CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6225 articles  ·  updated every 4 hours · grows forever

6225Total
4060Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2025-15632 | 1Panel-dev MaxKB up to 2.4.2 MdPreview ui/src/chat.ts cross site scripting

A vulnerability categorized as problematic has been discovered in 1Panel-dev MaxKB up to 2.4.2 . Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview . Such manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6108 | 1Panel-dev MaxKB up to 2.6.1 Model Context Protocol Node base_mcp_node.py execute os command injection

A vulnerability identified as critical has been detected in 1Panel-dev MaxKB up to 2.6.1 . The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6109 | FoundationAgents MetaGPT up to 0.8.1 Mineflayer HTTP API index.js evaluateCode cross-site request forgery (Issue 1932)

A vulnerability labeled as problematic has been found in FoundationAgents MetaGPT up to 0.8.1 . The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6110 | FoundationAgents MetaGPT up to 0.8.1 Tree-of-Thought Solver metagpt/strategy/tot.py generate_thoughts code injection (Issue 1933)

A vulnerability marked as critical has been reported in FoundationAgents MetaGPT up to 0.8.1 . This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6111 | FoundationAgents MetaGPT up to 0.8.1 metagpt/utils/common.py decode_image img_url_or_b64 server-side request forgery (Issue 1934)

A vulnerability described as critical has been identified in FoundationAgents MetaGPT up to 0.8.1 . This impacts the function decode_image of the file metagpt/utils/common.py . The manipulation of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6112 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setRadvdCfg maxRtrAdvInterval os command injection

A vulnerability classified as critical has been found in Totolink A7100RU 7.4cu.2313_b20191024 . Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6113 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setTtyServiceCfg ttyEnable os command injection

A vulnerability classified as critical was found in Totolink A7100RU 7.4cu.2313_b20191024 . Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the comp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6114 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setNetworkCfg proto os command injection

A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6115 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setAppCfg enable os command injection

A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6116 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setDiagnosisCfg ip os command injection

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024 and classified as critical . This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6117 | AstrBotDevs AstrBot up to 4.22.1 install-upload Endpoint plugin.py install_plugin_upload File sandbox (Issue 7168)

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1 and classified as critical . This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6118 | AstrBotDevs AstrBot up to 4.22.1 MCP Endpoint tools.py add_mcp_server command command injection (Issue 7169)

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1 . It has been classified as critical . Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6119 | AstrBotDevs AstrBot up to 4.22.1 API Endpoint post_data.get server-side request forgery (Issue 7171)

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1 . It has been declared as critical . The affected element is the function post_data.get of the component API Endpoint . Such manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5809 | tomdever wpForo Forum Plugin up to 3.0.2 on WordPress topic_add body file inclusion

A vulnerability was found in tomdever wpForo Forum Plugin up to 3.0.2 on WordPress. It has been rated as critical . The impacted element is the function topic_add . Performing a manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
Microsoft Patch Tuesday March 2026 Fixes 79 Vulnerabilities, Including Two Zero-Days - cyberpress.org

Microsoft Patch Tuesday March 2026 Fixes 79 Vulnerabilities, Including Two Zero-Days cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-34621 | Adobe Acrobat Reader up to 24.001.30356/26.001.21367 File prototype pollution (apsb26-43)

A vulnerability has been found in Adobe Acrobat Reader up to 24.001.30356/26.001.21367 and classified as critical . Affected by this vulnerability is an unknown functionality of the component File Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-3865 | Kubernetes up to 1.20.0 CSI Driver for SMB path traversal (Issue 138319)

A vulnerability was found in Kubernetes up to 1.20.0 and classified as critical . Affected by this issue is some unknown functionality of the component CSI Driver for SMB . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-6105 | perfree go-fastdfs-web up to 1.3.7 doInstall Interface InstallController.java improper authorization (IGB6M9)

A vulnerability was found in perfree go-fastdfs-web up to 1.3.7 . It has been classified as critical . This affects an unknown part of the file src/main/java/com/perfree/controller/InstallController.j…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-4895 | wpsoul Greenshift Plugin up to 12.8.9 on WordPress HTML Attribute gspb_greenShift_block_script_assets disablelazy HTML injection

A vulnerability was found in wpsoul Greenshift Plugin up to 12.8.9 on WordPress. It has been classified as problematic . Affected is the function gspb_greenShift_block_script_assets of the component H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-4979 | stiofansisland UsersWP Plugin up to 1.2.58 on WordPress process_image_crop uwp_crop server-side request forgery (bca-4611-9753)

A vulnerability was found in stiofansisland UsersWP Plugin up to 1.2.58 on WordPress. It has been declared as critical . Affected by this vulnerability is the function process_image_crop . Executing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5217 | Optimole Plugin up to 4.2.2 on WordPress REST Endpoint optimizations sanitize_text_field cross site scripting

A vulnerability was found in Optimole Plugin up to 4.2.2 on WordPress. It has been rated as problematic . Affected by this issue is the function sanitize_text_field of the file /wp-json/optimole/v1/op…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-3371 | themeum Tutor LMS Plugin up to 3.9.7 on WordPress AJAX save_course_content_order authorization

A vulnerability categorized as critical has been discovered in themeum Tutor LMS Plugin up to 3.9.7 on WordPress. This affects the function save_course_content_order of the component AJAX Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5144 | boonebgorges BuddyPress Groupblog Plugin up to 1.9.3 on WordPress privileges management

A vulnerability identified as critical has been detected in boonebgorges BuddyPress Groupblog Plugin up to 1.9.3 on WordPress. This vulnerability affects unknown code. This manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-3358 | themeum Tutor LMS Plugin up to 3.9.7 on WordPress POST enroll_now/course_enrollment authorization

A vulnerability labeled as critical has been found in themeum Tutor LMS Plugin up to 3.9.7 on WordPress. This issue affects the function enroll_now/course_enrollment of the component POST Handler . Su…

VulDB Read →
← Prev 126 / 260 Next →