A vulnerability identified as critical has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is uniquely identified as CVE-2026-90510. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability categorized as critical has been discovered in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials.
This vulnerability is handled as CVE-2026-90509. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. It has been rated as problematic. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization.
This vulnerability is known as CVE-2026-90508. Attacking locally is a requirement. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. It has been declared as critical. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2026-90507. The attack may be launched remotely. Furthermore, there is an exploit available.
This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. It has been classified as problematic. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability appears as CVE-2026-90506. The attack may be initiated remotely. In addition, an exploit is available.
This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46 and classified as problematic. This affects the function doUpdateLicenseKey. The manipulation results in race condition. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is reported as CVE-2026-90505. The attack can be launched remotely. Moreover, an exploit is present.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46 and classified as critical. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is documented as CVE-2026-90504. The attack can be initiated remotely. Additionally, an exploit exists.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure.
This vulnerability is registered as CVE-2026-90503. The attack needs to be launched locally. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
25 ведущих математиков предупреждают, что корпоративная гонка за громкими доказательствами может разрушить проверку результатов, авторство и сам процесс научного поиска.