVE-2026-46493. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in defenseunicorns uds-identity-config up to 0.26.0. Affected by this vulnerability is an unknown functionality of the component Keycloak Token Endpoint. The manipulation results in improper authentication.
This vulnerability is identified as CVE-2026-46389. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in haxtheweb haxcms-nodejs, video-player and iframe-loader up to 25.x. It has been rated as problematic. Affected is an unknown function. The manipulation of the argument src leads to cross site scripting.
This vulnerability is referenced as CVE-2026-46396. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in Altium Enterprise Server and 365 up to 8.1.0. It has been declared as critical. This impacts an unknown function of the component Projects Service Download Endpoint. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-11431. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Arista Edge Threat Management up to 17.4.0. It has been classified as critical. This affects an unknown function. Performing a manipulation results in os command injection.
This vulnerability was named CVE-2026-25623. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Arista Edge Threat Management up to 17.4.0 and classified as critical. The impacted element is an unknown function of the component User Interface. Such manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-25622. The attack can be launched remotely. No exploit exists.
A vulnerability has been found in Arista Edge Threat Management 17.4.0 and classified as critical. The affected element is an unknown function of the component Captive Portal Application Framework. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-25620. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as critical, was found in Arista Edge Threat Management 17.4.0. Impacted is an unknown function. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-25621. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as problematic, has been found in haxtheweb haxcms-nodejs and video-player up to 25.x. This issue affects some unknown processing. The manipulation of the argument Source leads to cross site scripting.
This vulnerability is traded as CVE-2026-46496. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in haxtheweb haxcms-nodejs and haxcms-php up to 25.x. This vulnerability affects unknown code. Executing a manipulation can lead to server-side request forgery.
This vulnerability appears as CVE-2026-46393. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromDhcpListClient of the component HTTP Handler. Performing a manipulation of the argument page results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-36785. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability described as problematic has been identified in AsyncHttpClient async-http-client up to 2.14.x/3.0.9. Affected by this issue is the function propagatedHeaders of the file Redirect30xInterceptor.java of the component Session Cookie Handler. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-45300. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.