A vulnerability categorized as critical has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. The manipulation of the argument filename results in path traversal.
This vulnerability is identified as CVE-2026-15700. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability described as problematic has been identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference.
This vulnerability is documented as CVE-2026-15690. The attack can be executed remotely. Additionally, an exploit exists.
The project closed the issue report, stating that this is not the official way to report a security vulnerability.
A vulnerability was found in spencermountain compromise up to 14.15.1. It has been rated as critical. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes.
This vulnerability is referenced as CVE-2026-15699. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Applying a patch is the recommended action to fix this issue.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability was found in kofrasa mingo up to 7.2.1. It has been declared as critical. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the argument Set can lead to improperly controlled modification of object prototype attributes.
The identification of this vulnerability is CVE-2026-15698. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in svgdotjs svg.js up to 3.2.5. It has been classified as critical. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manipulation results in improperly controlled modification of object prototype attributes.
This vulnerability was named CVE-2026-15697. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in Tenda BE12 Pro 16.03.66.23 and classified as critical. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-15696. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability has been found in Tenda BE12 Pro 16.03.66.23 and classified as critical. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow.
This vulnerability is handled as CVE-2026-15695. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability, which was classified as critical, was found in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in stack-based buffer overflow.
This vulnerability is known as CVE-2026-15694. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability, which was classified as critical, has been found in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2026-15693. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2026-15692. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability classified as critical has been found in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-15691. The attack is possible to be carried out remotely. Moreover, an exploit is present.