A vulnerability classified as problematic has been found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/agents.csv of the component Research Export. Performing a manipulation results in information disclosure.
This vulnerability is known as CVE-2026-12203. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. Applying a patch is the recommended action to fix this issue.
The vendor confirms: "Research export endpoints now require an authenticated agent with the research_exports capability".
A vulnerability described as problematic has been identified in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulation of the argument CSS class name leads to cross site scripting.
This vulnerability is traded as CVE-2026-12202. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability marked as critical has been reported in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues.
This vulnerability appears as CVE-2026-12201. The attack requires local access. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability described as problematic has been identified in IObit Malware Fighter 12.1.0. This vulnerability affects unknown code of the component IMFForceDelete Driver. Executing a manipulation can lead to privilege escalation.
This vulnerability is tracked as CVE-2025-26125. The attack is only possible within the local network. No exploit exists.
A vulnerability labeled as critical has been found in Iptanus File Upload Plugin up to 5.1.6 on WordPress. Affected is an unknown function of the component Setting Handler. The manipulation of the argument duplicatepolicy results in race condition.
This vulnerability is reported as CVE-2025-15546. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown function in the library libeay32.dll.html of the component Header Handler. The manipulation of the argument Authorization leads to stack-based buffer overflow.
This vulnerability is documented as CVE-2026-12200. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.83. It has been rated as problematic. The affected element is an unknown function of the component Private Key Handler. Performing a manipulation results in covert timing channel.
This vulnerability was named CVE-2026-5598. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.19.3. The impacted element is an unknown function of the component apparmor. This manipulation causes privilege escalation.
This vulnerability is handled as CVE-2026-46328. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.19.3. This impacts an unknown function of the component SMC. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-46330. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.0.3. Affected by this vulnerability is an unknown functionality of the component media. The manipulation leads to off-by-one.
This vulnerability is referenced as CVE-2026-52907. The attack needs to be initiated within the local network. No exploit is available.
It is advisable to upgrade the affected component.