A vulnerability has been found in crmeb_java up to 1.3.4 and classified as critical. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a manipulation of the argument model results in unrestricted upload.
This vulnerability is known as CVE-2026-7673. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.java of the component Users Endpoint. Such manipulation of the argument order leads to sql injection.
This vulnerability is traded as CVE-2026-7672. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
Deep#Door hides a Python RAT inside a batch file, kills Windows defenses, survives via multiple persistence methods, and exfiltrates data through a public TCP tunnel. Security researchers at Securonix uncovered a sophisticated malware campaign called Deep#Door. Threat actors employed a stealthy Python-based backdoor that uses a surprisingly simple delivery method to achieve deep, persistent access […]
A vulnerability, which was classified as critical, has been found in wproyal Royal Addons for Elementor Plugin up to 1.7.1057 on WordPress. Affected by this issue is the function render_csv_data of the component Query Parameter Handler. This manipulation causes server-side request forgery.
This vulnerability appears as CVE-2026-6229. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as critical was found in cyberhobo Geo Mashup Plugin up to 1.13.19 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation of the argument geo_mashup_null_fields results in sql injection.
This vulnerability is reported as CVE-2026-6457. The attack can be launched remotely. No exploit exists.
A vulnerability described as critical has been identified in thimpress FundPress Plugin up to 2.0.8 on WordPress. This impacts the function donate_action_status of the component AJAX Handler. Executing a manipulation can lead to missing authorization.
This vulnerability is registered as CVE-2026-4650. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as critical has been reported in Marketing Fire Widget Options Plugin up to 4.2.2 on WordPress. This affects the function eval. Performing a manipulation of the argument extended_widget_opts_block results in code injection.
This vulnerability is cataloged as CVE-2026-2052. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as problematic has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. Such manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is listed as CVE-2026-7671. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability identified as critical has been detected in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This manipulation of the argument DeptIDList causes sql injection.
This vulnerability is tracked as CVE-2026-7670. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability categorized as critical has been discovered in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization.
This vulnerability is identified as CVE-2026-7669. The attack can be executed remotely. There is not any exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Linux Kernel up to 6.6.135/6.12.82/6.18.23/6.19.13/7.0.0. It has been rated as critical. This issue affects the function vidtv_ts_null_write_into of the component media. The manipulation leads to stack-based buffer overflow.
This vulnerability is referenced as CVE-2026-43058. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.