CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6195 articles  ·  updated every 4 hours · grows forever

6195Total
4060Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6113 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setTtyServiceCfg ttyEnable os command injection

A vulnerability classified as critical was found in Totolink A7100RU 7.4cu.2313_b20191024 . Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the comp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6114 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setNetworkCfg proto os command injection

A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6115 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setAppCfg enable os command injection

A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6116 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setDiagnosisCfg ip os command injection

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024 and classified as critical . This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6117 | AstrBotDevs AstrBot up to 4.22.1 install-upload Endpoint plugin.py install_plugin_upload File sandbox (Issue 7168)

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1 and classified as critical . This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6118 | AstrBotDevs AstrBot up to 4.22.1 MCP Endpoint tools.py add_mcp_server command command injection (Issue 7169)

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1 . It has been classified as critical . Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6119 | AstrBotDevs AstrBot up to 4.22.1 API Endpoint post_data.get server-side request forgery (Issue 7171)

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1 . It has been declared as critical . The affected element is the function post_data.get of the component API Endpoint . Such manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5809 | tomdever wpForo Forum Plugin up to 3.0.2 on WordPress topic_add body file inclusion

A vulnerability was found in tomdever wpForo Forum Plugin up to 3.0.2 on WordPress. It has been rated as critical . The impacted element is the function topic_add . Performing a manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
Microsoft Patch Tuesday March 2026 Fixes 79 Vulnerabilities, Including Two Zero-Days - cyberpress.org

Microsoft Patch Tuesday March 2026 Fixes 79 Vulnerabilities, Including Two Zero-Days cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-34621 | Adobe Acrobat Reader up to 24.001.30356/26.001.21367 File prototype pollution (apsb26-43)

A vulnerability has been found in Adobe Acrobat Reader up to 24.001.30356/26.001.21367 and classified as critical . Affected by this vulnerability is an unknown functionality of the component File Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-3865 | Kubernetes up to 1.20.0 CSI Driver for SMB path traversal (Issue 138319)

A vulnerability was found in Kubernetes up to 1.20.0 and classified as critical . Affected by this issue is some unknown functionality of the component CSI Driver for SMB . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6105 | perfree go-fastdfs-web up to 1.3.7 doInstall Interface InstallController.java improper authorization (IGB6M9)

A vulnerability was found in perfree go-fastdfs-web up to 1.3.7 . It has been classified as critical . This affects an unknown part of the file src/main/java/com/perfree/controller/InstallController.j…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-4895 | wpsoul Greenshift Plugin up to 12.8.9 on WordPress HTML Attribute gspb_greenShift_block_script_assets disablelazy HTML injection

A vulnerability was found in wpsoul Greenshift Plugin up to 12.8.9 on WordPress. It has been classified as problematic . Affected is the function gspb_greenShift_block_script_assets of the component H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-4979 | stiofansisland UsersWP Plugin up to 1.2.58 on WordPress process_image_crop uwp_crop server-side request forgery (bca-4611-9753)

A vulnerability was found in stiofansisland UsersWP Plugin up to 1.2.58 on WordPress. It has been declared as critical . Affected by this vulnerability is the function process_image_crop . Executing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5217 | Optimole Plugin up to 4.2.2 on WordPress REST Endpoint optimizations sanitize_text_field cross site scripting

A vulnerability was found in Optimole Plugin up to 4.2.2 on WordPress. It has been rated as problematic . Affected by this issue is the function sanitize_text_field of the file /wp-json/optimole/v1/op…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-3371 | themeum Tutor LMS Plugin up to 3.9.7 on WordPress AJAX save_course_content_order authorization

A vulnerability categorized as critical has been discovered in themeum Tutor LMS Plugin up to 3.9.7 on WordPress. This affects the function save_course_content_order of the component AJAX Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5144 | boonebgorges BuddyPress Groupblog Plugin up to 1.9.3 on WordPress privileges management

A vulnerability identified as critical has been detected in boonebgorges BuddyPress Groupblog Plugin up to 1.9.3 on WordPress. This vulnerability affects unknown code. This manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-3358 | themeum Tutor LMS Plugin up to 3.9.7 on WordPress POST enroll_now/course_enrollment authorization

A vulnerability labeled as critical has been found in themeum Tutor LMS Plugin up to 3.9.7 on WordPress. This issue affects the function enroll_now/course_enrollment of the component POST Handler . Su…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5207 | chrisbadgett LifterLMS Plugin up to 9.2.1 on WordPress edit_post order sql injection

A vulnerability marked as critical has been reported in chrisbadgett LifterLMS Plugin up to 9.2.1 on WordPress. Impacted is the function edit_post . Performing a manipulation of the argument order res…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40198 | STIGTSP Net::CIDR::Lite up to 0.22 on Perl _pack_ipv6 improper validation of syntactic correctness of input

A vulnerability described as critical has been identified in STIGTSP Net::CIDR::Lite up to 0.22 on Perl. The affected element is the function _pack_ipv6 . Executing a manipulation can lead to improper…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40199 | STIGTSP Net::CIDR::Lite up to 0.22 on Perl IPv6 Address _pack_ipv6 length parameter

A vulnerability classified as critical has been found in STIGTSP Net::CIDR::Lite up to 0.22 on Perl. The impacted element is the function _pack_ipv6 of the component IPv6 Address Handler . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-3498 | wpblockart BlockArt Blocks Plugin up to 2.2.15 on WordPress Block Attribute cross site scripting

A vulnerability classified as problematic was found in wpblockart BlockArt Blocks Plugin up to 2.2.15 on WordPress. This affects an unknown function of the component Block Attribute Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5226 | Optimole Plugin up to 4.2.3 on WordPress get_current_url cross site scripting

A vulnerability, which was classified as problematic , has been found in Optimole Plugin up to 4.2.3 on WordPress. This impacts the function get_current_url . This manipulation causes cross site scrip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40354 | Flatpak xdg-desktop-portal up to 1.20.3/1.21.0 g_file_trash symlink (GHSA-rqr9-jwwf-wxgj)

A vulnerability, which was classified as critical , was found in Flatpak xdg-desktop-portal up to 1.20.3/1.21.0 . Affected is the function g_file_trash . Such manipulation leads to symlink following. …

VulDB Read →
← Prev 125 / 259 Next →