Vulnerabilities

  

CVE-2026-6208 | HAVELSAN Geographic Tracking System up to 0.0.1 authorization

A vulnerability was found in HAVELSAN Geographic Tracking System up to 0.0.1 and classified as critical. This vulnerability affects unknown

  

CVE-2026-6209 | HAVELSAN Geographic Tracking System up to 0.0.1 access control

A vulnerability was found in HAVELSAN Geographic Tracking System up to 0.0.1. It has been classified as critical. This issue

  

CVE-2026-6207 | HAVELSAN Geographic Tracking System up to 0.0.1 response discrepancy

A vulnerability was found in HAVELSAN Geographic Tracking System up to 0.0.1. It has been declared as problematic. Impacted is

  

CVE-2026-11345 | linqi 1.4.0.1 /api/Cdn/GetFile ValidateAnonFileAccess improper authentication

A vulnerability, which was classified as critical, was found in linqi 1.4.0.1. This vulnerability affects the function ValidateAnonFileAccess of the

  

CVE-2026-8914 | Teltonika RUTOS/TSWOS eval injection

A vulnerability has been found in Teltonika RUTOS and TSWOS and classified as critical. This issue affects some unknown processing.

  

CVE-2026-50256 | X.org X11 Server stack-based overflow

A vulnerability was found in X.org X11 Server and classified as critical. Impacted is an unknown function. Executing a manipulation

  

CVE-2026-50257 | X.org X11 Server miSyncDestroyFence use after free

A vulnerability was found in X.org X11 Server. It has been classified as critical. The affected element is the function

  

CVE-2026-50258 | X.org X11 Server CheckKeyTypes stack-based overflow

A vulnerability was found in X.org X11 Server. It has been declared as critical. The impacted element is the function

  

CVE-2026-50259 | X.org X11 Server _XkbSetMapChecks stack-based overflow

A vulnerability was found in X.org X11 Server. It has been rated as critical. This affects the function _XkbSetMapChecks. This

  

CVE-2026-50260 | X.org X11 Server FreeCounter use after free

A vulnerability categorized as critical has been discovered in X.org X11 Server. This impacts the function FreeCounter. Such manipulation leads

  

CVE-2026-25657 | Ericsson Packet Core Gateway up to 1.29 syntactically invalid structure

A vulnerability identified as problematic has been detected in Ericsson Packet Core Gateway up to 1.29. Affected is an unknown

  

CVE-2026-25658 | Ericsson Packet Core Gateway up to 1.29 missing values

A vulnerability labeled as problematic has been found in Ericsson Packet Core Gateway up to 1.29. Affected by this vulnerability

  

CVE-2026-25659 | Ericsson Packet Core Gateway up to 1.29 missing values

A vulnerability marked as problematic has been reported in Ericsson Packet Core Gateway up to 1.29. Affected by this issue

  

CVE-2026-11347 | linqi up to 1.4.8.5 Setting appsettings.json hard-coded key

A vulnerability described as problematic has been identified in linqi up to 1.4.8.5. This affects an unknown part of the

  

CVE-2026-11346 | linqi 504 Custom Process Creation Feature server-side request forgery

A vulnerability classified as critical has been found in linqi 504. This vulnerability affects unknown code of the component Custom

  

CVE-2026-21034 | Samsung Auto prior 3.1.2.61/3.2.0.38 Configuration improper export of android application components

A vulnerability classified as problematic was found in Samsung Auto. This issue affects some unknown processing of the component Configuration

  

CVE-2026-21035 | Samsung Plus TV prior 1.0.28.6 information disclosure

A vulnerability, which was classified as problematic, has been found in Samsung Plus TV. Impacted is an unknown function. Performing

  

CVE-2026-21029 | Samsung Devices Galaxy Editing Service improper export of android application components

A vulnerability, which was classified as critical, was found in Samsung Devices. The affected element is an unknown function of

  

CVE-2026-21017 | Samsung Devices insufficient permissions or privileges

A vulnerability has been found in Samsung Devices and classified as critical. The impacted element is an unknown function. The

  

CVE-2026-21025 | Samsung Devices Telephony privileges management

A vulnerability was found in Samsung Devices and classified as critical. This affects an unknown function of the component Telephony.

  

CVE-2026-21026 | Samsung Devices SpriteWallpaper improper export of android application components

A vulnerability was found in Samsung Devices. It has been classified as critical. This impacts an unknown function of the

  

CVE-2026-21027 | Samsung Devices Android Application improper export of android application components

A vulnerability was found in Samsung Devices. It has been declared as critical. Affected is an unknown function of the

  

CVE-2026-21028 | Samsung Devices AuditLogService access control

A vulnerability was found in Samsung Devices. It has been rated as critical. Affected by this vulnerability is an unknown

  

CVE-2026-21030 | Samsung Devices MediaTek Audio HAL access control

A vulnerability categorized as critical has been discovered in Samsung Devices. Affected by this issue is some unknown functionality of

  

CVE-2026-21031 | Samsung Devices AppBlock improper authorization

A vulnerability identified as critical has been detected in Samsung Devices. This affects an unknown part of the component AppBlock.

  

CVE-2026-21032 | Samsung Assistant up to up to 9.3.13 Android Application improper export of android application components

A vulnerability labeled as problematic has been found in Samsung Assistant up to up to 9.3.13. This vulnerability affects unknown

  

CVE-2026-21033 | Samsung Assistant up to up to 9.3.13 Android Application improper export of android application components

A vulnerability marked as problematic has been reported in Samsung Assistant up to up to 9.3.13. This issue affects some

  

CVE-2026-21036 | Samsung Internet up to 29.0.0.48 improper authorization

A vulnerability described as critical has been identified in Samsung Internet. Impacted is an unknown function. Such manipulation leads to

  

CVE-2026-21037 | Samsung Members up to 5.6.00.11 input validation

A vulnerability classified as problematic has been found in Samsung Members up to 5.6.00.11. The affected element is an unknown

  

CVE-2026-21038 | Samsung Android USB Driver 1.7.50 on Windows out-of-bounds

A vulnerability classified as problematic was found in Samsung Android USB Driver 1.7.50 on Windows. The impacted element is an

  

CVE-2026-50264 | X.org X11 Server Attachments out-of-bounds write

A vulnerability, which was classified as critical, has been found in X.org X11 Server. This affects an unknown function of

  

CVE-2026-50261 | X.org X11 Server SyncChangeCounter use after free

A vulnerability, which was classified as critical, was found in X.org X11 Server. This impacts the function SyncChangeCounter. The manipulation

  

CVE-2026-50262 | X.org X11 Server __glXDisp_ChangeDrawableAttributes out-of-bounds

A vulnerability has been found in X.org X11 Server and classified as problematic. Affected is the function __glXDisp_ChangeDrawableAttributes. This manipulation

  

CVE-2026-50263 | X.org X11 Server CreateSaverWindow use after free

A vulnerability was found in X.org X11 Server and classified as critical. Affected by this vulnerability is the function CreateSaverWindow.

  

CVE-2026-11332 | Red Hat Ansible Automation Platform 2 ansible-core meta/requirements.yml src argument injection

A vulnerability described as critical has been identified in Red Hat Ansible Automation Platform 2. Affected is an unknown function

  

CVE-2026-49777 | ShapedPlugin Product Slider Pro for WooCommerce Plugin up to 3.5.2 on WordPress improper validation of specified quantity in input

A vulnerability classified as critical has been found in ShapedPlugin Product Slider Pro for WooCommerce Plugin up to 3.5.2 on

  

CVE-2026-6274 | DTS Redline WR3200 up to 7.1.7 improper authentication

A vulnerability classified as critical was found in DTS Redline WR3200 up to 7.1.7. Affected by this issue is some

  

CVE-2026-50265 | libinput Uinput os command injection

A vulnerability, which was classified as critical, has been found in libinput. This affects an unknown part of the component

  

CVE-2026-11333 | tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php Student-Data-CSV unrestricted upload

A vulnerability described as critical has been identified in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. The impacted element is an unknown function of

  

CVE-2026-11334 | tittuvarghese CollegeManagementSystem fetch.php department_code sql injection

A vulnerability classified as critical has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This affects an unknown function of the file

  

CVE-2026-11335 | tittuvarghese CollegeManagementSystem /login-form.php session_start UserAuthData session fixiation

A vulnerability classified as critical was found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This impacts the function session_start of the file /login-form.php.

  

CVE-2026-11336 | tittuvarghese CollegeManagementSystem Admin Interface admin_page.php UserAuthData improper authorization

A vulnerability, which was classified as critical, has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown function of

  

CVE-2026-11337 | tittuvarghese CollegeManagementSystem fetch.php department_name cross site scripting

A vulnerability, which was classified as problematic, was found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected by this vulnerability is an unknown

  

CVE-2026-48907 | joomlacontenteditor Content Editor Extension up to 2.9.99.4 on Joomla JCE Editor Extension access control

A vulnerability has been found in joomlacontenteditor Content Editor Extension up to 2.9.99.4 on Joomla and classified as critical. Affected

  

CVE-2026-9088 | Keycloak on Red Hat Group Members Endpoint insufficient granularity of access control

A vulnerability was found in Keycloak on Red Hat and classified as problematic. This affects an unknown part of the

  

CVE-2026-44889 | Pylons webob Location Header redirect

A vulnerability was found in Pylons webob. It has been classified as problematic. This vulnerability affects unknown code of the

  

CVE-2026-8462 | OpenMeter sql injection

A vulnerability was found in OpenMeter. It has been declared as critical. This issue affects some unknown processing. Executing a

  

CVE-2026-11338 | SourceCodester Ship Ferry Ticket Reservation System 1.0 manage_user Username cross site scripting

A vulnerability was found in SourceCodester Ship Ferry Ticket Reservation System 1.0. It has been rated as problematic. Impacted is

  

CVE-2026-11339 | D-Link DWR-M920 up to 1.1.50 /boafrm/formUSSDSetup sub_41CF20 ussdValue command injection

A vulnerability categorized as critical has been discovered in D-Link DWR-M920 up to 1.1.50. The affected element is the function

  

CVE-2026-11341 | D-Link DWR-M920 up to 1.1.50 /boafrm/formIMEISetup sub_412DA0 IMEI_value os command injection

A vulnerability identified as critical has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function

  

CVE-2026-11342 | code-projects Hotel and Tourism Reservation System 1.0 /details.php room sql injection

A vulnerability labeled as critical has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown

  

CVE-2026-11344 | code-projects Vehicle Management System 1.0 New Driver Registration Form newdriver.php photo unrestricted upload

A vulnerability marked as critical has been reported in code-projects Vehicle Management System 1.0. This impacts an unknown function of

  

CVE-2026-11329 | onnx onnx-mlir up to 0.5.0.0 Placeholder Node Cache backend.py generate_hash_key weak hash (ID 3427)

A vulnerability was found in onnx onnx-mlir up to 0.5.0.0. It has been declared as problematic. Affected by this issue

  

CVE-2026-10732 | decompress ZIP path traversal (SNYK-JS-DECOMPRESS-16415209)

A vulnerability was found in decompress. It has been rated as problematic. This affects an unknown part of the component

  

CVE-2026-21837 | HCL Digital Experience 9.5 Digital Asset Management API os command injection (KB0130849)

A vulnerability categorized as critical has been discovered in HCL Digital Experience 9.5. This vulnerability affects unknown code of the

  

CVE-2026-21826 | HCL Digital Experience & DX Compose 9.5 Header Host redirect (KB0130849)

A vulnerability identified as problematic has been detected in HCL Digital Experience & DX Compose 9.5. This issue affects some

  

CVE-2026-21825 | HCL DX Compose 9.5 cross site scripting (KB0130849)

A vulnerability labeled as problematic has been found in HCL DX Compose 9.5. Impacted is an unknown function. The manipulation

  

CVE-2026-11330 | thedotmack claude-mem up to 11.0.1 Observation Content Hash store.ts computeObservationContentHash weak hash (ID 1494)

A vulnerability marked as problematic has been reported in thedotmack claude-mem up to 11.0.1. The affected element is the function

  

CVE-2026-11218 | Google Chrome up to 148.0.7778.216 on Windows PlatformIntegration Remote Code Execution (ID 476862)

A vulnerability described as critical has been identified in Google Chrome on Windows. The affected element is an unknown function

  

CVE-2026-11222 | Google Chrome up to 148.0.7778.216 Tab Strip clickjacking (ID 458442)

A vulnerability classified as problematic has been found in Google Chrome. The impacted element is an unknown function of the

  

CVE-2026-11221 | Google Chrome up to 148.0.7778.216 PointerLock clickjacking (ID 492211)

A vulnerability classified as problematic was found in Google Chrome. This affects an unknown function of the component PointerLock. Such

  

CVE-2026-11220 | Google Chrome up to 148.0.7778.216 Navigation improper isolation or compartmentalization (ID 487300)

A vulnerability, which was classified as critical, has been found in Google Chrome. This impacts an unknown function of the

  

CVE-2026-11219 | Google Chrome up to 148.0.7778.216 Navigation Remote Code Execution (ID 480074)

A vulnerability, which was classified as critical, was found in Google Chrome. Affected is an unknown function of the component

  

CVE-2026-11225 | Google Chrome up to 148.0.7778.216 WebUI clickjacking (ID 503346)

A vulnerability has been found in Google Chrome and classified as problematic. Affected by this vulnerability is an unknown functionality

  

CVE-2026-11223 | Google Chrome up to 148.0.7778.216 Network cross-domain policy (ID 494800)

A vulnerability was found in Google Chrome and classified as problematic. Affected by this issue is some unknown functionality of

  

CVE-2026-11227 | Google Chrome up to 148.0.7778.216 Tab Hover Cards clickjacking (ID 448421)

A vulnerability was found in Google Chrome. It has been classified as problematic. This affects an unknown part of the

  

CVE-2026-11228 | Google Chrome up to 148.0.7778.216 File Input clickjacking (ID 454484)

A vulnerability was found in Google Chrome. It has been declared as problematic. This vulnerability affects unknown code of the

  

CVE-2026-11230 | Google Chrome up to 148.0.7778.216 Extensions use after free (ID 493225)

A vulnerability was found in Google Chrome. It has been rated as critical. This issue affects some unknown processing of

  

CVE-2026-11232 | Google Chrome up to 148.0.7778.216 TabGroups clickjacking (ID 495981)

A vulnerability categorized as problematic has been discovered in Google Chrome. Impacted is an unknown function of the component TabGroups.

  

CVE-2026-11231 | Google Chrome up to 148.0.7778.216 on macOS Safe Browsing Remote Code Execution (ID 495840)

A vulnerability identified as critical has been detected in Google Chrome on macOS. The affected element is an unknown function

  

CVE-2026-11199 | Google Chrome up to 148.0.7778.216 WebRTC cross-domain policy (ID 504572)

A vulnerability labeled as problematic has been found in Google Chrome. The impacted element is an unknown function of the

  

CVE-2026-11185 | Google Chrome up to 148.0.7778.216 V8 use after free (ID 502784)

A vulnerability marked as critical has been reported in Google Chrome. This affects an unknown function of the component V8.

  

CVE-2026-11189 | Google Chrome up to 148.0.7778.216 DevTools input validation (ID 503197)

A vulnerability described as critical has been identified in Google Chrome. This impacts an unknown function of the component DevTools.

  

CVE-2026-11201 | Google Chrome up to 148.0.7778.216 ServiceWorker use after free (ID 505068)

A vulnerability classified as critical has been found in Google Chrome. Affected is an unknown function of the component ServiceWorker.

  

CVE-2026-11169 | Google Chrome up to 148.0.7778.216 XML cross site scripting (ID 502285)

A vulnerability classified as problematic was found in Google Chrome. Affected by this vulnerability is an unknown functionality of the

  

CVE-2026-11214 | Google Chrome up to 148.0.7778.216 on iOS cross-domain policy (ID 508257)

A vulnerability, which was classified as problematic, has been found in Google Chrome on iOS. Affected by this issue is

  

CVE-2026-11150 | Google Chrome up to 148.0.7778.216 XML cross site scripting (ID 501740)

A vulnerability, which was classified as problematic, was found in Google Chrome. This affects an unknown part of the component

  

CVE-2026-11202 | Google Chrome up to 148.0.7778.216 on iOS sandbox (ID 505144)

A vulnerability has been found in Google Chrome on iOS and classified as critical. This vulnerability affects unknown code. This

  

CVE-2026-11186 | Google Chrome up to 148.0.7778.216 CSS cross site scripting (ID 502805)

A vulnerability was found in Google Chrome and classified as problematic. This issue affects some unknown processing of the component

  

CVE-2026-11157 | Google Chrome up to 148.0.7778.216 Accessibility cross site scripting (ID 501823)

A vulnerability was found in Google Chrome. It has been classified as problematic. Impacted is an unknown function of the

  

CVE-2026-11166 | Google Chrome up to 148.0.7778.216 SVG cross site scripting (ID 502118)

A vulnerability was found in Google Chrome. It has been declared as problematic. The affected element is an unknown function

  

CVE-2026-11183 | Google Chrome up to 148.0.7778.216 GWP-ASan out-of-bounds (ID 502768)

A vulnerability was found in Google Chrome. It has been rated as problematic. The impacted element is an unknown function

  

CVE-2026-11109 | Google Chrome up to 148.0.7778.216 ANGLE uninitialized variable (ID 500524)

A vulnerability categorized as problematic has been discovered in Google Chrome. This affects an unknown function of the component ANGLE.

  

CVE-2026-11205 | Google Chrome up to 148.0.7778.216 on iOS cross site scripting (ID 505290)

A vulnerability identified as problematic has been detected in Google Chrome on iOS. This impacts an unknown function. This manipulation

  

CVE-2026-11159 | Google Chrome up to 148.0.7778.216 Skia uninitialized variable (ID 501861)

A vulnerability labeled as problematic has been found in Google Chrome. Affected is an unknown function of the component Skia.

  

CVE-2026-11229 | Google Chrome up to 148.0.7778.216 Enterprise Local Privilege Escalation (ID 482713)

A vulnerability marked as problematic has been reported in Google Chrome. Affected by this vulnerability is an unknown functionality of

  

CVE-2026-11110 | Google Chrome up to 148.0.7778.216 ANGLE uninitialized variable (ID 500528)

A vulnerability described as problematic has been identified in Google Chrome. Affected by this issue is some unknown functionality of

  

CVE-2026-11138 | Google Chrome up to 148.0.7778.216 ANGLE uninitialized variable (ID 501650)

A vulnerability classified as problematic has been found in Google Chrome. This affects an unknown part of the component ANGLE.

  

CVE-2026-11235 | Google Chrome up to 148.0.7778.216 Compositing sandbox (ID 496419)

A vulnerability classified as critical was found in Google Chrome. This vulnerability affects unknown code of the component Compositing. The

  

CVE-2026-11236 | Google Chrome up to 148.0.7778.216 Web Bluetooth sandbox (ID 496427)

A vulnerability, which was classified as critical, has been found in Google Chrome. This issue affects some unknown processing of

  

CVE-2026-11234 | Google Chrome up to 148.0.7778.216 FoldableAPIs improper isolation or compartmentalization (ID 496095)

A vulnerability, which was classified as critical, was found in Google Chrome. Impacted is an unknown function of the component

  

CVE-2026-7763 | Morse Micro HaLowLink 2 up to 2.11.12 morse.ko morse_page_slicing_process_tim_element heap-based overflow

A vulnerability has been found in Morse Micro HaLowLink 2 up to 2.11.12 and classified as critical. The affected element

  

CVE-2026-11237 | Google Chrome up to 148.0.7778.216 Media clickjacking (ID 496617)

A vulnerability was found in Google Chrome and classified as problematic. The impacted element is an unknown function of the

  

CVE-2026-7762 | Morse Micro HaLowLink 2 up to 2.11.12 dot11ah.ko morse_dot11ah_find_s1g_caps_for_bssid heap-based overflow

A vulnerability was found in Morse Micro HaLowLink 2 up to 2.11.12. It has been classified as critical. This affects

  

CVE-2026-41567 | Moby up to 2.0.0-beta.13 uncontrolled search path (GHSA-x86f-5xw2-fm2r)

A vulnerability was found in Moby up to 2.0.0-beta.13. It has been declared as problematic. This impacts an unknown function.

  

CVE-2023-5502 | Arista EOS up to 4.31.0F improper authentication

A vulnerability was found in Arista EOS up to 4.31.0F. It has been rated as critical. Affected is an unknown

  

CVE-2024-27890 | Arista EOS up to 4.29.7M Configuration missing authentication

A vulnerability categorized as critical has been discovered in Arista EOS up to 4.29.7M. Affected by this vulnerability is an

  

CVE-2024-27892 | Arista EOS up to 4.31.2F Configuration missing authentication

A vulnerability identified as critical has been detected in Arista EOS up to 4.31.2F. Affected by this issue is some

  

CVE-2025-8873 | Arista EOS up to 4.33.4M IPsec improper validation of syntactic correctness of input

A vulnerability labeled as critical has been found in Arista EOS up to 4.29.10.1M/4.30.10M/4.31.7.1M/4.32.6.1M/4.33.4M. This affects an unknown part of

  

CVE-2026-50593 | Graphite up to 1.3.14 integer underflow

A vulnerability marked as problematic has been reported in Graphite up to 1.3.14. This vulnerability affects unknown code. The manipulation