Currently trending CVE - Hype Score: 3 - Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
Currently trending CVE - Hype Score: 20 - The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Currently trending CVE - Hype Score: 4 - In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks ...
A vulnerability classified as critical was found in GitLab Remote Development up to 16.5.5/16.6.3/16.7.1. Affected by this issue is some unknown functionality. The manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2023-6955. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability marked as critical has been reported in Flowise up to 2.1.3. Affected by this vulnerability is an unknown functionality of the component Configuration Handler. Performing a manipulation results in code injection.
This vulnerability is reported as CVE-2024-58351. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in prefecthq prefect up to 3.6.23. It has been rated as critical. This affects an unknown part. Performing a manipulation of the argument commit_sha results in code injection.
This vulnerability is identified as CVE-2026-5366. The attack can be initiated remotely. There is not any exploit available.
It is suggested to install a patch to address this issue.
A vulnerability marked as problematic has been reported in AVideo up to 26.0. The affected element is an unknown function of the file list.json.php of the component API Response Handler. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2026-56341. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability classified as critical has been found in AVideo up to 27.0. This affects the function isSSRFSafeURL of the file plugin/Live/test.php of the component Network Configuration Handler. Performing a manipulation of the argument statsURL results in server-side request forgery.
This vulnerability is reported as CVE-2026-56342. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in AVideo Meet Plugin up to 29.0. This vulnerability affects unknown code of the file uploadRecordedVideo.json.php of the component File Handler. Executing a manipulation of the argument Login can lead to improper authentication.
This vulnerability is tracked as CVE-2026-56345. The attack can be launched remotely. No exploit exists.
A vulnerability identified as critical has been detected in AVideo up to 25.0. This issue affects some unknown processing of the file decryptMessage.json.php. The manipulation leads to missing authentication.
This vulnerability is listed as CVE-2026-56346. The attack may be initiated remotely. There is no available exploit.
A vulnerability described as problematic has been identified in WWBN AVideo up to 26.0. The impacted element is an unknown function of the component Session Cookie Handler. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-56347. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as critical has been found in Linux Kernel up to 6.19.3. Affected by this vulnerability is the function ib_uverbs_post_send of the component uverbs. The manipulation leads to out-of-bounds read.
This vulnerability is listed as CVE-2026-45856. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.164/6.6.127/6.12.74/6.18.13/6.19.3. This affects an unknown part of the component bpf. The manipulation leads to uninitialized pointer.
This vulnerability is uniquely identified as CVE-2026-45886. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.140/6.12.90/6.18.32/7.0.9/7.1-rc1 and classified as critical. Affected by this issue is the function bareudp_fill_metadata_dst of the file net/ipv6/ip6_udp_tunnel.c of the component bareudp. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2026-45846. The attack needs to be approached within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in markdown-it up to 14.1.x. The affected element is the function replaceAt of the component Markdown Parser. Executing a manipulation can lead to resource consumption.
This vulnerability is handled as CVE-2026-48988. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, was found in Tinyproxy up to 1.11.3. Affected by this vulnerability is an unknown functionality of the component Header Handler. The manipulation of the argument Host results in authentication bypass by spoofing.
This vulnerability was named CVE-2026-55202. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
A vulnerability was found in Oracle VM VirtualBox 7.2.8. It has been declared as critical. The impacted element is an unknown function of the component VMSVGA Device. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2026-46877. The attack requires local access. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Microsoft Windows up to Server 2022 and classified as critical. This issue affects some unknown processing of the component Local Session Manager. The manipulation results in denial of service.
This vulnerability is reported as CVE-2022-37998. The attack can be launched remotely. No exploit exists.
A patch should be applied to remediate this issue.
A vulnerability identified as critical has been detected in Microsoft Windows. This affects an unknown function of the component Graphics. Performing a manipulation results in privilege escalation.
This vulnerability is identified as CVE-2022-37997. The attack can be initiated remotely. There is not any exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Microsoft Windows. It has been classified as problematic. Impacted is an unknown function of the component Kernel. This manipulation causes information disclosure.
This vulnerability appears as CVE-2022-37996. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.