A vulnerability was found in haxtheweb haxcms-nodejs, video-player and iframe-loader up to 25.x. It has been rated as problematic. Affected is an unknown function. The manipulation of the argument src leads to cross site scripting.
This vulnerability is referenced as CVE-2026-46396. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in Altium Enterprise Server and 365 up to 8.1.0. It has been declared as critical. This impacts an unknown function of the component Projects Service Download Endpoint. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-11431. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Arista Edge Threat Management up to 17.4.0. It has been classified as critical. This affects an unknown function. Performing a manipulation results in os command injection.
This vulnerability was named CVE-2026-25623. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Arista Edge Threat Management up to 17.4.0 and classified as critical. The impacted element is an unknown function of the component User Interface. Such manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-25622. The attack can be launched remotely. No exploit exists.
A vulnerability has been found in Arista Edge Threat Management 17.4.0 and classified as critical. The affected element is an unknown function of the component Captive Portal Application Framework. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-25620. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as critical, was found in Arista Edge Threat Management 17.4.0. Impacted is an unknown function. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-25621. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as problematic, has been found in haxtheweb haxcms-nodejs and video-player up to 25.x. This issue affects some unknown processing. The manipulation of the argument Source leads to cross site scripting.
This vulnerability is traded as CVE-2026-46496. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in haxtheweb haxcms-nodejs and haxcms-php up to 25.x. This vulnerability affects unknown code. Executing a manipulation can lead to server-side request forgery.
This vulnerability appears as CVE-2026-46393. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromDhcpListClient of the component HTTP Handler. Performing a manipulation of the argument page results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-36785. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability described as problematic has been identified in AsyncHttpClient async-http-client up to 2.14.x/3.0.9. Affected by this issue is the function propagatedHeaders of the file Redirect30xInterceptor.java of the component Session Cookie Handler. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-45300. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Altium Enterprise Server up to 8.1.0. Affected by this vulnerability is an unknown functionality of the component Collaboration Service. This manipulation causes path traversal.
This vulnerability is registered as CVE-2026-11423. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Hippoo Mobile App for WooCommerce Plugin up to 1.9.4 on WordPress. Affected is the function HippooPermissions::get_user_permissions of the file /wc-hippoo/v1/ext of the component REST Endpoint. The manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-10580. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in webfactory Advanced Google reCAPTCHA Plugin up to 5.38 on WordPress. This impacts the function ajax_run_tool of the component AJAX Handler. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is listed as CVE-2026-5415. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as critical has been discovered in haxtheweb haxcms-php and haxcms-nodejs up to 25.x. This affects an unknown function of the file site.json of the component saveOutline Endpoint. Executing a manipulation of the argument location can lead to path traversal.
This vulnerability is tracked as CVE-2026-46397. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in haxtheweb haxcms-php up to 25.x. It has been rated as problematic. The impacted element is an unknown function. Performing a manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-46390. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Altium Enterprise Server up to 8.1.0. It has been declared as critical. The affected element is an unknown function of the component Network Installation Service. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-11420. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in haxtheweb haxcms-nodejs and haxcms-php up to 25.x. It has been classified as problematic. Impacted is an unknown function of the file /system/api/connectionSettings of the component Setting Handler. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-46511. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Altium Enterprise Server and 365 up to 8.1.0 and classified as critical. This issue affects some unknown processing of the component Git Service. The manipulation results in path traversal.
This vulnerability was named CVE-2026-11429. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.