A vulnerability was found in e107 CMS up to 2.3.4. It has been rated as problematic. Affected by this vulnerability is the function session_handler::check. Performing a manipulation results in cross-site request forgery.
This vulnerability was named CVE-2026-46620. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability was found in e107 CMS up to 2.3.3. It has been declared as critical. Affected is an unknown function. Such manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-43936. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in e107 CMS up to 2.3.3. It has been classified as critical. This impacts an unknown function of the component Header Handler. This manipulation of the argument Host causes improper input validation.
This vulnerability is handled as CVE-2026-43935. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in e107 CMS up to 2.3.3 and classified as critical. This affects an unknown function. The manipulation results in improper access controls.
This vulnerability is known as CVE-2026-43934. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability has been found in FastNetMon Community Edition up to 1.2.9 and classified as problematic. The impacted element is the function decode_mp_reach_ipv6 of the file src/bgp_protocol.cpp. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2026-48688. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability, which was classified as critical, was found in FastNetMon Community Edition up to 1.2.9. The affected element is the function decode_bgp_subnet_encoding_ipv4_raw of the file src/bgp_protocol.cpp of the component BGP NLRI Decoder. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2026-48686. The attacker needs to be present on the local network. There is no available exploit.
A vulnerability, which was classified as problematic, has been found in FastNetMon Community Edition up to 1.2.9. Impacted is the function process_netflow_v9_options_template of the file src/netflow_plugin/netflow_v9_collector.cpp. Performing a manipulation of the argument options results in out-of-bounds read.
This vulnerability is reported as CVE-2026-48684. The attacker must have access to the local network to execute the attack. No exploit exists.
A vulnerability classified as problematic was found in FastNetMon Community Edition up to 1.2.9. This issue affects the function grpc::InsecureServerCredentials of the file src/fastnetmon.cpp of the component gRPC API. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-48692. The attack requires being on the local network. There is not any exploit available.
A vulnerability classified as problematic has been found in FastNetMon Community Edition up to 1.2.9. This vulnerability affects unknown code of the file src/netflow_plugin/netflow_v9_collector.cpp of the component NetFlow v9 Data Flowset Processor. This manipulation causes out-of-bounds read.
This vulnerability is registered as CVE-2026-48683. The attack requires access to the local network. No exploit is available.
A vulnerability described as problematic has been identified in ONLYOFFICE DocSpace up to 3.2.0. This affects an unknown part of the component REST API. The manipulation results in improper control of resource identifiers.
This vulnerability is cataloged as CVE-2026-38587. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in FastNetMon Community Edition up to 1.2.9/4.3. Affected by this issue is the function parse_raw_bgp_attribute of the file src/bgp_protocol.hpp. The manipulation leads to out-of-bounds read.
This vulnerability is listed as CVE-2026-48685. The attack must be carried out from within the local network. There is no available exploit.
A vulnerability labeled as critical has been found in FastNetMon Community Edition up to 1.2.9. Affected by this vulnerability is the function _log of the file src/juniper_plugin/fastnetmon_juniper.php. Executing a manipulation of the argument msg can lead to os command injection.
This vulnerability is tracked as CVE-2026-48687. The attack is only possible within the local network. No exploit exists.
A vulnerability identified as problematic has been detected in Apache Flink Kubernetes Operator up to 1.14.x. Affected is an unknown function. Performing a manipulation results in files or directories accessible.
This vulnerability is identified as CVE-2026-40564. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.