8.8
CVE-2026-1618 - Admin Account Takeover in Universal Sotware's FlexCity/Kiosk
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.
8.8
CVE-2025-14349 - Business Logic Error in Universal Software's FlexCity/Kiosk
Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Properly Constrained by ACLs, Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.
7.3
CVE-2025-33042 - Apache Avro Java SDK: Code injection on Java generated code
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and versionΒ 1.12.0. Users are recommended to upgrade to version 1.12.1β¦
0.0
CVE-2026-26302 -
Not used
0.0
CVE-2026-26303 -
Not used
0.0
CVE-2026-26297 -
Not used
0.0
CVE-2026-26300 -
Not used
0.0
CVE-2026-26301 -
Not used
0.0
CVE-2026-26299 -
Not used
0.0
CVE-2026-26298 -
Not used