CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Critical CVEs
Intel Feed

cyberintel.kalymoon.com  ·  82 articles  ·  updated every 4 hours · grows forever

82Total
21Full Text
Jul 28, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⚠ Critical CVEs Jul 11, 2026
CVE-2026-15155 | wpdevteam Essential Addons for Elementor Plugin up to 6.6.10 on WordPress Login/Register Widget crlf injection

A vulnerability was found in wpdevteam Essential Addons for Elementor Plugin up to 6.6.10 on WordPress. It has been classified as critical . Impacted is an unknown function of the component Login/Regi…

VulDB Read →
⚠ Critical CVEs Jul 11, 2026
CVE-2026-9017 | webaways NEX-Forms Plugin up to 9.2.2 on WordPress Authorization saved_user_email_address authorization

A vulnerability was found in webaways NEX-Forms Plugin up to 9.2.2 on WordPress. It has been declared as critical . The affected element is an unknown function of the component Authorization . Such ma…

VulDB Read →
⚠ Critical CVEs Jul 11, 2026
CVE-2026-4661 | blendmedia WP CTA Plugin up to 2.2.2 on WordPress SQL Injection ajaxCheck fildname sql injection

A vulnerability was found in blendmedia WP CTA Plugin up to 2.2.2 on WordPress. It has been rated as critical . The impacted element is the function ajaxCheck of the component SQL Injection Handler . …

VulDB Read →
⚠ Critical CVEs Jul 11, 2026
CVE-2026-1382 | freshlabs fresh Podcaster Plugin up to 1.0.7 on WordPress Shortcode freshpodcaster attributes cross site scripting

A vulnerability categorized as problematic has been discovered in freshlabs fresh Podcaster Plugin up to 1.0.7 on WordPress. This affects the function freshpodcaster of the component Shortcode Handler…

VulDB Read →
⚠ Critical CVEs Jul 11, 2026
CVE-2026-6939 | corvusinfo CorvusPay WooCommerce Payment Gateway Plugin up to 2.7.4 on WordPress approval_code success cross site scripting

A vulnerability identified as problematic has been detected in corvusinfo CorvusPay WooCommerce Payment Gateway Plugin up to 2.7.4 on WordPress. This impacts an unknown function of the file /wp-json/c…

VulDB Read →
⚠ Critical CVEs Jul 11, 2026
CVE-2026-15010 | robin-w bbp Style Pack Plugin up to 6.4.5 on WordPress Topic Form Additional Fields Feature bsp_topic_fields_label{n} cross site scripting

A vulnerability labeled as problematic has been found in robin-w bbp Style Pack Plugin up to 6.4.5 on WordPress. Affected is the function bsp_topic_fields_form_save/bsp_topic_content_append_topic_fiel…

VulDB Read →
⚠ Critical CVEs Jul 11, 2026
Microsoft Fixes 165 Vulnerabilities, Including Exploited SharePoint Zero-Day CVE-2026-32201 - NewsCord

Microsoft Fixes 165 Vulnerabilities, Including Exploited SharePoint Zero-Day CVE-2026-32201 NewsCord

NewsCord Read →
⚠ Critical CVEs Jul 04, 2026
CVE-2026-14713 | SourceCodester Pizzafy E-Commerce System 1.0 ajax.php?action=confirm_order ID sql injection

A vulnerability labeled as critical has been found in SourceCodester Pizzafy E-Commerce System 1.0 . This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order . The mani…

VulDB Read →
⚠ Critical CVEs Jul 04, 2026
CVE-2026-14714 | zhayujie chatgpt-on-wechat CowAgent 2.1.0 wx Endpoint common.py verify_server wechatmp_token missing authentication (Issue 2860)

A vulnerability marked as critical has been reported in zhayujie chatgpt-on-wechat CowAgent 2.1.0 . This issue affects the function verify_server of the file channel/wechatmp/common.py of the componen…

VulDB Read →
⚠ Critical CVEs Jul 04, 2026
CVE-2026-14716 | nextlevelbuilder GoClaw up to 3.13.0-beta.2 WebSocket RPC router.go MethodRouter.Handle authorization (Issue 1188)

A vulnerability described as critical has been identified in nextlevelbuilder GoClaw up to 3.13.0-beta.2 . Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the co…

VulDB Read →
⚠ Critical CVEs Jul 04, 2026
CVE-2026-14717 | itsourcecode Hospital Management System 1.0 /patientlogin.php loginid sql injection

A vulnerability classified as critical has been found in itsourcecode Hospital Management System 1.0 . The affected element is an unknown function of the file /patientlogin.php . Performing a manipula…

VulDB Read →
⚠ Critical CVEs Jul 04, 2026
CVE-2026-14719 | SourceCodester Onlne Examination & Learning Management System 1.0 Registration Endpoint register.php role privileges management

A vulnerability classified as critical was found in SourceCodester Onlne Examination & Learning Management System 1.0 . The impacted element is an unknown function of the file register.php of the comp…

VulDB Read →
⚠ Critical CVEs Jun 26, 2026
CVE-2026-13325 | Red Hat OpenShift Virtualization 4 missing authentication

A vulnerability was found in Red Hat OpenShift Virtualization 4 . It has been declared as critical . Affected is an unknown function. The manipulation results in missing authentication. This vulnerabi…

VulDB Read →
⚠ Critical CVEs Jun 26, 2026
CVE-2026-57473 | Reolink Home Hub prior 3.3.0.456_26031911 weak credentials

A vulnerability categorized as critical has been discovered in Reolink Home Hub . Affected by this issue is some unknown functionality. Such manipulation leads to use of weak credentials. This vulnera…

VulDB Read →
⚠ Critical CVEs Jun 26, 2026
CVE-2025-7958 | Trellix Network Security NX 10.0.4 Web Interface code injection

A vulnerability identified as critical has been detected in Trellix Network Security NX, Network Security EX, Network Security FX, Network Security AX and Network Security CMS 10.0.4 . This affects an…

VulDB Read →
⚠ Critical CVEs Jun 14, 2026
CVE-2026-12200 | Ritlabs TinyWeb Server up to 1.94 on Win32 Header libeay32.dll.html Authorization stack-based overflow

A vulnerability identified as critical has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown function in the library libeay32.dll.html of the component Header Handle…

VulDB Read →
⚠ Critical CVEs Jun 14, 2026
CVE-2025-15546 | Iptanus File Upload Plugin up to 5.1.6 on WordPress Setting duplicatepolicy race condition

A vulnerability labeled as critical has been found in Iptanus File Upload Plugin up to 5.1.6 on WordPress. Affected is an unknown function of the component Setting Handler . The manipulation of the ar…

VulDB Read →
⚠ Critical CVEs Jun 14, 2026
CVE-2026-12201 | IObit Malware Fighter up to 13.2.0 DLL permission

A vulnerability marked as critical has been reported in IObit Malware Fighter up to 13.2.0 . Affected by this vulnerability is an unknown functionality of the component DLL Handler . This manipulation…

VulDB Read →
⚠ Critical CVEs Jun 14, 2026
CVE-2026-12204 | ShopXO up to 6.7.1 Scheduled Task Endpoint Crontab.php authorization

A vulnerability classified as critical was found in ShopXO up to 6.7.1 . This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controll…

VulDB Read →
⚠ Critical CVEs Jun 07, 2026
CVE-2026-11513 | itsourcecode Hospital Management System 1.0 /adminaccount.php Date sql injection

A vulnerability categorized as critical has been discovered in itsourcecode Hospital Management System 1.0 . Impacted is an unknown function of the file /adminaccount.php . The manipulation of the arg…

VulDB Read →
⚠ Critical CVEs Jun 07, 2026
CVE-2026-11514 | itsourcecode Hospital Management System 1.0 /addpatient.php admissiontme sql injection

A vulnerability identified as critical has been detected in itsourcecode Hospital Management System 1.0 . The affected element is an unknown function of the file /addpatient.php . This manipulation of…

VulDB Read →
⚠ Critical CVEs Jun 07, 2026
CVE-2026-11515 | SourceCodester Barangay Resident Profiling and Information Management System Password Reset passsword_reset.php hard-coded password

A vulnerability labeled as critical has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0 . The impacted element is an unknown function of the file passswo…

VulDB Read →
⚠ Critical CVEs May 27, 2026
CVE-2026-44887 | leiweibau Pi.Alert prior 2026-05-07 exec code injection

A vulnerability was found in leiweibau Pi.Alert . It has been declared as critical . Affected by this vulnerability is the function exec . The manipulation results in code injection. This vulnerabilit…

VulDB Read →
⚠ Critical CVEs May 27, 2026
CVE-2026-44886 | leiweibau Pi.Alert prior 2026-05-07 Web Application Endpoint sql injection

A vulnerability was found in leiweibau Pi.Alert . It has been rated as critical . Affected by this issue is some unknown functionality of the component Web Application Endpoint . This manipulation cau…

VulDB Read →
← Prev 2 / 4 Next →