CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  15861 articles  ·  updated every 4 hours · grows forever

15861Total
4381Full Text
Aug 14, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19834 | Webkul Bagisto up to 2.4.4 Admin Customer Impersonation Feature login-as-customer ID authorization

A vulnerability, which was classified as problematic , has been found in Webkul Bagisto up to 2.4.4 . Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component A…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19835 | Webkul Bagisto up to 2.4.4 Customer Item Deletion Endpoint access control

A vulnerability, which was classified as critical , was found in Webkul Bagisto up to 2.4.4 . Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19836 | Webkul Bagisto up to 2.4.4 Backend Customer Detail Feature /admin/customers/view ID authorization

A vulnerability has been found in Webkul Bagisto up to 2.4.4 and classified as critical . Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backen…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19837 | Webkul Bagisto up to 2.4.4 Customer Search /admin/customers/search Query information disclosure

A vulnerability was found in Webkul Bagisto up to 2.4.4 and classified as problematic . This affects an unknown part of the file /admin/customers/search of the component Customer Search . Executing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19838 | Webkul Bagisto up to 2.4.4 Backend Reporting Endpoint /admin/reporting/sales/ authorization

A vulnerability was found in Webkul Bagisto up to 2.4.4 . It has been classified as problematic . This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend R…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19839 | SourceCodester Simple Doctors Appointment System 1.0 /save_file.php save_doctor unrestricted upload

A vulnerability was found in SourceCodester Simple Doctors Appointment System 1.0 . It has been declared as critical . This issue affects the function save_doctor of the file /save_file.php . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19841 | TRENDNET TEW-813DRU 1.01b01 vsftpd /etc/vsftpd.conf default permission

A vulnerability was found in TRENDNET TEW-813DRU 1.01b01 . It has been rated as critical . Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd . This manipulation caus…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19794 | gamerz WP-Stats Plugin up to 2.56 on WordPress cross site scripting (EUVD-2026-58607)

A vulnerability categorized as problematic has been discovered in gamerz WP-Stats Plugin up to 2.56 on WordPress. The affected element is an unknown function. Such manipulation leads to cross site scr…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19844 | TOTOLINK A800R 4.1.2cu.5137_B20200730 ipv6.so /cgi-bin/cstecgi.cgi setRadvdCfg radvdinterfacename stack-based overflow

A vulnerability identified as critical has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730 . The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component i…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19845 | TOTOLINK A800R 4.1.2cu.5137_B20200730 lan.so /cgi-bin/cstecgi.cgi setStaticDhcpConfig Comment stack-based overflow

A vulnerability labeled as critical has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730 . This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so . E…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19846 | TOTOLINK A800R 4.1.2cu.5137_B20200730 firewall.so /cgi-bin/cstecgi.cgi setUrlFilterRules url stack-based overflow

A vulnerability marked as critical has been reported in TOTOLINK A800R 4.1.2cu.5137_B20200730 . This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.s…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19847 | TOTOLINK A800R 4.1.2cu.5137_B20200730 wps.so /cgi-bin/cstecgi.cgi setWiFiWpsConfig pin stack-based overflow

A vulnerability described as critical has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730 . Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so …

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2025-10308 | Alian Astro Booking Engine Plugin up to 1.4.0 on WordPress cross-site request forgery (EUVD-2025-210726)

A vulnerability labeled as problematic has been found in Alian Astro Booking Engine Plugin up to 1.4.0 on WordPress. This affects an unknown part. The manipulation results in cross-site request forger…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19821 | Tenda AC12 15.03.06.23_multi_TD01 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer rebootTime buffer overflow

A vulnerability marked as critical has been reported in Tenda AC12 15.03.06.23_multi_TD01 . This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19822 | Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC QoS Edit /goform/editQos lstAdd qosListConnecttedNum stack-based overflow

A vulnerability described as critical has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC . This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit .…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19823 | Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC QoS Rule Deletion /goform/delQos formQOSRuleDel qosIndex stack-based overflow

A vulnerability classified as critical has been found in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC . Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Delet…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19824 | Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC /goform/addIpMacBind ipMacBindListStore IPMacBindRule stack-based overflow

A vulnerability classified as critical was found in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC . The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind . Executing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19825 | SourceCodester Simple Client Management System 1.0 Master.php?f=save_service ID sql injection

A vulnerability, which was classified as critical , has been found in SourceCodester Simple Client Management System 1.0 . The impacted element is an unknown function of the file /classes/Master.php?f…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19826 | alldatacenter alldata up to 0.6.8 xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization (Issue 832)

A vulnerability, which was classified as critical , was found in alldatacenter alldata up to 0.6.8 . This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.ja…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19827 | alldatacenter alldata up to 0.6.8 logDetailCat Endpoint JobLogController.java FileInputStream executorAddress path traversal (Issue 834)

A vulnerability has been found in alldatacenter alldata up to 0.6.8 and classified as critical . This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-12743 | cservit affiliate-toolkit Plugin up to 3.8.8 on WordPress orderby sql injection (EUVD-2026-58590)

A vulnerability was found in cservit affiliate-toolkit Plugin up to 3.8.8 on WordPress and classified as problematic . Affected is an unknown function. Such manipulation of the argument orderby leads …

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-12949 | Wishlist Member Plugin up to 3.34.1 on WordPress Registration wpm_register/wp_update_user mergewith/wpm_id improper authentication (EUVD-2026-58589)

A vulnerability was found in Wishlist Member Plugin up to 3.34.1 on WordPress. It has been classified as critical . Affected by this vulnerability is the function wpm_register/wp_update_user of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-16810 | BitPress Admin Bit Form Plugin up to 3.2.0 on WordPress data[queryCondition] sql injection (EUVD-2026-58588)

A vulnerability was found in BitPress Admin Bit Form Plugin up to 3.2.0 on WordPress. It has been declared as problematic . Affected by this issue is some unknown functionality. Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Aug 14, 2026
CVE-2026-19828 | 648540858 wvp-GB28181-pro 2.7.4-20260107 Snapshot Endpoint PlayController.java deviceId/channelId path traversal (Issue 2175)

A vulnerability was found in 648540858 wvp-GB28181-pro 2.7.4-20260107 . It has been rated as critical . This affects an unknown part of the file PlayController.java of the component Snapshot Endpoint …

VulDB Read →
1 / 661 Next →