A vulnerability was found in GALAYOU Y4 1.0.0. It has been classified as critical. Impacted is an unknown function of the component Web Server. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2026-12192. The attack is only possible within the local network. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Comma AI Openpilot 0.11 and classified as critical. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization.
This vulnerability is identified as CVE-2026-12191. The attack is only possible with local access. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android and classified as problematic. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme.
This vulnerability is referenced as CVE-2026-12190. The attack can only be performed from a local environment. No exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, was found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to improper authorization in handler for custom url scheme.
The identification of this vulnerability is CVE-2026-12189. The attack can only be executed locally. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, has been found in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/controllers/concerns/grit/core/grit_entity_controller.rb of the component GritEntityController. Performing a manipulation results in sql injection.
This vulnerability was named CVE-2026-12188. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical was found in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2026-12187. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability classified as critical has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection.
This vulnerability is handled as CVE-2026-12186. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability described as critical has been identified in LiteSpeed cPanel Plugin up to 2.4.7. This impacts an unknown function. The manipulation results in symlink following.
This vulnerability is known as CVE-2026-54420. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in OpenStack Ironic up to 35.0.1. This affects an unknown function. The manipulation leads to improper removal of sensitive information before storage or transfer.
This vulnerability is traded as CVE-2026-54421. It is possible to initiate the attack remotely. There is no exploit available.
Applying a patch is the recommended action to fix this issue.
A vulnerability labeled as critical has been found in Koha up to 26.05.0. The impacted element is an unknown function of the file reports/catalogue_out.pl of the component Reports Module. Executing a manipulation of the argument strsth2 can lead to sql injection.
This vulnerability appears as CVE-2026-6428. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Nefteprodukttekhnika BUK TS-G Gas Station Automation System up to 2.10.2 on Linux. The affected element is an unknown function of the file /php/ajax-login.php of the component System Configuration Module. Performing a manipulation results in improper authentication.
This vulnerability is reported as CVE-2026-12183. The attack is possible to be carried out remotely. No exploit exists.