Posts of last 24 hours
A vulnerability classified as critical has been found in Wikimedia MediaWiki up to 1.45.x/1.45.3/1.44.5/1.43.8. This issue affects some unknown processing of the file includes/Api/ApiChangeAuthenticationData.Php,. This manipulation causes Remote Code Execution.
This vulnerability is tracked as CVE-2026-58029. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/375578
A vulnerability described as problematic has been identified in Wikimedia AbuseFilter up to 1.45.x/1.45.3/1.44.5/1.43.8. This vulnerability affects unknown code of the file includes/Api/QueryAbuseFilters.Php. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-58027. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/375577
A vulnerability marked as problematic has been reported in Wikimedia MediaWiki up to 1.45.x/1.45.3/1.44.5/1.43.8. This affects an unknown part of the file includes/Parser/Parser.Php. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-58026. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/375576
A vulnerability labeled as problematic has been found in Wikimedia MediaWiki up to 1.45.x/1.45.3/1.44.5/1.43.8. Affected by this issue is some unknown functionality of the file includes/Import/WikiImporter.Php. Executing a manipulation can lead to deserialization.
The identification of this vulnerability is CVE-2026-58025. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/375575
A vulnerability identified as problematic has been detected in Wikimedia MediaWiki up to 1.45.x/1.45.3/1.44.5/1.43.8. Affected by this vulnerability is an unknown functionality of the file includes/Api/ApiUserrights.Php. Performing a manipulation results in information disclosure.
This vulnerability was named CVE-2026-58024. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/375574
A vulnerability categorized as problematic has been discovered in guardian language-system up to 119. Affected is an unknown function of the file media.php of the component GET Parameter Handler. Such manipulation of the argument ID leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-34098. The attack can be launched remotely. No exploit exists.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/375573
A vulnerability was found in Control Web Panel 0.9.8.1209. It has been rated as critical. This impacts an unknown function of the component User Endpoint. This manipulation of the argument userRes causes sql injection.
This vulnerability is handled as CVE-2026-57517. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/375572
A vulnerability was found in BPS HTML::Gumbo up to 0.18 on Perl. It has been declared as critical. This affects the function strlen in the library lib/HTML/Gumbo.xs. The manipulation results in type confusion.
This vulnerability is known as CVE-2025-15646. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/375571
A vulnerability was found in Wikimedia UrlShortener up to 1.46.0/1.45.4/1.44.6/1.43.9. It has been classified as critical. The impacted element is an unknown function. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2026-13706. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/375570
A vulnerability was found in NVIDIA Megatron-Bridge on Linux and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to deserialization.
This vulnerability appears as CVE-2026-24245. The attack requires local access. There is no available exploit.
https://vuldb.com/vuln/375569