A vulnerability, which was classified as critical, was found in addonsorg Drag and Drop File Upload for Elementor Forms Plugin up to 1.6.0 on WordPress. Affected is the function elementor_file_upload. The manipulation of the argument Type results in unrestricted upload.
This vulnerability was named CVE-2026-18351. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as problematic, has been found in VMware Workstation. This impacts an unknown function of the component Vmxnet3. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-59346. Local access is required to approach this attack. No exploit exists.
A vulnerability classified as critical was found in GeoNetwork. This affects an unknown function of the file /api/tools/ogc/sld of the component SLD Tooling Endpoint. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2026-55864. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Joker up to 1.8.1. The impacted element is an unknown function of the file jokerd/linter.cljc. Performing a manipulation results in code injection.
This vulnerability is known as CVE-2026-59172. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in jordanburke functype 1.4.3. The affected element is the function set_functype_version of the file packages/mcp-server/src/index.ts of the component mcp-server. Such manipulation of the argument Version leads to inclusion of functionality from untrusted control sphere.
This vulnerability is traded as CVE-2026-59176. The attack may be launched remotely. There is no exploit available.
A vulnerability marked as critical has been reported in yeger turbo-graph 2.8.8. Impacted is the function GET of the file packages/turbo-graph-ui/app/api/run/route.ts of the component API Run Endpoint. This manipulation of the argument tasks causes missing authentication.
This vulnerability appears as CVE-2026-59160. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as problematic has been found in thoda-dev nuxt-ollama 1.2.26. This issue affects the function setup of the file src/module.ts of the component Runtime Config. The manipulation of the argument api_key results in insufficiently protected credentials.
This vulnerability is reported as CVE-2026-59158. The attack can be launched remotely. No exploit exists.
A vulnerability identified as critical has been detected in webhookd up to 1.21.x. This vulnerability affects unknown code of the component Basic Auth Middleware. The manipulation leads to injection.
This vulnerability is documented as CVE-2026-59157. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, was found in beaugunderson ip-address up to 10.2.0. This vulnerability affects the function Address6.getType. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2026-54272. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in WordPress Coding Standards up to 3.4.0. This impacts the function is_falsy of the component EnqueuedResourceParameter. The manipulation of the argument ver leads to os command injection.
This vulnerability is traded as CVE-2026-45293. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in ruby-oauth oauth2 up to 2.0.21. It has been classified as problematic. Impacted is the function OAuth2::Client#request of the component Client. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2026-54603. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in ruby-oauth oauth up to 1.1.5. It has been declared as problematic. The affected element is the function OAuth::Consumer#token_request. The manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability was named CVE-2026-54605. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in CyberTimon RapidRAW up to 1.5.x. This issue affects the function handle_import_presets_from_file/File::open of the file lut_processing.rs/file_management.rs of the component Preset Processing. The manipulation of the argument lutPath results in file inclusion.
This vulnerability is known as CVE-2026-64816. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in Ylianst MeshCentral 1.1.21 and classified as problematic. The affected element is the function CheckWebServerOriginName of the file webserver.js of the component WebSocket Endpoint. Such manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is uniquely identified as CVE-2026-66420. The attack can be launched remotely. No exploit exists.
A vulnerability classified as critical was found in drakkan SFTPGo up to 2.7.3. Impacted is an unknown function of the component Symbolic Link Handler. The manipulation results in improper access controls.
This vulnerability is reported as CVE-2026-10031. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.