A vulnerability classified as problematic has been found in Keycloak on Red Hat. This vulnerability affects unknown code of the component JWT Handler. This manipulation of the argument azp causes origin validation error.
This vulnerability is handled as CVE-2026-37977. The attack can be initiated remotely. There is not any exploit available.
A vulnerability described as critical has been identified in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection.
This vulnerability is known as CVE-2026-5675. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability, which was classified as problematic, has been found in Rack up to 2.2.22/3.1.20/3.2.5. The affected element is the function Rack::Utils. This manipulation causes resource consumption.
This vulnerability appears as CVE-2026-34826. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability was found in mbed TLS up to 2.19.0/3.6.5/4.0.0. It has been rated as critical. Affected by this issue is some unknown functionality. This manipulation causes memory corruption.
The identification of this vulnerability is CVE-2026-34877. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as critical was found in OpenSSH up to 10.2. This affects an unknown part of the component scp. Executing a manipulation can lead to preservation of permissions.
This vulnerability appears as CVE-2026-35385. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as problematic was found in Rack up to 2.2.22/3.1.20/3.2.5. Impacted is the function Rack::Directory of the component Regular Expression Handler. The manipulation results in permissive regular expression.
This vulnerability is reported as CVE-2026-34763. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability was found in Rack up to 2.2.22/3.1.20/3.2.5. It has been declared as problematic. Affected by this vulnerability is the function Rack::Sendfile of the component Regular Expression Handler. The manipulation of the argument X-Accel-Mapping results in permissive regular expression.
This vulnerability was named CVE-2026-34830. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in OpenSSH up to 10.2. The affected element is an unknown function. The manipulation results in incorrect control flow.
This vulnerability is cataloged as CVE-2026-35387. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as problematic has been found in OpenSSH up to 10.2. The impacted element is the function ssh_config of the component Command Line Handler. This manipulation causes incorrect behavior order.
This vulnerability is registered as CVE-2026-35386. The attack needs to be launched locally. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in OpenSSH up to 10.2. This affects the function authorized_keys of the component Certificate Handler. Such manipulation leads to incorrect control flow.
This vulnerability is referenced as CVE-2026-35414. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.