A vulnerability was found in rust-lang Cargo up to 1.95.x and classified as problematic. This affects an unknown part. Executing a manipulation can lead to use of non-canonical url paths for authorization decisions.
This vulnerability appears as CVE-2026-5222. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability has been found in rust-lang Cargo up to 1.95.x and classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in symlink following.
This vulnerability is reported as CVE-2026-5223. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in Apache Airflow Google Provider up to 21.x. Affected by this vulnerability is an unknown functionality of the component SSH Host-Key Verification. Such manipulation leads to key exchange without entity authentication.
This vulnerability is documented as CVE-2026-45361. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read.
This vulnerability is registered as CVE-2026-9504. The attack needs to be launched locally. Furthermore, an exploit is available.
Applying a patch is the recommended action to fix this issue.
A vulnerability classified as problematic was found in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-9503. The attack must be initiated from a local position. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2026-9502. The attack must be carried out locally. In addition, an exploit is available.
To fix this issue, it is recommended to deploy a patch.
A vulnerability described as problematic has been identified in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion.
This vulnerability is tracked as CVE-2026-9501. The attack is restricted to local execution. Moreover, an exploit is present.
A patch should be applied to remediate this issue.
A vulnerability marked as critical has been reported in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is identified as CVE-2026-9500. The attack is only possible with local access. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability, which was classified as critical, has been found in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection.
This vulnerability is known as CVE-2026-9435. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability, which was classified as critical, was found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection.
This vulnerability is handled as CVE-2026-9436. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability was found in Vmware Spring AI up to 1.1.6. It has been classified as critical. Affected by this vulnerability is the function Path.resolve of the component Anthropic Skills API Handler. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2026-41863. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability has been found in DTStack Taier 1.4.0 and classified as critical. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlText leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-9437. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203 and classified as problematic. This impacts an unknown function of the file courseDel.php. The manipulation of the argument ID results in improper control of resource identifiers.
This vulnerability was named CVE-2026-9438. The attack may be performed from remote. In addition, an exploit is available.
This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in Mattermost up to 10.11.14/11.4.4/11.5.3/11.6.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Webhook Attachment Handler. Executing a manipulation can lead to improper check for unusual conditions.
This vulnerability is handled as CVE-2026-4915. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Acer Care Center up to 4.00.3058. This vulnerability affects unknown code of the component ACCSvc Service. The manipulation results in improper privilege management.
This vulnerability was named CVE-2026-9490. The attack needs to be approached locally. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability was found in Edimax BR-6675nD 1.12. It has been classified as critical. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command injection.
The identification of this vulnerability is CVE-2026-9439. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.