CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6195 articles  ·  updated every 4 hours · grows forever

6195Total
4060Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6136 | Tenda F451 1.0.0.7_cn_svn7958 /goform/L7Im frmL7ImForm page stack-based overflow

A vulnerability classified as critical has been found in Tenda F451 1.0.0.7_cn_svn7958 . Impacted is the function frmL7ImForm of the file /goform/L7Im . The manipulation of the argument page leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6137 | Tenda F451 1.0.0.7_cn_svn7958 /goform/AdvSetWan fromAdvSetWan wanmode/PPPOEPassword stack-based overflow

A vulnerability classified as critical was found in Tenda F451 1.0.0.7_cn_svn7958 . The affected element is the function fromAdvSetWan of the file /goform/AdvSetWan . The manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6138 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setAccessDeviceCfg mac os command injection

A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6139 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi UploadOpenVpnCert FileName os command injection

A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6140 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi UploadFirmwareFile FileName os command injection

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024 and classified as critical . This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in the Wild, Targeting Corporate Networks - gbhackers.com

Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in the Wild, Targeting Corporate Networks gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-31845 | Rukovoditel CRM up to 3.6/3.6.4 API Endpoint /api/tel/zadarma.php zd_echo cross site scripting (EUVD-2026-21682)

A vulnerability, which was classified as problematic , has been found in Rukovoditel CRM up to 3.6/3.6.4 . This issue affects some unknown processing of the file /api/tel/zadarma.php of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6125 | Dromara warm-flow up to 1.8.4 Workflow Definition /warm-flow/save-json SpelHelper.parseExpression listenerPath/skipCondition/permissionFlag code injection (IHURVQ)

A vulnerability, which was classified as critical , was found in Dromara warm-flow up to 1.8.4 . Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component W…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6126 | zhayujie chatgpt-on-wechat CowAgent 2.0.4 Administrative HTTP Endpoint missing authentication (Issue 2733)

A vulnerability has been found in zhayujie chatgpt-on-wechat CowAgent 2.0.4 and classified as critical . The affected element is an unknown function of the component Administrative HTTP Endpoint . Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-32146 | Gleam up to 1.15.3/1.16.0-rc1 path traversal (GHSA-vq5j-55vx-wq8j / EUVD-2026-21680)

A vulnerability categorized as critical has been discovered in Gleam up to 1.15.3/1.16.0-rc1 . This affects an unknown function. Executing a manipulation can lead to path traversal. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-23900 | Phoca Maps for Joomla up to 6.0.2 cross site scripting (EUVD-2026-21678)

A vulnerability identified as problematic has been detected in Phoca Maps for Joomla up to 6.0.2 . This impacts an unknown function. The manipulation leads to cross site scripting. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6120 | Tenda F451 1.0.0.7 httpd /goform/DhcpListClient fromDhcpListClient page stack-based overflow

A vulnerability labeled as critical has been found in Tenda F451 1.0.0.7 . Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd . The manipulation of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6121 | Tenda F451 1.0.0.7 httpd /goform/WrlclientSet GO stack-based overflow

A vulnerability marked as critical has been reported in Tenda F451 1.0.0.7 . Affected by this vulnerability is the function WrlclientSet of the file /goform/WrlclientSet of the component httpd . This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6122 | Tenda F451 1.0.0.7 httpd /goform/L7Prot frmL7ProtForm page stack-based overflow

A vulnerability described as critical has been identified in Tenda F451 1.0.0.7 . Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd . Such manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6123 | Tenda F451 1.0.0.7 httpd /goform/addressNat fromAddressNat entrys stack-based overflow

A vulnerability classified as critical has been found in Tenda F451 1.0.0.7 . This affects the function fromAddressNat of the file /goform/addressNat of the component httpd . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6124 | Tenda F451 1.0.0.7 httpd /goform/SafeMacFilter fromSafeMacFilter page/menufacturer stack-based overflow

A vulnerability classified as critical was found in Tenda F451 1.0.0.7 . This vulnerability affects the function fromSafeMacFilter of the file /goform/SafeMacFilter of the component httpd . Executing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6106 | 1Panel-dev MaxKB up to 2.2.1 Public Chat Interface static_headers_middleware.py StaticHeadersMiddleware Name cross site scripting

A vulnerability was found in 1Panel-dev MaxKB up to 2.2.1 . It has been declared as problematic . This vulnerability affects the function StaticHeadersMiddleware of the file apps/common/middleware/sta…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6107 | 1Panel-dev MaxKB up to 2.6.1 ChatHeadersMiddleware chat_headers_middleware.py Name cross site scripting

A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1 . It has been rated as problematic . This issue affects some unknown processing of the file apps/common/middleware/chat_headers_middleware.py …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2025-15632 | 1Panel-dev MaxKB up to 2.4.2 MdPreview ui/src/chat.ts cross site scripting

A vulnerability categorized as problematic has been discovered in 1Panel-dev MaxKB up to 2.4.2 . Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview . Such manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6108 | 1Panel-dev MaxKB up to 2.6.1 Model Context Protocol Node base_mcp_node.py execute os command injection

A vulnerability identified as critical has been detected in 1Panel-dev MaxKB up to 2.6.1 . The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6109 | FoundationAgents MetaGPT up to 0.8.1 Mineflayer HTTP API index.js evaluateCode cross-site request forgery (Issue 1932)

A vulnerability labeled as problematic has been found in FoundationAgents MetaGPT up to 0.8.1 . The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6110 | FoundationAgents MetaGPT up to 0.8.1 Tree-of-Thought Solver metagpt/strategy/tot.py generate_thoughts code injection (Issue 1933)

A vulnerability marked as critical has been reported in FoundationAgents MetaGPT up to 0.8.1 . This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6111 | FoundationAgents MetaGPT up to 0.8.1 metagpt/utils/common.py decode_image img_url_or_b64 server-side request forgery (Issue 1934)

A vulnerability described as critical has been identified in FoundationAgents MetaGPT up to 0.8.1 . This impacts the function decode_image of the file metagpt/utils/common.py . The manipulation of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6112 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setRadvdCfg maxRtrAdvInterval os command injection

A vulnerability classified as critical has been found in Totolink A7100RU 7.4cu.2313_b20191024 . Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler . Th…

VulDB Read →
← Prev 124 / 259 Next →