A vulnerability was found in givanz Vvveb up to 1.0.8.2. It has been classified as problematic. The impacted element is an unknown function. The manipulation leads to insecure default initialization of resource.
This vulnerability is traded as CVE-2026-41931. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, was found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs/api/v2/patient-records of the component API Endpoint. The manipulation results in missing authentication.
This vulnerability is identified as CVE-2026-8031. The attack can be executed remotely. Additionally, an exploit exists.
You should upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability classified as critical has been found in givanz Vvveb up to 1.0.8.1. Affected by this issue is some unknown functionality. The manipulation leads to missing authentication.
This vulnerability is listed as CVE-2026-41930. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in givanz Vvveb up to 1.0.8.1. This vulnerability affects unknown code. This manipulation causes unrestricted upload.
This vulnerability is registered as CVE-2026-41938. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in ZTE ZXHN H298A 1.1. Affected by this issue is some unknown functionality of the component Router Web Interface. Executing a manipulation can lead to information disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2026-34474. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. This issue affects some unknown processing. Such manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-0300. The attack can be executed remotely. There is not any exploit available.
A patch for the bug, tracked as CVE-2026-0300, has not been published yet and Palo Alto Networks said it will be included in releases over the next two weeks.
A vulnerability labeled as critical has been found in weDevs WP User Frontend Plugin up to 4.3.1 on WordPress. This affects an unknown function. Such manipulation leads to missing authorization.
This vulnerability is traded as CVE-2026-42412. The attack may be launched remotely. There is no exploit available.
A vulnerability categorized as problematic has been discovered in CDAC-Noida e-Sushrut Hospital Management Information System. The affected element is an unknown function of the component API. The manipulation results in cleartext transmission of sensitive information.
This vulnerability is reported as CVE-2026-42514. The attack can be launched remotely. No exploit exists.
A vulnerability was found in WSO2 Identity Server. It has been declared as problematic. This issue affects some unknown processing of the component Authentication Endpoint. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2025-10503. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability has been found in CRM Sistemas de Fidelización MegaCMS 12.0.0 and classified as critical. This issue affects some unknown processing of the file /web_comunications/cms/get_provincias of the component POST Request Handler. Performing a manipulation of the argument id_territorio results in sql injection.
This vulnerability is identified as CVE-2026-3325. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in Brainstorm Force SureForms Pro Plugin up to 2.8.0 on WordPress and classified as critical. This affects an unknown part. Such manipulation leads to missing authorization.
This vulnerability is listed as CVE-2026-42377. The attack may be performed from remote. There is no available exploit.
Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist them in a network capable of carrying out distributed denial-of-service (DDoS) attacks.
Hunt.io, which detailed the malware, said it made the discovery after identifying an exposed directory on a Netherlands-hosted
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.6.135/6.12.82/6.18.23/6.19.13/7.0.0. This vulnerability affects the function platform_get_irq_byname. Executing a manipulation can lead to privilege escalation.
This vulnerability is registered as CVE-2026-43072. The attack requires access to the local network. No exploit is available.
The affected component should be upgraded.
A vulnerability classified as critical was found in Linux Kernel up to 6.18.20/6.19.10. This issue affects the function __mark_reg_known of the component bpf. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2026-43070. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.135/6.12.82/6.18.23/6.19.13/7.0.0. This affects the function dcache_init of the component dcache. Performing a manipulation results in out-of-bounds read.
This vulnerability is cataloged as CVE-2026-43071. The attack must originate from the local network. There is no exploit available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.19.10. This vulnerability affects the function download_firmware of the file drivers/bluetooth/hci_ll.c of the component Bluetooth. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2026-43069. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.19.10. Affected by this issue is the function ext4_fc_replay_inode of the component ext4. Executing a manipulation can lead to memory leak.
This vulnerability is handled as CVE-2026-43066. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.