CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6338 articles  ·  updated every 4 hours · grows forever

6338Total
4066Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5650 | code-projects Online Application System for Admission 1.0 oas.sql sensitive information

A vulnerability was found in code-projects Online Application System for Admission 1.0 . It has been classified as critical . Impacted is an unknown function of the file /enrollment/database/oas.sql .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5619 | Braffolk mcp-summarization-functions up to 0.1.5 summarize_command src/server/mcp-server.ts os command injection

A vulnerability was found in Braffolk mcp-summarization-functions up to 0.1.5 and classified as critical . This impacts an unknown function of the file src/server/mcp-server.ts of the component summar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5620 | itsourcecode Construction Management System 1.0 Parameter borrowed_equip_report.php Home sql injection

A vulnerability was found in itsourcecode Construction Management System 1.0 . It has been classified as critical . Affected is an unknown function of the file /borrowed_equip_report.php of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5621 | ChrisChinchilla Vale-MCP up to 0.1.0 HTTP Interface src/index.ts config_path os command injection

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0 . It has been declared as critical . Affected by this vulnerability is an unknown functionality of the file src/index.ts of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5622 | hcengineering Huly Platform 0.7.382 JWT Token token.ts SERVER_SECRET hard-coded key

A vulnerability was found in hcengineering Huly Platform 0.7.382 . It has been rated as problematic . Affected by this issue is some unknown functionality of the file foundations/core/packages/token/s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5623 | hcengineering Huly Platform 0.7.382 Import Endpoint index.ts server-side request forgery

A vulnerability categorized as critical has been discovered in hcengineering Huly Platform 0.7.382 . This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5624 | ProjectSend r2002 upload.php cross-site request forgery

A vulnerability identified as problematic has been detected in ProjectSend r2002 . This vulnerability affects unknown code of the file upload.php . Performing a manipulation results in cross-site requ…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5625 | assafelovic gpt-researcher up to 3.4.3 WebSocket Interface researcher.py task cross site scripting (Issue 1692)

A vulnerability labeled as problematic has been found in assafelovic gpt-researcher up to 3.4.3 . This issue affects some unknown processing of the file gpt_researcher/skills/researcher.py of the comp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5628 | Belkin F9K1015 1.00.10 Setting formSetSystemSettings webpage stack-based overflow

A vulnerability marked as critical has been reported in Belkin F9K1015 1.00.10 . Impacted is the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5629 | Belkin F9K1015 1.00.10 /goform/formSetFirewall webpage stack-based overflow

A vulnerability described as critical has been identified in Belkin F9K1015 1.00.10 . The affected element is the function formSetFirewall of the file /goform/formSetFirewall . The manipulation of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5630 | assafelovic gpt-researcher up to 3.4.3 Report API backend/server/app.py cross site scripting (Issue 1693)

A vulnerability classified as problematic has been found in assafelovic gpt-researcher up to 3.4.3 . The impacted element is an unknown function of the file backend/server/app.py of the component Repo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5631 | assafelovic gpt-researcher up to 3.4.3 ws Endpoint server_utils.py extract_command_data args code injection (Issue 1694)

A vulnerability classified as critical was found in assafelovic gpt-researcher up to 3.4.3 . This affects the function extract_command_data of the file backend/server/server_utils.py of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5632 | assafelovic gpt-researcher up to 3.4.3 HTTP REST API Endpoint missing authentication (Issue 1695)

A vulnerability, which was classified as critical , has been found in assafelovic gpt-researcher up to 3.4.3 . This impacts an unknown function of the component HTTP REST API Endpoint . Performing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5633 | assafelovic gpt-researcher up to 3.4.3 ws Endpoint source_urls server-side request forgery (Issue 1696)

A vulnerability, which was classified as critical , was found in assafelovic gpt-researcher up to 3.4.3 . Affected is an unknown function of the component ws Endpoint . Executing a manipulation of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5634 | projectworlds Car Rental Project 1.0 Parameter /book_car.php fname sql injection

A vulnerability has been found in projectworlds Car Rental Project 1.0 and classified as critical . Affected by this vulnerability is an unknown functionality of the file /book_car.php of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5635 | PHPGurukul Online Shopping Portal Project 2.1 Parameter categorywise-products.php cid sql injection

A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1 and classified as critical . Affected by this issue is some unknown functionality of the file /categorywise-products.php of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5636 | PHPGurukul Online Shopping Portal Project 2.1 Parameter /cancelorder.php oid sql injection

A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1 . It has been classified as critical . This affects an unknown part of the file /cancelorder.php of the component Parameter H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5637 | projectworlds Car Rental System 1.0 Parameter /message_admin.php Message sql injection

A vulnerability was found in projectworlds Car Rental System 1.0 . It has been declared as critical . This vulnerability affects unknown code of the file /message_admin.php of the component Parameter …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5599 | pretix Venueless API improper isolation or compartmentalization (02b9cbe5)

A vulnerability, which was classified as critical , has been found in pretix Venueless . This vulnerability affects unknown code of the component API . The manipulation leads to improper isolation or …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5601 | Acrel Electrical Prepaid Cloud Platform 1.0 Backup File /bin.rar information disclosure

A vulnerability, which was classified as problematic , was found in Acrel Electrical Prepaid Cloud Platform 1.0 . This issue affects some unknown processing of the file /bin.rar of the component Backu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5602 | Nor2-io heim-mcp up to 0.1.3 new_heim_application src/tools.ts registerTools os command injection

A vulnerability has been found in Nor2-io heim-mcp up to 0.1.3 and classified as critical . Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5603 | elgentos magento2-dev-mcp up to 1.0.2 src/index.ts executeMagerun2Command os command injection

A vulnerability was found in elgentos magento2-dev-mcp up to 1.0.2 and classified as critical . The affected element is the function executeMagerun2Command of the file src/index.ts . Such manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5604 | Tenda CH22 1.0.0.1 Parameter CertLocalPrecreate formCertLocalPrecreate standard stack-based overflow

A vulnerability was found in Tenda CH22 1.0.0.1 . It has been classified as critical . The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 05, 2026
CVE-2026-5605 | Tenda CH22 1.0.0.1 /goform/WrlExtraSet formWrlExtraSet GO stack-based overflow

A vulnerability was found in Tenda CH22 1.0.0.1 . It has been declared as critical . This affects the function formWrlExtraSet of the file /goform/WrlExtraSet . Executing a manipulation of the argumen…

VulDB Read →
← Prev 160 / 265 Next →