TeamPCP, the threat actor behind the recentsupply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a fresh Mini Shai-Hulud campaign.
The affected npm packages have been modified to include an obfuscated JavaScript file ("router_init.js") that's designed to profile the execution
A vulnerability categorized as critical has been discovered in WP Travel Plugin up to 11.4.0 on WordPress. This vulnerability affects unknown code. Such manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-45218. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Saad Iqbal WP EasyPay Plugin up to 4.3.0 on WordPress. It has been rated as problematic. This affects an unknown part. This manipulation causes insertion of sensitive information into sent data.
This vulnerability appears as CVE-2026-45215. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Xpro Elementor Addons Plugin up to 1.5.1 on WordPress. It has been declared as critical. Affected by this issue is some unknown functionality. The manipulation results in sql injection.
This vulnerability is reported as CVE-2026-45214. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Vmware Spring AI up to 1.0.6/1.1.5. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Chat Memory. The manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-41712. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
Attackers are exploiting cPanel flaw CVE-2026-41940 to install the Filemanager backdoor and gain unauthorized admin access. Cybercriminals are actively exploiting the critical cPanel vulnerability CVE-2026-41940 (CVSS score of 9.3) to deploy a backdoor called Filemanager on compromised servers. cPanel is a widely used web hosting control panel that lets users manage websites and servers through a […]
A vulnerability was found in Hikvision Hik-Connect APP up to 6.10.x/6.11.x and classified as critical. Affected is an unknown function. Executing a manipulation can lead to permission issues.
This vulnerability is registered as CVE-2026-32684. The attack needs to be launched locally. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability has been found in RealMag777 BEAR Plugin up to 1.1.7.1 on WordPress and classified as critical. This impacts an unknown function. Performing a manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-45213. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Gabe Livan Asset CleanUp Plugin up to 1.4.0.3 on WordPress. This affects an unknown function. Such manipulation leads to missing authorization.
This vulnerability is listed as CVE-2026-45212. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as critical, has been found in Broadstreet Ads Plugin up to 1.52.2 on WordPress. The impacted element is an unknown function. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2026-45210. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability classified as critical was found in Aman Views for WPForms Plugin up to 3.4.6 on WordPress. The affected element is an unknown function. The manipulation results in sql injection.
This vulnerability is identified as CVE-2026-42742. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as critical has been found in Aman Ninja Forms Views Plugin up to 3.3.2 on WordPress. Impacted is an unknown function. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-42741. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability described as critical has been identified in Vmware Spring AI up to 1.0.6/1.1.5. This issue affects some unknown processing of the component Conversation Memory Handler. Executing a manipulation can lead to improper neutralization of special elements used in a template engine.
The identification of this vulnerability is CVE-2026-41713. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Saad Iqbal APIExperts Square for WooCommerce Plugin up to 4.7.1 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in sql injection.
This vulnerability was named CVE-2026-45211. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as very critical has been found in E-Kalite Turboard FOR-S. This affects an unknown part. Such manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2026-2465. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.