A vulnerability categorized as problematic has been discovered in Saturday Drive Ninja Forms Plugin up to 3.0.3 on WordPress. Impacted is an unknown function of the component Scheduled Exports. The manipulation of the argument interval/format/emailTo results in cross site scripting.
This vulnerability is cataloged as CVE-2026-87870. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in D-ZERO BurgerEditor up to 3.4.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
This vulnerability is listed as CVE-2026-84063. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in D-ZERO BurgerEditor up to 3.4.0. It has been declared as problematic. This vulnerability affects unknown code. Executing a manipulation can lead to authorization bypass.
This vulnerability is tracked as CVE-2026-84062. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Identrail. It has been classified as critical. This affects the function CompleteGitHubConnection of the file internal/api/github_connect.go of the component GitHub Connection Handler. Performing a manipulation of the argument installation_id results in authorization bypass.
This vulnerability is identified as CVE-2026-59185. The attack can be initiated remotely. There is not any exploit available.
A vulnerability has been found in ESPHome device-builder and classified as critical. Affected by this vulnerability is an unknown functionality of the component Dashboard. This manipulation causes improper authentication.
The identification of this vulnerability is CVE-2026-59177. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability was found in OpenHop and classified as critical. Affected by this issue is the function FlowStore.filePath of the file packages/server/src/store.ts of the component Flow ID File Operations. Such manipulation of the argument ID leads to path traversal.
This vulnerability is referenced as CVE-2026-59179. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as critical, was found in addonsorg Drag and Drop File Upload for Elementor Forms Plugin up to 1.6.0 on WordPress. Affected is the function elementor_file_upload. The manipulation of the argument Type results in unrestricted upload.
This vulnerability was named CVE-2026-18351. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as problematic, has been found in VMware Workstation. This impacts an unknown function of the component Vmxnet3. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-59346. Local access is required to approach this attack. No exploit exists.
A vulnerability classified as critical was found in GeoNetwork. This affects an unknown function of the file /api/tools/ogc/sld of the component SLD Tooling Endpoint. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2026-55864. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.