CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  22382 articles  ·  updated every 4 hours · grows forever

22382Total
19066Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-39852 | io.quarkus:quarkus-vertx-http HTTP Request /api/admin authorization

A vulnerability was found in io.quarkus:quarkus-vertx-http . It has been declared as critical . Affected by this vulnerability is an unknown functionality of the file /api/admin of the component HTTP …

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-4362 | roxnor ElementsKit Elementor Addons Plugin up to 3.8.2 on WordPress Live_Action::reset authorization (EUVD-2026-27213)

A vulnerability was found in roxnor ElementsKit Elementor Addons Plugin up to 3.8.2 on WordPress. It has been rated as critical . Affected by this issue is the function Live_Action::reset . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7832 | IObit Advanced SystemCare 19 Service ASC.exe symlink

A vulnerability categorized as critical has been discovered in IObit Advanced SystemCare 19 . This affects an unknown part of the file ASC.exe of the component Service . The manipulation results in sy…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7833 | EFM ipTIME C200 up to 1.092 ApplyRestore Endpoint /cgi/iux_set.cgi sub_408F90 RestoreFile command injection

A vulnerability identified as critical has been detected in EFM ipTIME C200 up to 1.092 . This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the component ApplyRestore …

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7834 | EFM ipTIME NAS1dual 1.5.24 misc_main.cgi get_csrf_whites stack-based overflow

A vulnerability labeled as critical has been found in EFM ipTIME NAS1dual 1.5.24 . This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi . Such manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-2729 | wpmudev Forminator Forms Plugin up to 1.52.0 on WordPress authorization (EUVD-2026-27223)

A vulnerability marked as critical has been reported in wpmudev Forminator Forms Plugin up to 1.52.0 on WordPress. Impacted is an unknown function. Performing a manipulation results in authorization b…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-3454 | edge22 GenerateBlocks Plugin up to 2.2.0 on WordPress REST Endpoint dynamic-tag-replacements ID authorization (EUVD-2026-27225)

A vulnerability described as problematic has been identified in edge22 GenerateBlocks Plugin up to 2.2.0 on WordPress. The affected element is an unknown function of the file /wp-json/generateblocks/v…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-5192 | wpmudev Forminator Forms Plugin up to 1.52.1 on WordPress File Upload file_path path traversal (EUVD-2026-27229)

A vulnerability classified as critical has been found in wpmudev Forminator Forms Plugin up to 1.52.1 on WordPress. The impacted element is the function file_path of the component File Upload . The ma…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-6180 | PaperCut NG/MF up to 24.1.8/25.0.9 toctou

A vulnerability classified as critical was found in PaperCut NG and MF up to 24.1.8/25.0.9 . This affects an unknown function. The manipulation results in time-of-check time-of-use. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-40797 | Saleswonder WebinarIgnition Plugin up to 4.08.253 on WordPress sql injection (EUVD-2026-27227)

A vulnerability, which was classified as critical , has been found in Saleswonder WebinarIgnition Plugin up to 4.08.253 on WordPress. This impacts an unknown function. This manipulation causes sql inj…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-6418 | PaperCut NG/MF up to 25.0.10 Account Synchronization absolute path traversal

A vulnerability, which was classified as problematic , was found in PaperCut NG and MF up to 25.0.10 . Affected is an unknown function of the component Account Synchronization Component . Such manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7824 | PaperCut Hive up to 2.1.x log file

A vulnerability has been found in PaperCut Hive up to 2.1.x and classified as problematic . Affected by this vulnerability is an unknown functionality. Performing a manipulation results in sensitive i…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-3359 | 10web Form Maker Plugin up to 1.15.42 on WordPress inputs sql injection

A vulnerability was found in 10web Form Maker Plugin up to 1.15.42 on WordPress and classified as critical . Affected by this issue is some unknown functionality. Executing a manipulation of the argum…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-3601 | wpeverest User Registration & Membership Plugin up to 5.1.4 on WordPress Shortcode embed_form_action authorization

A vulnerability was found in wpeverest User Registration & Membership Plugin up to 5.1.4 on WordPress. It has been classified as critical . This affects the function embed_form_action of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7844 | chatchat-space Langchain-Chatchat up to 0.3.1.3 Compatible File Service openai_routes.py missing authentication (Issue 5465)

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3 . It has been declared as critical . This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_c…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7845 | chatchat-space Langchain-Chatchat up to 0.3.1.3 Vision Chat Paste Image dialogue.py PIL.Image.tobytes paste_image.image_data weak hash (Issue 5462)

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3 . It has been rated as problematic . This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/cha…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7846 | chatchat-space Langchain-Chatchat up to 0.3.1.3 OpenAI-Compatible File Upload API openai_routes.py files file.filename toctou (Issue 5463)

A vulnerability categorized as problematic has been discovered in chatchat-space Langchain-Chatchat up to 0.3.1.3 . Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7847 | chatchat-space Langchain-Chatchat up to 0.3.1.3 Uploaded File openai_routes.py _get_file_id random values (Issue 5464)

A vulnerability identified as problematic has been detected in chatchat-space Langchain-Chatchat up to 0.3.1.3 . The affected element is the function _get_file_id of the file libs/chatchat-server/chat…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-6322 | fast-uri up to 3.1.1 normalize interpretation conflict

A vulnerability labeled as problematic has been found in fast-uri up to 3.1.1 . The impacted element is the function normalize . Executing a manipulation can lead to interpretation conflict. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7851 | D-Link DI-8100 16.07.26A1 yyxz.asp sprintf ID stack-based overflow

A vulnerability marked as critical has been reported in D-Link DI-8100 16.07.26A1 . This affects the function sprintf of the file yyxz.asp . The manipulation of the argument ID leads to stack-based bu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2025-42611 | Mikrotik RouterOS up to 7.20.x certificate validation

A vulnerability described as critical has been identified in Mikrotik RouterOS up to 7.20.x . This impacts an unknown function. The manipulation results in improper certificate validation. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7853 | D-Link DI-8100 16.07.26A1 HTTP /auto_reboot.asp sprintf enable/time buffer overflow

A vulnerability classified as critical has been found in D-Link DI-8100 16.07.26A1 . Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler . This manipulation of …

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7854 | D-Link DI-8100 16.07.26A1 POST Parameter /url_rule.asp url_rule_asp buffer overflow

A vulnerability classified as critical was found in D-Link DI-8100 16.07.26A1 . Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7855 | D-Link DI-8100 16.07.26A1 HTTP Request /tggl.asp tggl_asp Name buffer overflow

A vulnerability, which was classified as critical , has been found in D-Link DI-8100 16.07.26A1 . Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Ha…

VulDB Read →
← Prev 176 / 933 Next →