A vulnerability described as problematic has been identified in FreeOpcUa. This issue affects some unknown processing. Such manipulation of the argument deleteSubscription leads to uncontrolled memory allocation.
This vulnerability is uniquely identified as CVE-2022-24298. The attack can be launched remotely. No exploit exists.
A vulnerability marked as problematic has been reported in Yannick Lefebvre Modal Dialog Plugin up to 3.5.9 on WordPress. Impacted is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2023-24001. The attack can be initiated remotely. There is not any exploit available.
A vulnerability has been found in DoLogin Security Plugin up to 3.6 on WordPress and classified as problematic. The impacted element is an unknown function of the component Header Handler. This manipulation of the argument X-Forwarded-For causes cross site scripting.
This vulnerability appears as CVE-2023-4549. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability was found in DoLogin Security Plugin up to 3.6 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to authentication bypass by spoofing.
This vulnerability is uniquely identified as CVE-2023-4631. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in Microchip Time Provider 4100 up to 2.4. This vulnerability affects unknown code of the component Software Update Handler. Executing a manipulation can lead to download of code without integrity check.
The identification of this vulnerability is CVE-2025-47904. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in SUSE Rancher up to 2.10.10/2.11.9/2.12.5/2.13.1. It has been classified as critical. This affects an unknown function of the component CLI Login. Performing a manipulation results in improper certificate validation.
This vulnerability is identified as CVE-2025-67601. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, was found in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administrative Interface. Executing a manipulation can lead to execution after redirect.
This vulnerability is handled as CVE-2026-3264. The attack can be executed remotely. Additionally, an exploit exists.
This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in steve-community steve up to 3.11.0. This affects the function getTransaction of the component SOAP Endpoint. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-28230. It is possible to launch the attack remotely. No exploit is available.
It is best practice to apply a patch to resolve this issue.
A vulnerability categorized as problematic has been discovered in wger-project wger up to 2.4. This vulnerability affects the function RepetitionsConfigViewSet/MaxRepetitionsConfigViewSet. Executing a manipulation can lead to authorization bypass.
This vulnerability is handled as CVE-2026-27835. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
A vulnerability was found in kiteworks up to 9.1.x. It has been classified as critical. The affected element is an unknown function. The manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-28269. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability has been found in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1 and classified as critical. This affects an unknown part of the file /api/Security/ of the component Security API. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-3265. The attack is possible to be carried out remotely. Moreover, an exploit is present.
This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, has been found in Google Android 13/14/15/16. This issue affects the function onHeaderDecoded of the file LocalImageResolver.java. The manipulation leads to resource consumption.
This vulnerability is documented as CVE-2025-48631. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in TSplus Remote Access up to 16.0.2.14. It has been classified as problematic. The impacted element is an unknown function. Performing a manipulation results in source code.
This vulnerability was named CVE-2023-31069. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as critical, was found in TSplus Remote Access up to 16.0.2.14. This impacts an unknown function of the file %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.. Such manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2023-31068. The attack can be launched remotely. Moreover, an exploit is present.