A vulnerability was found in Edimax BR-6478AC V2 1.23. It has been rated as critical. Affected by this vulnerability is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in command injection.
This vulnerability was named CVE-2026-12810. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Edimax BR-6478AC V2 1.23. It has been declared as critical. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation of the argument newpass leads to command injection.
This vulnerability is uniquely identified as CVE-2026-12809. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Edimax BR-6478AC V2 1.23. It has been classified as critical. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument interface causes command injection.
This vulnerability is handled as CVE-2026-12808. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Edimax BR-6478AC V2 1.23 and classified as critical. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName results in command injection.
This vulnerability is known as CVE-2026-12807. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Edimax BR-6478AC V2 1.23 and classified as critical. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow.
This vulnerability is traded as CVE-2026-12806. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability appears as CVE-2026-12805. The attack may be performed from remote. In addition, an exploit is available.
It is best practice to apply a patch to resolve this issue.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability, which was classified as problematic, has been found in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect.
This vulnerability is reported as CVE-2026-12804. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as problematic was found in wproyal Royal Addons for Elementor Plugin up to 1.7.1059 on WordPress. This issue affects some unknown processing. Such manipulation leads to file inclusion.
This vulnerability is documented as CVE-2026-8118. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as problematic has been found in getgrav grav. This vulnerability affects the function MediaObjectTrait::style of the component Markdown Image Handler. This manipulation of the argument style causes cross site scripting.
This vulnerability is registered as CVE-2026-55890. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Symfony ux-toolkit. This affects an unknown part of the component Recipe Manifest Handler. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-55878. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.