A vulnerability, which was classified as critical, was found in Mysterium Network Mysterium Node up to 1.35.x. This issue affects some unknown processing of the file /tequilapi/config/user of the component Config User Endpoint. The manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-31309. The attack can be executed remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, has been found in CycloneDX cyclonedx-node-npm up to 4.x. This vulnerability affects unknown code of the component CLI. The manipulation of the argument --workspace leads to os command injection.
This vulnerability is referenced as CVE-2026-55849. The attack can only be performed from a local environment. No exploit is available.
A vulnerability classified as critical was found in CoreWCF up to 1.8.0/1.9.0. This affects an unknown part of the component SAML Token Validation. Executing a manipulation can lead to algorithm downgrade.
The identification of this vulnerability is CVE-2026-54781. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Monsta Limited of New Zealand Monsta FTP up to 2.14.4. Affected by this issue is the function isBlockedIP of the component IP Blocklist Handler. Performing a manipulation of the argument URL results in server-side request forgery.
This vulnerability was named CVE-2026-60105. The attack may be initiated remotely. There is no available exploit.
A vulnerability described as problematic has been identified in GitLab up to 18.11.6/19.0.3/19.1.1. Affected by this vulnerability is an unknown functionality of the component Work Item Metadata Access. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-8472. The attack can be launched remotely. No exploit exists.
A vulnerability marked as problematic has been reported in GitLab up to 18.11.6/19.0.3/19.1.1. Affected is an unknown function of the component Cross-project Reference Pages. This manipulation causes improper authorization.
This vulnerability is handled as CVE-2026-7492. The attack can be initiated remotely. There is not any exploit available.
A vulnerability labeled as problematic has been found in GitLab up to 18.11.6/19.0.3/19.1.1. This impacts an unknown function of the component Input Sanitization. The manipulation results in permission issues.
This vulnerability is known as CVE-2026-6896. It is possible to launch the attack remotely. No exploit is available.