A vulnerability marked as critical has been reported in Google Chrome. This vulnerability affects unknown code of the component Angle. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2026-7354. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability described as critical has been identified in Google Chrome. Affected by this issue is some unknown functionality of the component WebRTC. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2026-7336. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Google Chrome. Impacted is an unknown function of the component Animation. This manipulation causes use after free.
The identification of this vulnerability is CVE-2026-7358. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. It has been declared as critical. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql injection.
This vulnerability is tracked as CVE-2026-7409. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. It has been rated as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection.
This vulnerability is listed as CVE-2026-7410. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability categorized as critical has been discovered in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection.
This vulnerability is cataloged as CVE-2026-7416. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in ZachHandley ZMCPTools up to 0.2.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler. The manipulation of the argument dirname leads to path traversal.
This vulnerability is referenced as CVE-2026-7445. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability categorized as critical has been discovered in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection.
This vulnerability is identified as CVE-2026-7446. The attack can be executed remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.5/6.19-rc4. This issue affects the function crypto_alloc_acomp. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-23044. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.5/6.19-rc4. Affected by this issue is the function do_abort_log_replay of the component btrfs. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-23043. The attack can only be initiated within the local network. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.5/6.19-rc4. The affected element is the function idpf_idc_vport_dev_down of the component idpf. This manipulation causes null pointer dereference.
This vulnerability is tracked as CVE-2026-23042. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.5/6.19-rc4. This impacts the function bnxt_init_one of the file drivers/net/ethernet/broadcom/bnxt/bnxt_hwrm.c of the component bnxt_en. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-23041. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.