A vulnerability has been found in sysadminsmedia homebox 0.20.1/0.24.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Response Body Handler. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-27600. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in devcode-it openstamanager up to 2.9.8. It has been declared as problematic. This vulnerability affects the function htmlspecialchars of the component GET Parameter Handler. The manipulation of the argument righe results in cross site scripting.
This vulnerability was named CVE-2026-24415. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Dell Command up to 4.6.x. It has been rated as problematic. This issue affects some unknown processing. This manipulation causes uncontrolled search path.
The identification of this vulnerability is CVE-2026-24502. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability identified as problematic has been detected in glpi-project glpi-inventory-plugin up to 1.6.5. The affected element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-25590. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability described as problematic has been identified in langgenius dify up to 1.11.1. This impacts an unknown function of the component Mermaid Diagram Handler. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-21866. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.