A vulnerability was found in JeecgBoot 3.9.1. It has been declared as critical. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulation leads to improper authentication.
This vulnerability is documented as CVE-2026-9373. The attack can be executed remotely. There is not any exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in ItzCrazyKns Vane up to 1.12.1. It has been classified as critical. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of the argument baseURL causes server-side request forgery.
This vulnerability is registered as CVE-2026-9372. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in Linux Kernel up to 7.0.9 and classified as critical. This affects the function skb_try_coalesce of the component net. The manipulation results in infinite loop.
This vulnerability is cataloged as CVE-2026-43503. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in ItzCrazyKns Vane up to 1.12.1 and classified as problematic. Affected by this issue is some unknown functionality of the file route.ts of the component API. The manipulation leads to missing authentication.
This vulnerability is listed as CVE-2026-9371. The attack may be initiated remotely. In addition, an exploit is available.
It is recommended to apply restrictive firewalling.
It appears that basic authentication is planned.
Ransomware gangs are shifting from encryption to pure extortion, focusing on stolen data, reputational pressure, and stealthier attacks. Ransomware groups are quietly changing strategy in 2026. Instead of encrypting systems and causing immediate disruption, many attackers are now focusing on pure extortion: stealing sensitive data and threatening to leak it publicly if victims refuse to […]
A vulnerability identified as critical has been detected in windmill-labs windmill up to 1.703.1. This issue affects some unknown processing of the file /etc of the component Configuration Handler. The manipulation leads to incorrect default permissions.
This vulnerability is traded as CVE-2026-47107. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in innocommerce Innoshop 0.6.0. This affects an unknown function of the component Backend Application Handler. Performing a manipulation results in improper authorization.
This vulnerability was named CVE-2026-39250. The attack needs to be approached within the local network. There is no available exploit.