A vulnerability labeled as critical has been found in Erlang OTP up to 6.x/[email protected]. This issue affects some unknown processing in the library lib/tftp/src/tftp_file.erl of the component tftp_file. Executing a manipulation can lead to relative path traversal.
This vulnerability appears as CVE-2026-21620. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in dropbox/arekinath/handnot2 esaml. This affects an unknown part of the component SAML Handler. Such manipulation leads to xml external entity reference.
This vulnerability is listed as CVE-2026-28809. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
A vulnerability described as problematic has been identified in Erlang OTP. Affected by this issue is some unknown functionality in the library lib/inets/src/http_server/httpd_request.erl of the component RFC 9112. Executing a manipulation of the argument Content-Length can lead to http request smuggling.
The identification of this vulnerability is CVE-2026-23941. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, was found in Erlang OTP. Impacted is an unknown function in the library lib/ssh/src/ssh_sftpd.erl of the component ssh_sftpd. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-23942. The attack may be performed from remote. There is no available exploit.
A vulnerability classified as problematic has been found in Erlang OTP. This affects an unknown part in the library lib/ssh/src/ssh_transport.erl. The manipulation leads to highly compressed data.
This vulnerability is referenced as CVE-2026-23943. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in ImageMagick. This impacts an unknown function of the component FreeType. Performing a manipulation results in use after free.
This vulnerability is known as CVE-2026-61860. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability labeled as problematic has been found in ImageMagick. The affected element is an unknown function of the component Script Operation. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-61859. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in Open5GS up to 2.7.7. It has been declared as problematic. Affected is the function pcf_nbsf_management_handle_register of the file src/pcf/nbsf-handler.c of the component sm-policies Endpoint. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2026-8222. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in Open5GS up to 2.7.7. It has been rated as problematic. Affected by this vulnerability is the function pcf_sess_sbi_discover_and_send of the component sm-policies Endpoint. Performing a manipulation results in denial of service.
This vulnerability is cataloged as CVE-2026-8223. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability categorized as problematic has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of the argument SmPolicyContextData.ipv6AddressPrefix can lead to denial of service.
This vulnerability is registered as CVE-2026-8224. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability identified as problematic has been detected in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-8225. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability classified as critical has been found in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection.
This vulnerability is known as CVE-2026-8229. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure.
A vulnerability classified as critical was found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection.
This vulnerability is handled as CVE-2026-8230. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure.
A vulnerability labeled as problematic has been found in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in denial of service.
This vulnerability is reported as CVE-2026-8226. The attack can be launched remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability marked as critical has been reported in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection.
This vulnerability appears as CVE-2026-8227. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure.
A vulnerability described as critical has been identified in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command injection.
This vulnerability is traded as CVE-2026-8228. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure.
A vulnerability was found in Devs Palace ERP Online up to 4.0.0 and classified as problematic. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-8220. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Devs Palace ERP Online up to 4.0.0. It has been classified as problematic. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2026-8221. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Project Management, Bug and Issue Tracking Plugin up to 5.0.x on WordPress. It has been classified as critical. This affects an unknown function of the component Issue-Tracker Configuration. Performing a manipulation results in improper authentication.
This vulnerability was named CVE-2026-12877. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.