A vulnerability, which was classified as critical, was found in JD Cloud JDCOS 4.5.1.r4518. This vulnerability affects the function set_iptv_info of the file /jdcap of the component Service Interface. Executing a manipulation of the argument vid can lead to command injection.
This vulnerability is registered as CVE-2026-7705. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, has been found in Apache Polaris up to 1.4.0. This affects an unknown part. Performing a manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2026-42812. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Apache Polaris up to 1.4.0. Affected by this issue is some unknown functionality. Such manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-42811. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Apache Polaris up to 1.4.0. Affected by this vulnerability is an unknown functionality of the component Asterisk Handler. This manipulation causes escaping of output.
This vulnerability is tracked as CVE-2026-42810. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in Apache Polaris up to 1.4.0. Affected is an unknown function of the component Staged Table Creation. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-42809. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in Frontend File Manager Plugin up to 23.6 on WordPress. This impacts the function wpfm_download of the component Download Endpoint. The manipulation of the argument file_id leads to authorization bypass.
This vulnerability is referenced as CVE-2026-5337. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as critical has been found in KAZUHO Starlet up to 0.31 on Perl. This affects an unknown function of the component Reverse Proxy Handler. Executing a manipulation of the argument Content-Length can lead to http request smuggling.
The identification of this vulnerability is CVE-2026-40561. The attack may be launched remotely. There is no exploit available.
A patch should be applied to remediate this issue.
A vulnerability identified as problematic has been detected in webaways NEX-Forms Plugin up to 9.1.11 on WordPress. The impacted element is the function submit_nex_form of the component POST Parameter Handler. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-5063. The attack may be initiated remotely. There is no available exploit.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux distributions to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-31431 (CVSS score: 7.8), is a case of local privilege escalation (LPE) flaw that could allow an