A vulnerability classified as problematic was found in Faceted Search Extension up to 5.6.1/6.6.0/7.0.0 on TYPO3. Affected is an unknown function of the component OOXML Parser. Such manipulation leads to xml external entity reference.
This vulnerability is documented as CVE-2026-46722. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in MLflow up to 3.9.x. This impacts an unknown function of the file /ajax-api of the component Assistant Feature. This manipulation causes origin validation error.
This vulnerability is registered as CVE-2026-2611. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Frontend User Registration Extension up to 13.2.3/14.0.1 on TYPO3. This affects an unknown function. The manipulation results in dynamically-determined object attributes.
This vulnerability is cataloged as CVE-2026-46721. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Apache OFBiz up to 24.09.05. The impacted element is an unknown function. The manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-31387. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Apache OFBiz up to 24.09.05. The affected element is an unknown function. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-31910. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in Apache OFBiz up to 24.09.05. Impacted is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-31906. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Apache OFBiz up to 24.09.05. This issue affects some unknown processing. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-31379. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Apache OFBiz up to 24.09.05. It has been rated as critical. This vulnerability affects unknown code of the component Content Component Operation Handler. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-29226. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Apache OFBiz up to 24.09.05. It has been declared as critical. This affects an unknown part. The manipulation results in code injection.
This vulnerability was named CVE-2026-46586. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Apache OFBiz up to 24.09.05. It has been classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-45187. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in Apache OFBiz up to 24.09.05 and classified as problematic. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to ldap injection.
This vulnerability is handled as CVE-2026-41919. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Apache OFBiz up to 24.09.05 and classified as critical. Affected is an unknown function of the component Email Service. Performing a manipulation results in code injection.
This vulnerability is known as CVE-2026-35086. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in Apache OFBiz up to 24.09.05. This impacts an unknown function. Such manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is traded as CVE-2026-31986. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Apache OFBiz up to 24.09.05. This affects an unknown function. This manipulation causes information disclosure.
This vulnerability appears as CVE-2026-31909. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Apache OFBiz up to 24.09.05. The impacted element is an unknown function. The manipulation results in improper access controls.
This vulnerability is reported as CVE-2026-31388. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Apache OFBiz up to 24.09.05. The affected element is an unknown function of the component Expression Language Statement Handler. The manipulation leads to improper neutralization of special elements used in an expression language statement.
This vulnerability is documented as CVE-2026-31380. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.