Deepfakes and injection attacks are targeting identity verification moments, from onboarding to account recovery. Incode explains why enterprises must validate the full session—media, device integrity, and behavior—to stop synthetic and injected attacks in real time. [...]
A vulnerability classified as problematic has been found in Tygo-van-den-Hurk Slyde up to 0.0.4. Affected by this issue is the function node_modules. Performing a manipulation results in inclusion of functionality from untrusted control sphere.
This vulnerability was named CVE-2026-26974. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in gVectors wpForo Forum up to 2.4.14 and classified as critical. Affected by this vulnerability is the function Topics::get_topics. The manipulation of the argument wpfob results in sql injection.
This vulnerability is reported as CVE-2026-28562. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability identified as problematic has been detected in gVectors wpForo Forum up to 2.4.15. Impacted is the function json_encode. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-28560. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability marked as problematic has been reported in gVectors wpForo Forum up to 2.4.15. The impacted element is an unknown function. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-28561. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in gVectors wpForo Forum up to 2.4.15 and classified as critical. Affected is the function wpforo_synch_roles of the component AJAX Handler. The manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-28557. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability categorized as problematic has been discovered in gVectors wpForo Forum up to 2.4.15. This issue affects some unknown processing of the component SVG File Parser. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-28558. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in gVectors wpForo Forum up to 2.4.15. The affected element is an unknown function of the component Global RSS Feed Endpoint. The manipulation of the argument ID results in information disclosure.
This vulnerability was named CVE-2026-28559. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability labeled as critical has been found in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSafeMacFilter of the file /goform/SafeMacFilter. Such manipulation of the argument page leads to buffer overflow.
This vulnerability is referenced as CVE-2026-3376. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Russia-linked APT28 reportedly exploited MSHTML zero-day CVE-2026-21513 before Microsoft patched it, a high-severity bypass flaw. Akamai reports that Russia-linked APT28 may have exploited CVE-2026-21513 CVSS score of 8.8), a high-severity MSHTML vulnerability (CVSS 8.8), before Microsoft patched it in February 2026. The vulnerability is an Internet Explorer security control bypass that can lead to code […]
A vulnerability identified as critical has been detected in denoland deno up to 2.6.7. Affected by this vulnerability is the function child_process. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-27190. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in vapor leaf-kit up to 1.4.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Special Character Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-27120. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Slican NCP, IPL, IPM and IPU. This vulnerability affects unknown code of the file /webcti/session_ajax.php of the component Request Handler. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2025-14577. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in gVectors wpForo Forum up to 2.4.15. It has been classified as critical. Affected by this issue is the function wpforo_approve_ajax of the component AJAX Handler. This manipulation causes missing authorization.
This vulnerability appears as CVE-2026-28554. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in gVectors wpForo Forum up to 2.4.15. It has been declared as critical. This affects the function wpforo_close_ajax. Such manipulation leads to missing authorization.
This vulnerability is traded as CVE-2026-28555. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in gVectors wpForo Forum up to 2.4.15. It has been rated as critical. This vulnerability affects the function topic_move/topic_merge/topic_split. Performing a manipulation results in missing authorization.
This vulnerability is known as CVE-2026-28556. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.