CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  47181 articles  ·  updated every 4 hours · grows forever

47181Total
32679Full Text
Aug 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5562 | provectus kafka-ui up to 0.7.2 Endpoint testexecutions validateAccess code injection

A vulnerability marked as critical has been reported in provectus kafka-ui up to 0.7.2 . This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5563 | AutohomeCorp frostmourne up to 1.0 Alarm Preview previewData httpTest sql injection

A vulnerability described as critical has been identified in AutohomeCorp frostmourne up to 1.0 . Affected is the function httpTest of the file /api/monitor-api/alarm/previewData of the component Alar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5564 | code-projects Simple Laundry System 1.0 Parameter /searchguest.php searchServiceId sql injection

A vulnerability classified as critical has been found in code-projects Simple Laundry System 1.0 . Affected by this vulnerability is an unknown functionality of the file /searchguest.php of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5565 | code-projects Simple Laundry System 1.0 Parameter /delmemberinfo.php userid sql injection

A vulnerability classified as critical was found in code-projects Simple Laundry System 1.0 . Affected by this issue is some unknown functionality of the file /delmemberinfo.php of the component Param…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5566 | UTT HiPER 1250GW up to 3.2.7-210907-180535 /goform/formNatStaticMap strcpy NatBind buffer overflow

A vulnerability, which was classified as critical , has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535 . This affects the function strcpy of the file /goform/formNatStaticMap . Performing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5567 | Tenda M3 1.0.0.10 Destination /goform/setAdvPolicyData policyType buffer overflow

A vulnerability, which was classified as critical , was found in Tenda M3 1.0.0.10 . This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Dest…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5568 | Akaunting up to 3.1.21 Invoice/Billing notes cross site scripting

A vulnerability has been found in Akaunting up to 3.1.21 and classified as problematic . This issue affects some unknown processing of the component Invoice/Billing . The manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5569 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 Endpoint /Technostrobe/ access control

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 and classified as critical . Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5570 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 /LoginCB index_config improper authentication

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been classified as critical . The affected element is the function index_config of the file /LoginCB . This manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5571 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 Configuration Data /fs File information disclosure

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been declared as problematic . The impacted element is an unknown function of the file /fs of the component Configura…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5572 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 cross-site request forgery

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been rated as problematic . This affects an unknown function. Performing a manipulation results in cross-site request…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5573 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 /fs cwd unrestricted upload

A vulnerability categorized as critical has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . This impacts an unknown function of the file /fs . Executing a manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5574 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 FsBrowseClean deletefile dir/path authorization

A vulnerability identified as problematic has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . Affected is the function deletefile of the component FsBrowseClean . The manipulation of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5575 | SourceCodester/jkev Record Management System 1.0 Login index.php Username sql injection

A vulnerability labeled as critical has been found in SourceCodester/jkev Record Management System 1.0 . Affected by this vulnerability is an unknown functionality of the file index.php of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5576 | SourceCodester/jkev Record Management System 1.0 Add Employee Page save_emp.php unrestricted upload

A vulnerability marked as critical has been reported in SourceCodester/jkev Record Management System 1.0 . Affected by this issue is some unknown functionality of the file save_emp.php of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5577 | Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a details Endpoint uniquemachine_app.py ID sql injection

A vulnerability described as critical has been identified in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a . This affects an unknown part of the file flask/uniquemachine_app.py …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5578 | CodeAstro Online Classroom 1.0 Parameter addassessment.php deleteid sql injection

A vulnerability classified as critical has been found in CodeAstro Online Classroom 1.0 . This vulnerability affects unknown code of the file /OnlineClassroom/addassessment.php of the component Parame…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5579 | CodeAstro Online Classroom 1.0 Parameter updatedetailsfromfaculty.php?myfid=108 fname sql injection

A vulnerability classified as critical was found in CodeAstro Online Classroom 1.0 . This issue affects some unknown processing of the file /OnlineClassroom/updatedetailsfromfaculty.php?myfid=108 of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5580 | CodeAstro Online Classroom 1.0 Parameter addvideos.php videotitle sql injection

A vulnerability, which was classified as critical , has been found in CodeAstro Online Classroom 1.0 . Impacted is an unknown function of the file /OnlineClassroom/addvideos.php of the component Param…

VulDB Read →
◇ Industry News & Leadership Apr 04, 2026
Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild

Fortinet has issued an emergency hotfix after security researchers disclosed a critical zero-day vulnerability in FortiClient EMS that is already being actively exploited by threat actors. Tracked as …

Cybersecurity News Read →
◇ Industry News & Leadership Apr 04, 2026
FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)

Defused Cyber has spotted a critical Fortinet FortiClient Endpoint Management Server (EMS) zero-day vulnerability (CVE-2026-35616) being exploited in the wild. This time around, the confirmation of ac…

Help Net Security Read →
◇ Industry News & Leadership Apr 04, 2026
LinkedIn secretly scans for 6,000+ Chrome extensions, collects data

A new report dubbed "BrowserGate" warns that Microsoft's LinkedIn is using hidden JavaScript scripts on its website to scan visitors' browsers for installed extensions and collect device data. [...]

Bleeping Computer Read →
◇ Industry News & Leadership Apr 04, 2026
Device code phishing attacks surge 37x as new kits spread online

Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. [...]

Bleeping Computer Read →
◇ Industry News & Leadership Apr 04, 2026
Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations - The Hacker News

Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations The Hacker News

The Hacker News Read →
← Prev 1544 / 1966 Next →