A vulnerability labeled as problematic has been found in Oracle MySQL Cluster and MySQL Server. This vulnerability affects unknown code of the component Pluggable Auth. Executing a manipulation can lead to an unknown weakness.
This vulnerability is registered as CVE-2026-61096. The attack needs to be launched locally. No exploit is available.
A vulnerability classified as problematic was found in Oracle MySQL Server and MySQL Cluster. This impacts an unknown function of the component Replication. Executing a manipulation can lead to improper privilege management.
This vulnerability appears as CVE-2026-60747. The attack requires local access. There is no available exploit.
A vulnerability was found in matrix-org dendrite up to 0.13.8. It has been declared as problematic. This affects an unknown part of the file syncapi/routing/context.go of the component Context Endpoint. The manipulation of the argument roomexists results in improper access controls. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is cataloged as CVE-2026-63097. The attack must be initiated from a local position. There is no exploit available.
A vulnerability has been found in Notepad++ up to 8.9.3 and classified as critical. The affected element is an unknown function of the component Find Results Panel. The manipulation leads to format string.
This vulnerability is uniquely identified as CVE-2026-6539. Local access is required to approach this attack. No exploit exists.
The affected component should be upgraded.
A vulnerability described as critical has been identified in Siteserver SSCMS 7.4.0. This issue affects some unknown processing of the file /api/stl/actions/dynamic. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-7435. The attack can be executed remotely. There is not any exploit available.
A vulnerability marked as critical has been reported in Taiko AG1000-01A SMS Alert Gateway 7.3/8. Impacted is the function validate of the component Embedded Web Configuration Interface. This manipulation causes hard-coded credentials.
This vulnerability appears as CVE-2026-9139. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Oracle MySQL Server and MySQL Cluster. It has been declared as problematic. Affected is an unknown function of the component Server Performance Schema. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-61081. The attack can be executed remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, has been found in Oracle MySQL Cluster and MySQL Server. The affected element is an unknown function of the component Server: Clone Plugin. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2026-60177. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability, which was classified as problematic, was found in Oracle MySQL Cluster and MySQL Server. This vulnerability affects unknown code of the component Server Replication. The manipulation results in privilege escalation.
This vulnerability was named CVE-2026-61094. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as problematic, was found in Oracle MySQL Cluster and MySQL Server. The impacted element is an unknown function of the component Server Replication. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2026-60190. The attack may be performed from remote. There is no available exploit.
A vulnerability labeled as problematic has been found in ICZ MATCHA SNS up to 1.3.9. This impacts an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-27787. The attack can be launched remotely. No exploit exists.
A vulnerability identified as problematic has been detected in johanaarstein AM LottiePlayer Plugin up to 3.6.0 on WordPress. This vulnerability affects unknown code of the component SVG File Parser. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-1794. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in awesomesupport Awesome Support Plugin up to 6.3.7 on WordPress and classified as problematic. Affected by this issue is the function wpas_get_ticket_replies_ajax. Executing a manipulation of the argument ticket_id can lead to authorization bypass.
This vulnerability appears as CVE-2026-4654. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability was found in bdthemes Element Pack Plugin up to 8.4.2 on WordPress. It has been classified as problematic. This affects the function render_svg of the component SVG Image Widget. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-4655. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in magicplugins Magic Conversation for Gravity Forms Plugin up to 3.0.97 on WordPress. This affects the function magic-conversation of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-1396. Remote exploitation of the attack is possible. No exploit is available.