CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  43776 articles  ·  updated every 4 hours · grows forever

43776Total
30977Full Text
Aug 12, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6614 | TransformerOptimus SuperAGI up to 0.0.14 project.py authorization

A vulnerability, which was classified as critical , was found in TransformerOptimus SuperAGI up to 0.0.14 . Affected by this vulnerability is the function get_project/update_project/get_projects_organ…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6615 | TransformerOptimus SuperAGI up to 0.0.14 Multipart Upload resources.py upload Name path traversal

A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14 and classified as critical . Affected by this issue is the function Upload of the file superagi/controllers/resources.py of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6616 | TransformerOptimus SuperAGI up to 0.0.14 WebScraperTool webpage_extractor.py server-side request forgery

A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14 and classified as critical . This affects the function extract_with_bs4/extract_with_3k/extract_with_lxml of the file superagi/hel…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6617 | langgenius dify up to 0.6.9 ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema url server-side request forgery

A vulnerability was found in langgenius dify up to 0.6.9 . It has been classified as critical . This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/too…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6618 | langgenius dify up to 1.13.3 ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle url server-side request forgery

A vulnerability was found in langgenius dify up to 1.13.3 . It has been declared as critical . This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6619 | langgenius dify up to 1.13.3 ImagePreview image-preview.tsx openInNewTab filename cross site scripting

A vulnerability was found in langgenius dify up to 1.13.3 . It has been rated as problematic . Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.ts…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6620 | SonicCloudOrg sonic-server up to 2.0.0 File Upload Endpoint FileTool.java upload Type path traversal

A vulnerability categorized as critical has been discovered in SonicCloudOrg sonic-server up to 2.0.0 . The affected element is the function Upload of the file FileTool.java of the component File Uplo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6621 | 1024bit extend-deep up to 0.1.6 index.js __proto__ prototype pollution

A vulnerability identified as critical has been detected in 1024bit extend-deep up to 0.1.6 . The impacted element is an unknown function of the file index.js . This manipulation of the argument __pro…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6622 | BichitroGan ISP Billing Software 2025.3.20 Customer edit cross site scripting

A vulnerability labeled as problematic has been found in BichitroGan ISP Billing Software 2025.3.20 . This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6623 | BichitroGan ISP Billing Software 2025.3.20 Profile Page users-view cross site scripting

A vulnerability marked as problematic has been reported in BichitroGan ISP Billing Software 2025.3.20 . This impacts an unknown function of the file /?_route=settings/users-view/ of the component Prof…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6624 | BichitroGan ISP Billing Software 2025.3.20 Pool List Interface /?\_route=pool/add cross site scripting

A vulnerability described as problematic has been identified in BichitroGan ISP Billing Software 2025.3.20 . Affected is an unknown function of the file /?\_route=pool/add of the component Pool List I…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6625 | moxi624 Mogu Blog v2 up to 5.2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgery

A vulnerability classified as critical has been found in moxi624 Mogu Blog v2 up to 5.2 . Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_pictur…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6626 | Cockpit-HQ Cockpit up to 2.13.5 Asset Handler/Aggregate data query logic injection

A vulnerability classified as critical was found in Cockpit-HQ Cockpit up to 2.13.5 . Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6628 | phili67 Ecclesia CRM up to 8.0.0 Query Viewer /v2/query/view/ ValidateInput custom sql injection

A vulnerability, which was classified as critical , has been found in phili67 Ecclesia CRM up to 8.0.0 . This affects the function ValidateInput of the file /v2/query/view/ of the component Query View…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6629 | Metasoft 美特软件 MetaCRM up to 6.4.0 Interface sql.jsp Statement.executeUpdate sql sql injection

A vulnerability, which was classified as critical , was found in Metasoft 美特软件 MetaCRM up to 6.4.0 . This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6630 | Tenda F451 1.0.0.7_cn_svn7958 httpd /goform/GstDhcpSetSer fromGstDhcpSetSer dips buffer overflow

A vulnerability has been found in Tenda F451 1.0.0.7_cn_svn7958 and classified as critical . This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6631 | Tenda F451 1.0.0.7_cn_svn7958 httpd webExcptypemanFilter fromwebExcptypemanFilter page buffer overflow

A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958 and classified as critical . Impacted is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component http…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6632 | Tenda F451 1.0.0.7_cn_svn7958 httpd /goform/SafeClientFilter fromSafeClientFilter menufacturer/Go buffer overflow

A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958 . It has been classified as critical . The affected element is the function fromSafeClientFilter of the file /goform/SafeClientFilter of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6633 | Yifang CMS up to 2.0.5 Extended Management L_rbac_admin.php store Account cross site scripting

A vulnerability was found in Yifang CMS up to 2.0.5 . It has been declared as problematic . The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_adm…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6634 | usememos up to 0.22.1 UpdateInstanceSetting src/App.tsx memos_access_token additionalStyle/additionalScript improper authorization

A vulnerability was found in usememos memos up to 0.22.1 . It has been rated as critical . This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6635 | rowboatlabs rowboat up to 0.1.67 tools_webhook app.py tool_call X-Tools-JWE improper authentication

A vulnerability categorized as critical has been discovered in rowboatlabs rowboat up to 0.1.67 . This impacts the function tool_call of the file apps/experimental/tools_webhook/app.py of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6636 | p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b API buildCache.js Bun.serve pathname path traversal

A vulnerability identified as critical has been detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b . Affected is the function Bun.serve of the file buildCache.js of the component …

VulDB Read →
◇ Industry News & Leadership Apr 19, 2026
Apple account change alerts abused to send phishing emails

Apple account change notifications are being abused to send fake iPhone purchase phishing scams within legitimate emails sent from Apple's servers, increasing legitimacy and potentially allowing them …

Bleeping Computer Read →
◇ Industry News & Leadership Apr 19, 2026
Vercel confirms breach as hackers claim to be selling stolen data

Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data. [...]

Bleeping Computer Read →
← Prev 1206 / 1824 Next →