A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.6.111/6.12.52/6.17.2. Impacted is the function cifs_sg_set_buf of the file smb2ops.c of the component Crypto API. This manipulation of the argument sensitive_size causes privilege escalation.
This vulnerability is tracked as CVE-2025-40052. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.155/6.6.111/6.12.52/6.17.2. It has been classified as critical. Affected by this issue is the function copy_from_iter of the component vhost. This manipulation causes unchecked return value.
This vulnerability is registered as CVE-2025-40051. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 5.15.194/6.1.155/6.6.111/6.12.52/6.17.2. It has been declared as critical. This affects the function netdev_alloc_skb_ip_align of the component net. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2025-40053. The attack requires being on the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 5.15.194/6.1.155/6.6.111/6.12.52/6.17.2. This vulnerability affects the function open_by_handle_at. The manipulation leads to use of uninitialized variable.
This vulnerability is referenced as CVE-2025-40049. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.17.2. This issue affects the function check_alu_op of the component bpf. The manipulation results in privilege escalation.
This vulnerability is identified as CVE-2025-40050. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in HiJiffy Chatbot. This impacts an unknown function of the file /api/v1/webchat/message of the component Private Message Handler. Performing a manipulation results in incorrect authorization.
This vulnerability is identified as CVE-2026-4263. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as critical, was found in plank laravel-mediable up to 6.4.0. Affected is an unknown function. Executing a manipulation can lead to unrestricted upload.
This vulnerability is tracked as CVE-2026-4809. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability classified as critical has been found in Vienna Symphonic Library Vienna Assistant 1.2.542. Affected is the function shouldAcceptNewConnection of the component Endpoint. Performing a manipulation results in missing authentication.
This vulnerability was named CVE-2026-24068. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as critical was found in BS Producten Petcam 33.1.0.0818. This impacts an unknown function of the component Network Interface Handler. The manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2025-69988. An attack on the physical device is feasible. There is no exploit available.
A vulnerability has been found in ON24 Q&A Chat and classified as problematic. Affected by this vulnerability is an unknown functionality of the file console-survey/api/v1/answer/ of the component History Handler. Performing a manipulation results in authorization bypass.
This vulnerability is cataloged as CVE-2026-3321. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in Umami Software application 3.0.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Request Parameter Handler. This manipulation of the argument prisma.rawQuery/prisma.queryRawUnsafe causes sql injection.
This vulnerability appears as CVE-2026-4317. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in FalkorDB Browser 1.9.3. It has been classified as critical. This affects an unknown part of the component File Upload API. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-6057. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to install a patch to address this issue.
A vulnerability, which was classified as problematic, has been found in Rukovoditel CRM up to 3.6/3.6.4. This issue affects some unknown processing of the file /api/tel/zadarma.php of the component API Endpoint. The manipulation of the argument zd_echo leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-31845. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in libcap up to 2.77. Affected by this vulnerability is the function cap_set_file. The manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2026-4878. The attack can only be performed from a local environment. No exploit is available.
It is recommended to apply a patch to fix this issue.