A vulnerability was found in Nokia SR Linux up to 23.10.7/24.10.5/25.7.1. It has been declared as problematic. This affects an unknown function. Such manipulation leads to Local Privilege Escalation.
This vulnerability is listed as CVE-2025-10262. The attack must be carried out locally. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Sony Optical Disc Archive Software for Windows up to 5.5.3 on Windows. It has been classified as critical. The impacted element is an unknown function. This manipulation causes incorrect default permissions.
This vulnerability is tracked as CVE-2026-50255. The attack is restricted to local execution. No exploit exists.
A vulnerability was found in rometheme RTMKit Plugin up to 2.0.7 on WordPress and classified as problematic. The affected element is an unknown function of the component AJAX Endpoint. The manipulation of the argument entries_id results in incorrect authorization.
This vulnerability is identified as CVE-2026-5149. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in mohammadtanzilurrahman Static Block Plugin up to 2.2 on WordPress and classified as problematic. Impacted is the function static_block_content of the component Shortcode Handler. The manipulation of the argument ID leads to authorization bypass.
This vulnerability is referenced as CVE-2026-10780. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability, which was classified as critical, was found in zealopensource Abandoned Contact Form 7 Plugin up to 2.2 on WordPress. This issue affects the function action__remove_abandoned. Executing a manipulation can lead to missing authorization.
The identification of this vulnerability is CVE-2026-9187. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in zephyrproject zephyr up to 4.4.x. This vulnerability affects the function k_mem_domain_deinit of the file arch/xtensa/core/ptables.c of the component Xtensa memory-domain de-initialization Feature. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-10635. The attack needs to be approached locally. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Premmerce Dev Tools Plugin up to 2.0 on WordPress. This affects the function generatePluginHandler. Such manipulation of the argument premmerce_plugin_namespace leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2026-6933. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in WP Review Slider Pro Plugin up to 12.6.8 on WordPress. Affected by this issue is the function stripslashes. This manipulation of the argument wpdb causes sql injection.
This vulnerability is handled as CVE-2026-8443. The attack can be initiated remotely. There is not any exploit available.
Digital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients' personal and health information stored on third-party-hosted business applications. [...]
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026.
The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case of privilege
A vulnerability described as problematic has been identified in Symfony. Affected by this vulnerability is an unknown functionality of the component UrlGenerator. The manipulation results in encoding error.
This vulnerability is known as CVE-2026-48784. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in Symfony. Affected is an unknown function of the component URL Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-48761. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.