A vulnerability marked as problematic has been reported in Red Hat Multicluster Engine for Kubernetes. The impacted element is the function InfraEnvStatus.ISODownloadURL of the file /v2/clusters/{cluster_id}/credentials of the component Credentials Download Endpoint. This manipulation causes cleartext storage of sensitive information.
This vulnerability is handled as CVE-2026-7163. The attack can be initiated remotely. There is not any exploit available.
A vulnerability categorized as problematic has been discovered in Foscam VD1 Video Doorbell up to 5.3.12. This impacts an unknown function. The manipulation results in cleartext transmission of sensitive information.
This vulnerability is identified as CVE-2026-38740. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability marked as critical has been reported in fleetdm fleet up to 4.80.0. Affected by this issue is some unknown functionality of the component Device Management Handler. Performing a manipulation results in authentication bypass by spoofing.
This vulnerability is cataloged as CVE-2026-24000. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability classified as problematic has been found in fleetdm fleet up to 4.80.x. This vulnerability affects unknown code of the component gRPC Endpoint. The manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-26062. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in SiYuan up to 3.6.x. Affected by this issue is the function child_process of the file app/src/block/popover.ts. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-44588. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in SiYuan up to 3.6.x and classified as critical. This affects the function model.Conf.Save of the file /api/graph/getGraph. Executing a manipulation can lead to improper authorization.
This vulnerability is tracked as CVE-2026-45371. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability classified as problematic has been found in p11-kit. Impacted is the function C_DeriveKey of the file rpc-message.c:. Performing a manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-2100. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in libssh and classified as problematic. The affected element is the function match_pattern of the component Client Configuration Handler. This manipulation causes inefficient regular expression complexity.
The identification of this vulnerability is CVE-2026-0967. The attack can only be executed locally. There is no exploit available.
A vulnerability marked as critical has been reported in libssh. The impacted element is the function ssh_get_hexa. Performing a manipulation results in buffer overflow.
This vulnerability was named CVE-2026-0966. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as problematic, was found in libssh. Impacted is the function ssh_config_parse_file/ssh_bind_config_parse_file of the component Configuration File Handler. The manipulation results in denial of service.
This vulnerability was named CVE-2026-0965. The attack needs to be approached locally. There is no available exploit.
A vulnerability was found in libssh and classified as problematic. The impacted element is an unknown function of the component SFTP Message Handler. Such manipulation of the argument SSH_FXP_NAME leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-0968. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in WooCommerce Fortis for WooCommerce Plugin up to 1.3.0 on WordPress. It has been rated as problematic. This affects an unknown function of the component Customer Information Handler. Performing a manipulation results in information disclosure.
This vulnerability is identified as CVE-2025-15609. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in exifreader up to 4.38.x. This impacts an unknown function of the component ICC mluc Tag Handler. Executing a manipulation can lead to improper validation of specified quantity in input.
This vulnerability is tracked as CVE-2026-8813. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in exifreader up to 4.38.x. Affected is an unknown function. The manipulation leads to highly compressed data.
This vulnerability is listed as CVE-2026-8814. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.