CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6289 articles  ·  updated every 4 hours · grows forever

6289Total
4064Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5803 | bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c API Proxy Endpoint server.js Query server-side request forgery

A vulnerability marked as critical has been reported in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c . The affected element is an unknown function of the file server.js of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5805 | code-projects Easy Blog Site up to 1.0 /users/contact_us.php Name sql injection

A vulnerability described as critical has been identified in code-projects Easy Blog Site up to 1.0 . The impacted element is an unknown function of the file /users/contact_us.php . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5806 | code-projects Easy Blog Site 1.0 /posts/update.php postTitle cross site scripting

A vulnerability classified as problematic has been found in code-projects Easy Blog Site 1.0 . This affects an unknown function of the file /posts/update.php . The manipulation of the argument postTit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5808 | openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c Onboarding Endpoint client.tsx callbackURL cross site scripting

A vulnerability classified as problematic was found in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c . This impacts an unknown function of the file apps/dashboard/src/app/(das…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5810 | SourceCodester Sales and Inventory System 1.0 GET Parameter /delete.php ID cross site scripting

A vulnerability, which was classified as problematic , has been found in SourceCodester Sales and Inventory System 1.0 . Affected is an unknown function of the file /delete.php of the component GET Pa…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39406 | honojs node-server up to 1.19.12 Request Path path traversal

A vulnerability, which was classified as critical , was found in honojs node-server up to 1.19.12 . Affected by this vulnerability is an unknown functionality of the component Request Path Handler . S…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39410 | honojs hono up to 4.12.11 parse input validation

A vulnerability has been found in honojs hono up to 4.12.11 and classified as problematic . Affected by this issue is the function parse . Performing a manipulation results in improper input validatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39865 | Axios up to 1.13.1 lib/adapters/http.js Http2Sessions.getSession resource consumption

A vulnerability was found in Axios up to 1.13.1 and classified as problematic . This affects the function Http2Sessions.getSession in the library lib/adapters/http.js . Executing a manipulation can le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39408 | honojs hono up to 4.12.11 toSSG path traversal

A vulnerability was found in honojs hono up to 4.12.11 . It has been classified as critical . This vulnerability affects the function toSSG . The manipulation leads to path traversal. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39407 | honojs hono up to 4.12.11 path traversal

A vulnerability was found in honojs hono up to 4.12.11 . It has been declared as critical . This issue affects some unknown processing. The manipulation results in path traversal. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39409 | honojs hono up to 4.12.11 ipRestriction incorrect behavior order: validate before canonicalize

A vulnerability was found in honojs hono up to 4.12.11 . It has been rated as problematic . Impacted is the function ipRestriction . This manipulation causes incorrect behavior order: validate before …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39390 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 compInfosPost cMap cross site scripting

A vulnerability categorized as problematic has been discovered in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 . The affected element is the function compInfosPost . Such manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39392 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 Pages cross site scripting (GHSA-fjpj-6qcq-6pw2)

A vulnerability identified as problematic has been detected in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 . The impacted element is an unknown function of the component Pages Module . Performing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39389 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 improper authorization (GHSA-9rxp-f27p-wv3h)

A vulnerability labeled as critical has been found in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 . This affects an unknown function. Executing a manipulation can lead to improper authorization. The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39391 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 ajax_blackList_post note cross site scripting (GHSA-7cm9-v848-cfh2)

A vulnerability marked as problematic has been reported in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 . This impacts the function UserController::ajax_blackList_post . The manipulation of the argume…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39393 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 missing authentication (GHSA-8rh5-4mvx-xj7j)

A vulnerability described as critical has been identified in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 . Affected is an unknown function. The manipulation results in missing authentication. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39394 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 Setting Install::index crlf injection (GHSA-vfhx-5459-qhqh)

A vulnerability classified as problematic has been found in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0 . Affected by this vulnerability is the function Install::index of the component Setting Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5811 | SourceCodester Online Food Ordering System 1.0 POST Parameter /Actions.php save_product price logic error

A vulnerability classified as critical was found in SourceCodester Online Food Ordering System 1.0 . Affected by this issue is the function save_product of the file /Actions.php of the component POST …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5812 | SourceCodester Pharmacy Product Management System 1.0 POST Parameter add-sales.php txtqty logic error

A vulnerability, which was classified as critical , has been found in SourceCodester Pharmacy Product Management System 1.0 . This affects an unknown part of the file add-sales.php of the component PO…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5813 | PHPGurukul Online Course Registration 3.1 /check_availability.php cid sql injection

A vulnerability, which was classified as critical , was found in PHPGurukul Online Course Registration 3.1 . This vulnerability affects unknown code of the file /check_availability.php . Executing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5814 | PHPGurukul Online Course Registration 3.1 check_availability.php regno sql injection

A vulnerability has been found in PHPGurukul Online Course Registration 3.1 and classified as critical . This issue affects some unknown processing of the file /admin/check_availability.php . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5815 | D-Link DIR-645 1.01/1.02/1.03 /cgi-bin/hedwig.cgi hedwigcgi_main stack-based overflow

A vulnerability was found in D-Link DIR-645 1.01/1.02/1.03 and classified as critical . Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi . The manipulation results in stack-base…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-33753 | trailofbits rfc3161-client up to 1.0.5 Time-Stamp Protocol certificate validation

A vulnerability was found in trailofbits rfc3161-client up to 1.0.5 . It has been classified as critical . The affected element is an unknown function of the component Time-Stamp Protocol Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-33229 | xwiki xwiki-platform up to 17.4.7/17.10.0 Velocity Scripting API authorization

A vulnerability was found in xwiki xwiki-platform, xwiki-platform-legacy-oldcore and xwiki-platform-oldcore up to 17.4.7/17.10.0 . It has been declared as problematic . The impacted element is an unkn…

VulDB Read →
← Prev 143 / 263 Next →