A vulnerability was found in CoreWorxLab CAAL up to 1.6.0. It has been rated as critical. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation causes server-side request forgery.
This vulnerability is registered as CVE-2026-8725. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Dataease 2.10.20. It has been declared as critical. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-8724. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure.
OpenAI said the TanStack supply chain attack compromised two employee devices and exposed credentials from code repositories. OpenAI confirmed that the recent TanStack supply chain attack compromised two employee devices and exposed credential material stored in internal source code repositories. The incident began after the TeamPCP hacking group abused weaknesses in the package publishing process […]
A vulnerability classified as critical was found in Google Chrome. This vulnerability affects unknown code of the component InterestGroups. Executing a manipulation can lead to sandbox issue.
This vulnerability is handled as CVE-2026-7916. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in dnsmasq 2.92rel2. This affects the function extract_addresses of the component DNS Response Handler. Such manipulation leads to out-of-bounds write.
This vulnerability is listed as CVE-2026-5172. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as critical, has been found in Google Chrome on Android. Affected by this issue is some unknown functionality of the component DevTools. Performing a manipulation results in improper input validation.
This vulnerability was named CVE-2026-7915. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Google Chrome on Windows. This impacts an unknown function of the component Accessibility. The manipulation leads to type confusion.
This vulnerability is documented as CVE-2026-7914. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, was found in dnsmasq 2.92rel2. The affected element is an unknown function of the component RFC 7871 Client Subnet Information Handler. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-4893. The attack can be launched remotely. No exploit exists.