CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  22660 articles  ·  updated every 4 hours · grows forever

22660Total
19223Full Text
May 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7384 | ezequiroga mcp-bases research_server.py search_papers topic path traversal

A vulnerability marked as critical has been reported in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566e9c0d15a16414c . This impacts the function search_papers…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7386 | fatbobman mail-mcp-bridge up to 1.3.3 src/mail_mcp_server.py message_ids path traversal

A vulnerability described as critical has been identified in fatbobman mail-mcp-bridge up to 1.3.3 . Affected is an unknown function of the file src/mail_mcp_server.py . Executing a manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-4019 | Complianz Plugin up to 7.4.5 on WordPress REST API Endpoint cmplz_rest_consented_content authorization

A vulnerability classified as problematic has been found in Complianz Plugin up to 7.4.5 on WordPress. Affected by this vulnerability is the function cmplz_rest_consented_content of the component REST…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42518 | CDAC-Noida e-Sushrut Hospital Management Information System hard-coded key (CIVN-2026-0207)

A vulnerability classified as problematic was found in CDAC-Noida e-Sushrut Hospital Management Information System . Affected by this issue is some unknown functionality. The manipulation results in u…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42516 | CDAC-Noida e-Sushrut Hospital Management Information System encoded authorization (CIVN-2026-0207)

A vulnerability, which was classified as critical , has been found in CDAC-Noida e-Sushrut Hospital Management Information System . This affects an unknown part. This manipulation of the argument enco…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42517 | CDAC-Noida e-Sushrut Hospital Management Information System Base64 Encoding authorization (CIVN-2026-0207)

A vulnerability, which was classified as problematic , was found in CDAC-Noida e-Sushrut Hospital Management Information System . This vulnerability affects unknown code of the component Base64 Encodi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-3325 | CRM Sistemas de Fidelización MegaCMS 12.0.0 POST Request get_provincias id_territorio sql injection

A vulnerability has been found in CRM Sistemas de Fidelización MegaCMS 12.0.0 and classified as critical . This issue affects some unknown processing of the file /web_comunications/cms/get_provincias …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7388 | EyouCMS up to 1.7.9 Template File FilemanagerLogic.php editFile code injection (IILDJS)

A vulnerability was found in EyouCMS up to 1.7.9 and classified as critical . Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7389 | EyouCMS up to 1.7.9 application/common.php GetSortData sort_asc sql injection (IILFPE)

A vulnerability was found in EyouCMS up to 1.7.9 . It has been classified as critical . The affected element is the function GetSortData of the file application/common.php . The manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7390 | SourceCodester Pharmacy Sales and Inventory System 1.0 /index.php?page=customer Name cross site scripting

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0 . It has been declared as problematic . The impacted element is the function Customer of the file /index.php?page=cu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7391 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=save_supplier ID sql injection

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0 . It has been rated as critical . This affects the function save_supplier of the file /ajax.php?action=save_supplier…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7392 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=delete_supplier ID sql injection

A vulnerability categorized as critical has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0 . This impacts the function delete_supplier of the file /ajax.php?action=delete_su…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7393 | SourceCodester Pizzafy Ecommerce System 1.0 File Extension admin_class_novo.php save_menu img unrestricted upload

A vulnerability identified as critical has been detected in SourceCodester Pizzafy Ecommerce System 1.0 . Affected is the function save_menu of the file /admin/admin_class_novo.php of the component Fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7394 | SourceCodester Pizzafy Ecommerce System 1.0 GET Parameter /admin/view_order.php ID sql injection

A vulnerability labeled as critical has been found in SourceCodester Pizzafy Ecommerce System 1.0 . Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7396 | NousResearch hermes-agent 0.8.0 WeChat Work Platform Adapter wecom.py path traversal (Issue 8733)

A vulnerability marked as critical has been reported in NousResearch hermes-agent 0.8.0 . Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component W…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7397 | NousResearch hermes-agent 0.8.0 tools/file_tools.py _check_sensitive_path symlink (Issue 8734)

A vulnerability described as critical has been identified in NousResearch hermes-agent 0.8.0 . This affects the function _check_sensitive_path of the file tools/file_tools.py . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7398 | florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54 Upload Endpoint app.py upload Name path traversal

A vulnerability classified as critical has been found in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54 . This vulnerability affects the function Upload of the file bioinfo…

VulDB Read →
◇ Industry News & Leadership Apr 29, 2026
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi

A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware that locks files a…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks

Google has released a critical security update for its Chrome desktop browser to address 30 security vulnerabilities, including four severe flaws that could enable Remote Code Execution (RCE) attacks.…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks

A critical, currently unpatched remote code execution (RCE) vulnerability has been disclosed in LeRobot, Hugging Face’s popular open-source machine learning framework for real-world robotics. Tracked …

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical zero-day vulnerability in Microsoft Windows. On April 28, 2026, the agency officially adde…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
Vimeo Confirms Data Breach – Hackers Accessed Users Database

Video hosting platform Vimeo has confirmed a data breach resulting in unauthorized access to its user database. The security incident stems from a compromise at Anodot, a third-party analytics vendor …

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
Minecraft Players Targeted by LofyStealer Using Node.js Loader and In-Memory Browser Injection

A dangerous infostealer malware called LofyStealer is actively targeting Minecraft players by disguising itself as a game cheat tool named “Slinky.” The malware runs a two-stage attack that quietly st…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
A Quarter of Healthcare Organizations Report Medical Device Cyber-Attacks

RunSafe report reveals most attacks on medical devices disrupt patient care

Infosecurity Magazine Read →
← Prev 211 / 945 Next →