A vulnerability categorized as critical has been discovered in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument table/column/xColumn/yColumn can lead to sql injection.
This vulnerability is tracked as CVE-2026-86282. The attack can be launched remotely. Moreover, an exploit is present.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable. A patch should be applied to remediate this issue.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.68/6.18.8. This vulnerability affects the function skb_segment_list. This manipulation causes privilege escalation.
This vulnerability is tracked as CVE-2026-23154. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.8. Affected by this issue is some unknown functionality of the component firewire. Executing a manipulation can lead to race condition.
This vulnerability is handled as CVE-2026-23153. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.68/6.18.8. Affected is the function set_ssp_complete of the component Bluetooth. Such manipulation leads to memory leak.
This vulnerability is traded as CVE-2026-23151. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.8. Affected is an unknown function of the component wifi. The manipulation results in memory corruption.
This vulnerability is identified as CVE-2026-23152. The attack can only be performed from the local network. There is not any exploit available.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.18.8. It has been declared as critical. This vulnerability affects the function drm_gem_change_handle_ioctl of the component drm. Executing a manipulation can lead to privilege escalation.
This vulnerability is registered as CVE-2026-23149. The attack requires access to the local network. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.8. The impacted element is the function nfc_llcp_send_ui_frame. Such manipulation leads to memory leak.
This vulnerability is traded as CVE-2026-23150. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.68/6.18.8. Affected by this vulnerability is the function nvmet_bio_done. Performing a manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-23148. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.18.8. It has been rated as critical. This issue affects the function btrfs_compress_filemap_get_folio. The manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2026-23147. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in Linux Kernel up to 6.18.6. The affected element is the function ext4_xattr_inode_update_ref of the component ext4. Such manipulation leads to improper update of reference count.
This vulnerability is uniquely identified as CVE-2026-23145. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.8. This impacts the function hci_uart_set_proto of the component Bluetooth. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-23146. The attack needs to be initiated within the local network. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.1.161/6.6.121/6.12.66/6.18.6. This affects an unknown function of the file mm/damon/sysfs of the component DAMON Sysfs Interface. Executing a manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2026-23144. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.6. The impacted element is an unknown function of the file drivers/net/virtio_net.c. Performing a manipulation of the argument hash_key_data[] results in uninitialized pointer.
This vulnerability was named CVE-2026-23143. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active […]