A vulnerability labeled as problematic has been found in HCL DX Compose 9.5. Impacted is an unknown function. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-21825. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as problematic has been detected in HCL Digital Experience & DX Compose 9.5. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument Host leads to open redirect.
This vulnerability is uniquely identified as CVE-2026-21826. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in HCL Digital Experience 9.5. This vulnerability affects unknown code of the component Digital Asset Management API. Executing a manipulation can lead to os command injection.
This vulnerability is handled as CVE-2026-21837. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in decompress. It has been rated as problematic. This affects an unknown part of the component ZIP Handler. Performing a manipulation results in path traversal: '\..\filename'.
This vulnerability is known as CVE-2026-10732. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in onnx onnx-mlir up to 0.5.0.0. It has been declared as problematic. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the component Placeholder Node Cache Handler. Such manipulation leads to use of weak hash.
This vulnerability is traded as CVE-2026-11329. An attack has to be approached locally. There is no exploit available.
Applying a patch is advised to resolve this issue.
Our TLS inspection proxy PolarProxy has been updated with bug fixes, improved performance and more reliable PCAP output. The recent PolarProxy 2.0 release added musl/Alpine compatibility and support for unencrypted HTTP proxy requests. But there were a few small, yet very important, updates that unf[...]