Hasbro suffers a cyberattack, disrupting some operations; the company is probing the scope and potential data compromise. Toy giant Hasbro reported a cyberattack on Wednesday that disrupted certain company operations. The firm is investigating the full extent of the incident, including whether any files or sensitive data were compromised, as it works to restore normal […]
A vulnerability was found in Oracle Communications Services Gatekeeper 7.0. It has been rated as critical. Affected is an unknown function of the component Policy service. Performing a manipulation results in command injection.
This vulnerability is reported as CVE-2021-23337. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in Oracle JD Edwards EnterpriseOne Tools. This affects an unknown function of the component E1 Dev Platform Tech - Cloud. The manipulation leads to command injection.
This vulnerability is referenced as CVE-2021-23337. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59. Impacted is an unknown function of the component Elastic Search. The manipulation results in command injection.
This vulnerability is known as CVE-2021-23337. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in Oracle Retail Customer Management and Segmentation Foundation 19.0 and classified as critical. This affects an unknown part of the component Security. The manipulation results in command injection.
This vulnerability is known as CVE-2021-23337. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in Oracle Communications Cloud Native Core Binding Support Function 1.9.0. It has been classified as critical. This affects an unknown function of the component Binding Support Function. This manipulation causes command injection.
This vulnerability is registered as CVE-2021-23337. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Oracle Banking Trade Finance Process Management 14.2/14.3/14.5. This affects an unknown part of the component Lodash. This manipulation causes command injection.
This vulnerability appears as CVE-2021-23337. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Tenda G103 1.0.0.5. It has been rated as critical. The impacted element is the function action_set_net_settings of the file gpon.lua of the component Setting Handler. Performing a manipulation of the argument authLoid/authLoidPassword/authPassword/authSerialNo/authType/oltType/usVlanId/usVlanPriority results in command injection.
This vulnerability is cataloged as CVE-2026-5339. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability categorized as problematic has been discovered in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw.cpp of the component TIFF/NEF. Executing a manipulation of the argument load_flags/raw_width can lead to out-of-bounds read.
This vulnerability is registered as CVE-2026-5342. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Textpattern up to 4.9.1. It has been classified as critical. Affected by this vulnerability is the function mt_uploadImage of the file rpc/TXP_RPCServer.php of the component XML-RPC Handler. The manipulation of the argument file.name leads to path traversal.
This vulnerability is referenced as CVE-2026-5344. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor confirmed the issue and will provide a fix in the upcoming release.
A vulnerability identified as critical has been detected in Agno up to 2.3.23. Affected is the function eval of the component Parameter Handler. The manipulation of the argument field_type leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is documented as CVE-2026-35002. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the component image-to-base64 Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-5346. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical has been found in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setup.cgi. This manipulation of the argument wl_enrolee_pin causes os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability appears as CVE-2026-5351. The attack may be initiated remotely. In addition, an exploit is available.
The vendor confirms, that "[t]he product in question (...) has been discontinued and end of life since June 23, 2011, that is more than 14 years ago. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on our website's product support page and notify customers who registered their products with us."
A vulnerability categorized as critical has been discovered in Balena Etcher up to 2.1.3 on Windows. Affected is an unknown function. The manipulation results in race condition.
This vulnerability is identified as CVE-2026-30332. The attack is only possible with local access. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability labeled as critical has been found in Oracle Banking Credit Facilities Process Management 14.2/14.3/14.5. Affected is an unknown function of the component Lodash. Executing a manipulation can lead to command injection.
This vulnerability is registered as CVE-2021-23337. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Oracle Banking Extensibility Workbench 14.2/14.3/14.5. Affected by this vulnerability is an unknown functionality of the component Lodash. The manipulation leads to command injection.
This vulnerability is documented as CVE-2021-23337. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability described as critical has been identified in Oracle Banking Supply Chain Finance 14.2/14.3/14.5. Affected by this issue is some unknown functionality of the component Lodash. The manipulation results in command injection.
This vulnerability is reported as CVE-2021-23337. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.