CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  22571 articles  ·  updated every 4 hours · grows forever

22571Total
19183Full Text
May 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 29, 2026
[webapps] Craft CMS 5.6.16 - RCE

Craft CMS 5.6.16 - RCE

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
[webapps] HAX CMS 24.x - Stored Cross-Site Scripting (XSS)

HAX CMS 24.x - Stored Cross-Site Scripting (XSS)

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2025-10503 | WSO2 Identity Server up to 7.0.0.87 Authentication Endpoint cross site scripting

A vulnerability was found in WSO2 Identity Server . It has been declared as problematic . This issue affects some unknown processing of the component Authentication Endpoint . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42513 | CDAC-Noida e-Sushrut Hospital Management Information System Server Response improper authentication (CIVN-2026-0207)

A vulnerability was found in CDAC-Noida e-Sushrut Hospital Management Information System . It has been rated as critical . Impacted is an unknown function of the component Server Response Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42514 | CDAC-Noida e-Sushrut Hospital Management Information System API cleartext transmission (CIVN-2026-0207)

A vulnerability categorized as problematic has been discovered in CDAC-Noida e-Sushrut Hospital Management Information System . The affected element is an unknown function of the component API . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42515 | CDAC-Noida e-Sushrut Hospital Management Information System API Request authorization (CIVN-2026-0207)

A vulnerability identified as problematic has been detected in CDAC-Noida e-Sushrut Hospital Management Information System . The impacted element is an unknown function of the component API Request Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42412 | weDevs WP User Frontend Plugin up to 4.3.1 on WordPress authorization

A vulnerability labeled as critical has been found in weDevs WP User Frontend Plugin up to 4.3.1 on WordPress. This affects an unknown function. Such manipulation leads to missing authorization. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7384 | ezequiroga mcp-bases research_server.py search_papers topic path traversal

A vulnerability marked as critical has been reported in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566e9c0d15a16414c . This impacts the function search_papers…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7386 | fatbobman mail-mcp-bridge up to 1.3.3 src/mail_mcp_server.py message_ids path traversal

A vulnerability described as critical has been identified in fatbobman mail-mcp-bridge up to 1.3.3 . Affected is an unknown function of the file src/mail_mcp_server.py . Executing a manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-4019 | Complianz Plugin up to 7.4.5 on WordPress REST API Endpoint cmplz_rest_consented_content authorization

A vulnerability classified as problematic has been found in Complianz Plugin up to 7.4.5 on WordPress. Affected by this vulnerability is the function cmplz_rest_consented_content of the component REST…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42518 | CDAC-Noida e-Sushrut Hospital Management Information System hard-coded key (CIVN-2026-0207)

A vulnerability classified as problematic was found in CDAC-Noida e-Sushrut Hospital Management Information System . Affected by this issue is some unknown functionality. The manipulation results in u…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42516 | CDAC-Noida e-Sushrut Hospital Management Information System encoded authorization (CIVN-2026-0207)

A vulnerability, which was classified as critical , has been found in CDAC-Noida e-Sushrut Hospital Management Information System . This affects an unknown part. This manipulation of the argument enco…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42517 | CDAC-Noida e-Sushrut Hospital Management Information System Base64 Encoding authorization (CIVN-2026-0207)

A vulnerability, which was classified as problematic , was found in CDAC-Noida e-Sushrut Hospital Management Information System . This vulnerability affects unknown code of the component Base64 Encodi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-3325 | CRM Sistemas de Fidelización MegaCMS 12.0.0 POST Request get_provincias id_territorio sql injection

A vulnerability has been found in CRM Sistemas de Fidelización MegaCMS 12.0.0 and classified as critical . This issue affects some unknown processing of the file /web_comunications/cms/get_provincias …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7388 | EyouCMS up to 1.7.9 Template File FilemanagerLogic.php editFile code injection (IILDJS)

A vulnerability was found in EyouCMS up to 1.7.9 and classified as critical . Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7389 | EyouCMS up to 1.7.9 application/common.php GetSortData sort_asc sql injection (IILFPE)

A vulnerability was found in EyouCMS up to 1.7.9 . It has been classified as critical . The affected element is the function GetSortData of the file application/common.php . The manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7390 | SourceCodester Pharmacy Sales and Inventory System 1.0 /index.php?page=customer Name cross site scripting

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0 . It has been declared as problematic . The impacted element is the function Customer of the file /index.php?page=cu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7391 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=save_supplier ID sql injection

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0 . It has been rated as critical . This affects the function save_supplier of the file /ajax.php?action=save_supplier…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7392 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=delete_supplier ID sql injection

A vulnerability categorized as critical has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0 . This impacts the function delete_supplier of the file /ajax.php?action=delete_su…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7393 | SourceCodester Pizzafy Ecommerce System 1.0 File Extension admin_class_novo.php save_menu img unrestricted upload

A vulnerability identified as critical has been detected in SourceCodester Pizzafy Ecommerce System 1.0 . Affected is the function save_menu of the file /admin/admin_class_novo.php of the component Fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7394 | SourceCodester Pizzafy Ecommerce System 1.0 GET Parameter /admin/view_order.php ID sql injection

A vulnerability labeled as critical has been found in SourceCodester Pizzafy Ecommerce System 1.0 . Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7396 | NousResearch hermes-agent 0.8.0 WeChat Work Platform Adapter wecom.py path traversal (Issue 8733)

A vulnerability marked as critical has been reported in NousResearch hermes-agent 0.8.0 . Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component W…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7397 | NousResearch hermes-agent 0.8.0 tools/file_tools.py _check_sensitive_path symlink (Issue 8734)

A vulnerability described as critical has been identified in NousResearch hermes-agent 0.8.0 . This affects the function _check_sensitive_path of the file tools/file_tools.py . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7398 | florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54 Upload Endpoint app.py upload Name path traversal

A vulnerability classified as critical has been found in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54 . This vulnerability affects the function Upload of the file bioinfo…

VulDB Read →
← Prev 207 / 941 Next →