CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6338 articles  ·  updated every 4 hours · grows forever

6338Total
4066Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5669 | Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f Parameter /login.php Password sql injection (Issue 240)

A vulnerability, which was classified as critical , was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f . This vulnerability affects unknown code of the fil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5670 | Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f upload.php move_uploaded_file File unrestricted upload

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f and classified as critical . This issue affects the function move_uploaded_file of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5671 | Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f Class Schedule Deletion Endpoint delete_batch.php batch cross site scripting (Issue 242)

A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f and classified as problematic . Impacted is an unknown function of the file /admin/class…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-31409 | Linux Kernel up to 7.0-rc4 ksmbd ksmbd_session_lookup_all state issue (EUVD-2026-19195)

A vulnerability was found in Linux Kernel up to 7.0-rc4 . It has been classified as critical . The affected element is the function ksmbd_session_lookup_all of the component ksmbd . The manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-31405 | Linux Kernel up to 7.0-rc2 handle_one_ule_extension out-of-bounds (EUVD-2026-19199)

A vulnerability was found in Linux Kernel up to 7.0-rc2 . It has been declared as critical . The impacted element is the function handle_one_ule_extension . The manipulation of the argument ule_mandat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-31410 | Linux Kernel up to 6.12.77/6.18.19/6.19.9/7.0-rc4 ksmbd vfs_statfs privilege escalation (EUVD-2026-19194)

A vulnerability was found in Linux Kernel up to 6.12.77/6.18.19/6.19.9/7.0-rc4 . It has been rated as critical . This affects the function vfs_statfs of the component ksmbd . This manipulation causes …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-31408 | Linux Kernel up to 6.6.130/6.12.79/6.18.20/6.19.10/7.0-rc5 Bluetooth sco_recv_frame use after free (EUVD-2026-19196)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.130/6.12.79/6.18.20/6.19.10/7.0-rc5 . This impacts the function sco_recv_frame of the component Bluetooth . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-31406 | Linux Kernel up to 6.12.79/6.18.20/6.19.10/7.0-rc5 xfrm_nat_keepalive_net_fini state issue (EUVD-2026-19198)

A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.79/6.18.20/6.19.10/7.0-rc5 . Affected is the function xfrm_nat_keepalive_net_fini . Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-31407 | Linux Kernel up to 6.19.9/7.0-rc4 netfilter nlattr_to_sctp out-of-bounds (EUVD-2026-19197)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.19.9/7.0-rc4 . Affected by this vulnerability is the function nlattr_to_sctp of the component netfilter . Executing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5672 | code-projects Simple IT Discussion Forum 1.0 Parameter /edit-category.php cat_id sql injection

A vulnerability marked as critical has been reported in code-projects Simple IT Discussion Forum 1.0 . Affected by this issue is some unknown functionality of the file /edit-category.php of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5675 | itsourcecode Construction Management System 1.0 Parameter /borrowed_tool.php emp sql injection

A vulnerability described as critical has been identified in itsourcecode Construction Management System 1.0 . This affects an unknown part of the file /borrowed_tool.php of the component Parameter Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-37977 | Keycloak on Red Hat JWT azp origin validation (EUVD-2026-19201)

A vulnerability classified as problematic has been found in Keycloak on Red Hat. This vulnerability affects unknown code of the component JWT Handler . This manipulation of the argument azp causes ori…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5676 | Totolink A8000R 5.9c.681_B20180413 /cgi-bin/cstecgi.cgi setLanguageCfg langType missing authentication

A vulnerability classified as critical was found in Totolink A8000R 5.9c.681_B20180413 . This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi . Such manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5677 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi CsteSystem resetFlags os command injection

A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5678 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi setScheduleCfg mode os command injection

A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi . Executin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5679 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi vsetTr069Cfg stun_pass os command injection

A vulnerability has been found in Totolink A3300R 17.0.0cu.557_B20221024 and classified as critical . The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5673 | libtheora AVI File Parser avi_parse_input_file out-of-bounds

A vulnerability was found in libtheora and classified as problematic . This affects the function avi_parse_input_file of the component AVI File Parser . The manipulation results in out-of-bounds read.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5681 | itsourcecode sanitize or validate this input 1.0 Parameter /borrowedequip.php emp_id sql injection

A vulnerability was found in itsourcecode sanitize or validate this input 1.0 . It has been classified as critical . This impacts an unknown function of the file /borrowedequip.php of the component Pa…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5682 | Meesho Online Shopping App up to 27.3 on Android com.meesho.supply /api/endpoint risky encryption

A vulnerability was found in Meesho Online Shopping App up to 27.3 on Android. It has been declared as problematic . Affected is an unknown function of the file /api/endpoint of the component com.mees…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5683 | Tenda CX12L 16.03.53.12 /goform/P2pListFilter fromP2pListFilter page stack-based overflow

A vulnerability was found in Tenda CX12L 16.03.53.12 . It has been rated as critical . Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5684 | Tenda CX12L 16.03.53.12 webExcptypemanFilter fromwebExcptypemanFilter page stack-based overflow

A vulnerability categorized as critical has been discovered in Tenda CX12L 16.03.53.12 . Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter . Exec…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5685 | Tenda CX12L 16.03.53.12 /goform/addressNat fromAddressNat page stack-based overflow

A vulnerability identified as critical has been detected in Tenda CX12L 16.03.53.12 . This affects the function fromAddressNat of the file /goform/addressNat . The manipulation of the argument page le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5686 | Tenda CX12L 16.03.53.12 /goform/RouteStatic fromRouteStatic page stack-based overflow

A vulnerability labeled as critical has been found in Tenda CX12L 16.03.53.12 . This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic . The manipulation of the argume…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5687 | Tenda CX12L 16.03.53.12 /goform/NatStaticSetting fromNatStaticSetting page stack-based overflow

A vulnerability marked as critical has been reported in Tenda CX12L 16.03.53.12 . This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting . This manipulation of the a…

VulDB Read →
← Prev 157 / 265 Next →