A vulnerability labeled as critical has been found in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-14793. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information. In April 2026, Medtronic confirmed a cyberattack on its corporate IT systems after the hacker group ShinyHunters claimed […]
A vulnerability identified as critical has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/modules/survey/link/actions.ts of the component Survey Handler. The manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2026-14792. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-14791. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in ail-project AIL Framework. It has been rated as problematic. The impacted element is the function PDF.get_filepath of the component PDF Object Handling. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-59510. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Linux Kernel up to 6.6.135/6.12.83/6.18.24/7.0.1. It has been declared as critical. Affected is the function ksmbd_tcp_new_connection. Such manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2026-31711. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.6.135/6.12.83/6.18.24/7.0.1. Impacted is the function check_add_overflow of the file smbacl.c of the component ksmbd. Such manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2026-31704. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.6.135/6.12.83/6.18.24/7.0.1. It has been declared as critical. This affects the function smb2_get_ea of the component ksmbd. Executing a manipulation can lead to out-of-bounds write.
The identification of this vulnerability is CVE-2026-31705. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.6.135/6.12.83/6.18.24/7.0.1. This affects the function create_card of the component Caiaq Driver. The manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2026-31701. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.135/6.12.83/6.18.24/7.0.1. This vulnerability affects the function f2fs_compress_write_end_io of the file data.c. This manipulation causes use after free.
This vulnerability appears as CVE-2026-31702. The attacker needs to be present on the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.6.134/6.12.81/6.18.22/6.19.12. Impacted is the function rxkad_decrypt_ticket of the component rxrpc. Such manipulation leads to privilege escalation.
This vulnerability is listed as CVE-2026-31637. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.135/6.12.83/6.18.24/7.0.1. Impacted is the function rxrpc_preparse of the file net/rxrpc/key.c of the component XDR Parser. Performing a manipulation results in memory corruption.
This vulnerability is known as CVE-2026-31696. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.82/6.18.23/6.19.13/7.0.0. It has been declared as critical. Affected is the function alps_raw_event of the component HID Driver. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2026-31625. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.