A vulnerability classified as critical was found in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2026-12187. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability classified as critical has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection.
This vulnerability is handled as CVE-2026-12186. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability described as critical has been identified in LiteSpeed cPanel Plugin up to 2.4.7. This impacts an unknown function. The manipulation results in symlink following.
This vulnerability is known as CVE-2026-54420. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in OpenStack Ironic up to 35.0.1. This affects an unknown function. The manipulation leads to improper removal of sensitive information before storage or transfer.
This vulnerability is traded as CVE-2026-54421. It is possible to initiate the attack remotely. There is no exploit available.
Applying a patch is the recommended action to fix this issue.
A vulnerability labeled as critical has been found in Koha up to 26.05.0. The impacted element is an unknown function of the file reports/catalogue_out.pl of the component Reports Module. Executing a manipulation of the argument strsth2 can lead to sql injection.
This vulnerability appears as CVE-2026-6428. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Nefteprodukttekhnika BUK TS-G Gas Station Automation System up to 2.10.2 on Linux. The affected element is an unknown function of the file /php/ajax-login.php of the component System Configuration Module. Performing a manipulation results in improper authentication.
This vulnerability is reported as CVE-2026-12183. The attack is possible to be carried out remotely. No exploit exists.
Ukrainian national Oleksii Lytvynenko pleaded guilty in the U.S. for his role in Conti ransomware attacks targeting victims worldwide. Oleksii Oleksiyovych Lytvynenko (44), a Ukrainian national extradited from Ireland to the U.S., has pleaded guilty to conspiracy to commit wire fraud for his involvement in the Conti ransomware operation. Prosecutors said he helped conduct attacks […]
A vulnerability classified as critical was found in MediaWiki up to 1.35.6/1.37.2/1.38.0. This impacts the function SpecialCreateAccount::successfulAction of the component Welcome Handler. Such manipulation of the argument Username leads to escaping of output.
This vulnerability is listed as CVE-2022-34911. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Aremis A4N 1.5.0 on Android. This affects an unknown part. This manipulation causes improper authorization.
The identification of this vulnerability is CVE-2022-34908. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as critical has been found in Aremis A4N 1.5.0 on Android. This vulnerability affects unknown code. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2022-34909. The attack can only be performed from a local environment. No exploit is available.