A vulnerability was found in GeoVision GV-IP Device Utility up to 9.0.7.0 and classified as critical. Affected is an unknown function. Executing a manipulation can lead to uncontrolled search path.
This vulnerability is handled as CVE-2026-16519. It is possible to launch the attack on the local host. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in wpmanageninja Fluent Support Plugin up to 2.3.0 on WordPress and classified as problematic. This impacts an unknown function of the component Shortcode Handler. Performing a manipulation of the argument redirect-to results in cross site scripting.
This vulnerability is known as CVE-2026-15665. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability, which was classified as problematic, was found in meIsle Visualizer Plugin up to 4.0.5 on WordPress. This affects an unknown function. Such manipulation of the argument backend-title leads to cross site scripting.
This vulnerability is traded as CVE-2026-15653. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in ThimPress WP Hotel Booking Plugin up to 2.3.2 on WordPress. The impacted element is an unknown function of the component Shortcode Handler. This manipulation of the argument widget_search causes cross site scripting.
This vulnerability appears as CVE-2026-15464. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as problematic was found in cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress. The affected element is an unknown function. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-15334. The attack can be launched remotely. No exploit exists.
A vulnerability classified as problematic has been found in cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress. Impacted is an unknown function. The manipulation of the argument cozyCustomFont leads to cross site scripting.
This vulnerability is documented as CVE-2026-15333. The attack can be initiated remotely. There is not any exploit available.
A vulnerability described as problematic has been identified in 100plugins Open User Map Plugin up to 1.4.45 on WordPress. This issue affects some unknown processing of the component Shortcode Handler. Executing a manipulation of the argument Shortcode can lead to cross site scripting.
This vulnerability is registered as CVE-2026-15755. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as problematic has been reported in berocket Brands for WooCommerce Plugin up to 3.8.8 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler. Performing a manipulation of the argument width results in cross site scripting.
This vulnerability is cataloged as CVE-2026-15648. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as problematic has been found in Red Hat OpenShift Update Service and Quay. This affects an unknown part of the component Notification Webhook. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-16910. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as problematic has been detected in paymentplugins Payment Plugins for Stripe WooCommerce Plugin up to 4.0.7 on WordPress. Affected by this issue is the function payment_complete of the component Signature Verification. This manipulation of the argument order_id/gateway_id/status causes authorization bypass.
This vulnerability is tracked as CVE-2026-12654. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Open5GS up to 2.7.7. It has been declared as problematic. Affected is the function pcf_nbsf_management_handle_register of the file src/pcf/nbsf-handler.c of the component sm-policies Endpoint. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2026-8222. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in Open5GS up to 2.7.7. It has been rated as problematic. Affected by this vulnerability is the function pcf_sess_sbi_discover_and_send of the component sm-policies Endpoint. Performing a manipulation results in denial of service.
This vulnerability is cataloged as CVE-2026-8223. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability categorized as problematic has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of the argument SmPolicyContextData.ipv6AddressPrefix can lead to denial of service.
This vulnerability is registered as CVE-2026-8224. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability identified as problematic has been detected in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-8225. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.