A vulnerability was found in ahmadgb GeekyBot Plugin up to 1.2.2 on WordPress and classified as critical. This vulnerability affects unknown code of the component ZIP File Handler. Executing a manipulation can lead to missing authorization.
This vulnerability appears as CVE-2026-5294. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.
A vulnerability has been found in roxnor EmailKit Plugin up to 1.6.5 on WordPress and classified as critical. This affects the function create_template of the file wp-content/uploads/emailkit/templates/. Performing a manipulation of the argument real_path results in path traversal.
This vulnerability is reported as CVE-2026-5957. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in timwhitlock Loco Translate Plugin up to 2.8.2 on WordPress. Affected by this issue is the function findSourceFile. Such manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-1921. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Oracle MCP Server Helper Tool up to 1.0.156. Affected by this vulnerability is an unknown functionality. This manipulation causes privilege escalation.
This vulnerability is registered as CVE-2026-35228. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability marked as critical has been reported in n8n-io n8n up to 1.123.32/2.17.4. The affected element is an unknown function. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2026-42226. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability described as problematic has been identified in n8n-io n8n up to 1.123.31/2.17.3/2.18.0. The impacted element is an unknown function. Such manipulation of the argument repository leads to authorization bypass.
This vulnerability is documented as CVE-2026-42227. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in n8n-io n8n up to 1.123.31/2.17.3/2.18.0 and classified as critical. The impacted element is an unknown function of the component Oracle Database Node Select Operation. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2026-42233. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in n8n-io n8n up to 1.123.31/2.17.3/2.18.0. This affects an unknown part. Executing a manipulation can lead to code injection.
This vulnerability is registered as CVE-2026-42234. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability classified as critical was found in FasterXML jackson-databind up to 2.9.10.3. Affected by this vulnerability is an unknown functionality. The manipulation results in deserialization (Serialized).
This vulnerability is known as CVE-2020-11112. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in FasterXML jackson-databind up to 2.9.10.3. Affected by this issue is some unknown functionality. This manipulation causes deserialization (Serialized).
This vulnerability is handled as CVE-2020-11113. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in FasterXML jackson-databind up to 2.9.10.3. This issue affects some unknown processing of the component org.springframework.aop.config.MethodLocatingFactoryBean. The manipulation results in deserialization.
This vulnerability was named CVE-2020-11619. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in FasterXML jackson-databind up to 2.9.10.4. Affected is an unknown function of the component oadd.org.apache.xalan.lib.sql.JNDIConnectionPool. The manipulation leads to deserialization (Serialized).
This vulnerability is listed as CVE-2020-14060. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
A vulnerability marked as critical has been reported in FasterXML jackson-databind up to 2.9.10.4. Affected by this issue is some unknown functionality of the component com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool. This manipulation causes deserialization (Serialized).
This vulnerability is registered as CVE-2020-14062. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in Oracle Retail Service Backbone 14.1/15.0/16.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component RSB kernel. Such manipulation leads to deserialization.
This vulnerability is listed as CVE-2020-9546. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability identified as problematic has been detected in FasterXML jackson-databind. Affected is an unknown function of the component Serialization Gadget Handler. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2020-35728. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.