CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10282 articles  ·  updated every 4 hours · grows forever

10282Total
4234Full Text
Jun 30, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13491 | 78 xiaozhi-esp32 up to 2.2.6 MQTT Goodbye mqtt_protocol.cc Application::GetInstance session_id denial of service (Issue 2022)

A vulnerability, which was classified as problematic , has been found in 78 xiaozhi-esp32 up to 2.2.6 . This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13493 | AIDC-AI ComfyUI-Copilot up to 2.0.28 Workflow Checkpoint Restore conversation_api.py resource injection (Issue 149)

A vulnerability, which was classified as problematic , was found in AIDC-AI ComfyUI-Copilot up to 2.0.28 . This issue affects some unknown processing of the file backend/controller/conversation_api.py…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13495 | itsourcecode Hospital Management System 1.0 /adminprofile.php loginid sql injection

A vulnerability has been found in itsourcecode Hospital Management System 1.0 and classified as critical . Impacted is an unknown function of the file /adminprofile.php . The manipulation of the argum…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13496 | itsourcecode Hospital Management System 1.0 /ajaxmedicine.php medicineid sql injection

A vulnerability was found in itsourcecode Hospital Management System 1.0 and classified as critical . The affected element is an unknown function of the file /ajaxmedicine.php . The manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13497 | itsourcecode Hospital Management System 1.0 /appointment.php editid sql injection

A vulnerability was found in itsourcecode Hospital Management System 1.0 . It has been classified as critical . The impacted element is an unknown function of the file /appointment.php . This manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13498 | yashpokharna2555 restaurent-management-system POST Parameter /forgotpassword.php email sql injection

A vulnerability was found in yashpokharna2555 restaurent-management-system . It has been declared as critical . This affects an unknown function of the file /forgotpassword.php of the component POST P…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13499 | yashpokharna2555 restaurent-management-system Registration login_register.php Username cross site scripting

A vulnerability was found in yashpokharna2555 restaurent-management-system . It has been rated as problematic . This impacts an unknown function of the file login_register.php of the component Registr…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13500 | antlr ANTLR4 up to 4.13.2 Grammar Action Block OutputFile.java code injection

A vulnerability categorized as critical has been discovered in antlr ANTLR4 up to 4.13.2 . Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13501 | antlr ANTLR4 up to 4.13.2 gofmt GoTarget.java GoTarget command injection

A vulnerability identified as critical has been detected in antlr ANTLR4 up to 4.13.2 . Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarge…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13503 | antlr ANTLR4 up to 4.13.2 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal

A vulnerability labeled as critical has been found in antlr ANTLR4 up to 4.13.2 . Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.j…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13502 | antlr ANTLR4 up to 4.13.2 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou

A vulnerability marked as problematic has been reported in antlr ANTLR4 up to 4.13.2 . This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mo…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13504 | code-projects Project Management System 1.0 Mail Compose Page /mail.php cross site scripting

A vulnerability described as problematic has been identified in code-projects Project Management System 1.0 . This vulnerability affects unknown code of the file /mail.php of the component Mail Compos…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13482 | skypilot-org skypilot up to 0.12.0 User ID sky/users/server.py username.encode weak hash (Issue 9194)

A vulnerability was found in skypilot-org skypilot up to 0.12.0 . It has been declared as problematic . Impacted is the function username.encode of the file sky/users/server.py of the component User I…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13483 | arc53 DocsGPT up to 0.18.0 Credential Storage encryption.py encrypt_credentials data authenticity (Issue 2503)

A vulnerability was found in arc53 DocsGPT up to 0.18.0 . It has been rated as problematic . The affected element is the function encrypt_credentials of the file application/security/encryption.py of …

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-11987 | dokaninc Dokan Plugin up to 5.0.4 on WordPress ID authorization

A vulnerability, which was classified as problematic , has been found in dokaninc Dokan Plugin up to 5.0.4 on WordPress. This affects an unknown function. The manipulation of the argument ID leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-3462 | reepaydenmark Frisbii Pay Plugin up to 1.8.9 on WordPress authorization

A vulnerability, which was classified as critical , was found in reepaydenmark Frisbii Pay Plugin up to 1.8.9 on WordPress. This impacts an unknown function. The manipulation results in missing author…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-12471 | templatescoderthemes Spexo Plugin up to 2.0.11 on WordPress authorization

A vulnerability has been found in templatescoderthemes Spexo Plugin up to 2.0.11 on WordPress and classified as critical . Affected is an unknown function. This manipulation causes missing authorizati…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-11364 | dornaweb Product Specifications for Woocommerce Plugin up to 0.8.9 on WordPress AJAX Action __invoke authorization

A vulnerability was found in dornaweb Product Specifications for Woocommerce Plugin up to 0.8.9 on WordPress and classified as critical . Affected by this vulnerability is the function __invoke of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-9242 | metagauss RegistrationMagic Plugin up to 6.0.8.6 on WordPress User Registration custom data authenticity

A vulnerability was found in metagauss RegistrationMagic Plugin up to 6.0.8.6 on WordPress. It has been classified as critical . Affected by this issue is some unknown functionality of the component U…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-11773 | Masteriyo LMS Plugin up to 2.2.1 on WordPress authorization

A vulnerability was found in Masteriyo LMS Plugin up to 2.2.1 on WordPress. It has been declared as critical . This affects an unknown part. Executing a manipulation can lead to missing authorization.…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-9233 | expresstech Quiz and Survey Master Plugin up to 11.1.4 on WordPress Database Table authorization

A vulnerability was found in expresstech Quiz and Survey Master Plugin up to 11.1.4 on WordPress. It has been rated as critical . This vulnerability affects unknown code of the component Database Tabl…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-12432 | themeisle Stripe Payment Forms by WP Full Pay Plugin up to 8.4.3 on WordPress Stripe.js wpfs_update_failed_payment_status db authorization

A vulnerability categorized as critical has been discovered in themeisle Stripe Payment Forms by WP Full Pay Plugin up to 8.4.3 on WordPress. This issue affects the function wpfs_update_failed_payment…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-11783 | dokaninc Dokan Plugin up to 5.0.4 on WordPress html cross site scripting

A vulnerability identified as problematic has been detected in dokaninc Dokan Plugin up to 5.0.4 on WordPress. Impacted is the function html . This manipulation causes cross site scripting. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13295 | gpriday Page Builder by SiteOrigin Plugin up to 2.34.3 on WordPress panels_data cross site scripting

A vulnerability labeled as problematic has been found in gpriday Page Builder by SiteOrigin Plugin up to 2.34.3 on WordPress. The affected element is an unknown function. Such manipulation of the argu…

VulDB Read →
← Prev 12 / 429 Next →