A vulnerability was found in Frappe ERPNext up to 15.101.x/16.10.x. It has been declared as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-44448. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. Affected by this issue is some unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-6073. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability marked as problematic has been reported in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. This issue affects some unknown processing of the component Analytics Dashboard. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-7377. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Northern.tech CFEngine Enterprise up to 3.21.7/3.24.2/3.26.x. This affects an unknown part. The manipulation results in improper access controls.
This vulnerability is reported as CVE-2026-24711. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in coleam00 Archon 0.1.0. This affects an unknown function of the component UI Including API. The manipulation results in code injection.
This vulnerability was named CVE-2025-69443. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in OpenBao up to 2.5.2 and classified as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to improper removal of sensitive information before storage or transfer.
This vulnerability is tracked as CVE-2026-42186. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in bytecodealliance wasmtime up to 36.0.7/43.0.1/44.0.0. It has been rated as problematic. This issue affects some unknown processing of the component WebAssembly Module. This manipulation causes allocation of resources.
This vulnerability is registered as CVE-2026-44216. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in Apache Commons Configuration up to 2.14.x. The impacted element is an unknown function. Such manipulation leads to uncontrolled recursion.
This vulnerability is traded as CVE-2026-45205. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in GitLab Enterprise Edition up to 18.9.6/18.10.5/18.11.2. It has been declared as problematic. The impacted element is an unknown function of the component File Handler. The manipulation results in deserialization.
This vulnerability is known as CVE-2026-1184. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.9.6/18.10.5/18.11.2. It has been rated as problematic. This affects the function read_api of the component Private Project Handler. This manipulation causes business logic errors.
This vulnerability is handled as CVE-2026-1322. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies
Poland told officials to stop using the popular instant messaging app Signal after cyberattacks targeted government accounts. Poland has instructed government officials to stop using Signal for sensitive communications and move to a state-developed alternative. The decision follows repeated cyberattacks targeting Signal accounts belonging to politicians, military personnel, and public servants. Officials believe the campaigns […]