A vulnerability labeled as critical has been found in dart-lang sdk and flutter. This affects an unknown function. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-27704. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in ensdomains ens-contracts up to 1.6.2. This vulnerability affects unknown code. The manipulation results in improper verification of cryptographic signature.
This vulnerability is known as CVE-2026-22866. It is possible to launch the attack remotely. No exploit is available.
It is best practice to apply a patch to resolve this issue.
A vulnerability labeled as problematic has been found in Nokia Impact up to 19.11.2.10-202. The affected element is an unknown function of the file /ui/rest-proxy/entity/import. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2021-35486. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as critical has been found in Octopus Deploy Octopus Server up to 2025.3.14760/2025.4.10408. Affected by this vulnerability is an unknown functionality of the component New API Key Handler. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-3236. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in astroidframe.work Astroid Template Framework 2.0.0-3.3.10. Affected by this issue is some unknown functionality. Executing a manipulation can lead to unrestricted upload.
The identification of this vulnerability is CVE-2026-21628. The attack may be launched remotely. There is no exploit available.
A vulnerability identified as problematic has been detected in Python-Markdown up to 3.8/3.8.1. This affects the function html.parser.HTMLParser. Performing a manipulation results in denial of service.
This vulnerability is reported as CVE-2025-69534. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in stellarwp Events Calendar Plugin up to 6.15.17 on WordPress. It has been classified as critical. This affects the function ajax_create_import. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-3585. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Gen Digital Avira Internet Security up to 1.1.109.1990. It has been declared as critical. Affected is an unknown function of the component Software Updater. The manipulation results in link following.
This vulnerability is cataloged as CVE-2026-27748. The attack must be initiated from a local position. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Gen Digital Avira Internet Security up to 1.1.109.1990. Affected by this issue is some unknown functionality of the component Optimizer. Such manipulation leads to time-of-check time-of-use.
This vulnerability is documented as CVE-2026-27750. The attack needs to be performed locally. There is not any exploit available.
A vulnerability labeled as problematic has been found in admidio up to 5.0.5. Affected is the function possibleToParticipate of the file modules/events/events_function.php of the component User Management Handler. Such manipulation of the argument user_uuid leads to authorization bypass.
This vulnerability is listed as CVE-2026-30927. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in WWBN AVideo up to 24.x. Affected by this vulnerability is an unknown functionality of the file /objects/playlistsFromUser.json.php. Performing a manipulation results in missing authentication.
This vulnerability is cataloged as CVE-2026-30885. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability marked as very critical has been reported in oneuptime up to 10.0.19. This vulnerability affects the function this.constructor.constructor. The manipulation leads to exposed dangerous routine.
This vulnerability is listed as CVE-2026-30921. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.