A vulnerability classified as critical was found in Dassault Systèmes DELMIA Apriso. Affected is an unknown function. The manipulation results in improper authentication.
This vulnerability is reported as CVE-2026-9695. The attack can be launched remotely. No exploit exists.
从下半年发布的 Windows 11 26H2 起,微软将对符合条件的企业设备默认启用云备份,但欧盟地区除外。被称为 Windows settings backup and restore 的功能将备份设备的设置和已安装 Microsoft Store 应用列表,用户可以将备份恢复到新设备上。微软称,想象下笔记本电脑丢失、硬件更新或意外重启。这些情况下用户最需要备份,而用户最不希望看到的就是备份功能从未启用。对于受到欧盟数字市场法案 (Digital Markets Act) 监管的组织,云备份不会默认启用。
A vulnerability described as problematic has been identified in wpkuf Wp Js Detect Plugin up to 1.0.9. This affects the function plugin_settings of the component Settings Handler. Executing a manipulation of the argument wp_non_js_notification_text/wp_non_js_notification_css can lead to cross-site request forgery.
This vulnerability is registered as CVE-2026-9731. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as critical has been reported in Fuji Electric Pupsman up to 3.8.x. The impacted element is an unknown function of the component DLL File Handler. Performing a manipulation results in uncontrolled search path.
This vulnerability is cataloged as CVE-2026-56437. The attack must be initiated from a local position. There is no exploit available.
A vulnerability labeled as problematic has been found in Chatra Live Chat and ChatBot and Cart Saver Plugin up to 1.0.12. The affected element is an unknown function of the component Admin Settings. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-12041. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as problematic has been detected in the_champ Social Share, Social Login and Social Comments Plugin up to 7.14.5. Impacted is an unknown function of the component Mastodon Share Handler. This manipulation of the argument heateor_mastodon_share causes cross site scripting.
This vulnerability is tracked as CVE-2026-11798. The attack is possible to be carried out remotely. No exploit exists.
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.
The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network
A vulnerability categorized as critical has been discovered in joe007 Eventer Plugin up to 4.4.2. This issue affects some unknown processing of the component SQL Query Handler. The manipulation of the argument code results in sql injection.
This vulnerability is identified as CVE-2026-9700. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in idocoh Sympl Repeater Plugin up to 2.3. It has been rated as problematic. This vulnerability affects the function symp_arfe_replace_content of the component ACF Repeater Field Handler. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-10570. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in Fuji Electric Pupsman up to 3.8.x. It has been declared as very critical. This affects an unknown part of the component Installation Folder. Executing a manipulation can lead to permission issues.
The identification of this vulnerability is CVE-2026-57895. The attack can only be executed locally. There is no exploit available.