A vulnerability was found in nic Knot Resolver up to 6.4.0. It has been declared as critical. Affected by this issue is some unknown functionality of the component DNS-over-QUIC. Executing a manipulation can lead to buffer overflow.
This vulnerability is tracked as CVE-2026-66374. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in Redis up to 8.7.x. It has been classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in double free.
This vulnerability is identified as CVE-2026-66373. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.7. Affected is an unknown function of the file team/channel of the component Microsoft Teams Plugin. The manipulation of the argument groupAllowFrom leads to incorrect authorization.
This vulnerability is listed as CVE-2026-34506. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in OpenClaw up to 2026.3.11. Affected by this issue is some unknown functionality. The manipulation results in improper restriction of excessive authentication attempts.
This vulnerability is identified as CVE-2026-34505. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in NocoBase up to 2.0.27. Impacted is an unknown function. Performing a manipulation results in dynamically-managed code resources.
This vulnerability is identified as CVE-2026-34156. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Giskard-AI giskard-oss up to 0.3.3/1.0.2. This vulnerability affects the function ChatWorkflow.chat of the component Name Message Handler. The manipulation results in improper neutralization of special elements used in a template engine.
This vulnerability is known as CVE-2026-34172. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in wevm mppx up to 0.4.10. This impacts an unknown function. The manipulation results in authentication bypass by capture-replay.
This vulnerability is identified as CVE-2026-34209. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in wevm mppx up to 0.4.10. Affected is an unknown function. This manipulation causes incorrect comparison.
This vulnerability is tracked as CVE-2026-34210. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in ZcashFoundation zebra and zebra-chain. It has been classified as problematic. This vulnerability affects unknown code of the component Transaction ID Handler. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is documented as CVE-2026-34202. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability categorized as critical has been discovered in labring FastGPT up to 4.14.7. The affected element is the function isInternalAddress of the file /api/core/app/mcpTools/getTools. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-34163. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability marked as problematic has been reported in go-git up to 5.17.0. This impacts an unknown function. The manipulation leads to integer underflow.
This vulnerability is uniquely identified as CVE-2026-34165. Local access is required to approach this attack. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in parse-community parse-server up to 8.6.63/9.7.0-alpha.7. It has been declared as problematic. The impacted element is an unknown function of the component authData Login Endpoint. Such manipulation leads to time-of-check time-of-use.
This vulnerability is documented as CVE-2026-34224. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in trinodb trino up to 479. This vulnerability affects unknown code. Performing a manipulation results in improper removal of sensitive information before storage or transfer.
This vulnerability was named CVE-2026-34214. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as very critical, was found in rauc up to 1.15.1. This affects an unknown function. The manipulation results in unsigned to signed conversion error.
This vulnerability is cataloged as CVE-2026-34155. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Nhost up to 1.40.x. This affects an unknown function. Executing a manipulation can lead to missing authentication.
This vulnerability is handled as CVE-2026-34200. It is possible to launch the attack on the local host. There is not any exploit available.
The affected component should be upgraded.