CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6368 articles  ·  updated every 4 hours · grows forever

6368Total
4066Full Text
May 24, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5562 | provectus kafka-ui up to 0.7.2 Endpoint testexecutions validateAccess code injection

A vulnerability marked as critical has been reported in provectus kafka-ui up to 0.7.2 . This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5563 | AutohomeCorp frostmourne up to 1.0 Alarm Preview previewData httpTest sql injection

A vulnerability described as critical has been identified in AutohomeCorp frostmourne up to 1.0 . Affected is the function httpTest of the file /api/monitor-api/alarm/previewData of the component Alar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5564 | code-projects Simple Laundry System 1.0 Parameter /searchguest.php searchServiceId sql injection

A vulnerability classified as critical has been found in code-projects Simple Laundry System 1.0 . Affected by this vulnerability is an unknown functionality of the file /searchguest.php of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5565 | code-projects Simple Laundry System 1.0 Parameter /delmemberinfo.php userid sql injection

A vulnerability classified as critical was found in code-projects Simple Laundry System 1.0 . Affected by this issue is some unknown functionality of the file /delmemberinfo.php of the component Param…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5566 | UTT HiPER 1250GW up to 3.2.7-210907-180535 /goform/formNatStaticMap strcpy NatBind buffer overflow

A vulnerability, which was classified as critical , has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535 . This affects the function strcpy of the file /goform/formNatStaticMap . Performing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5567 | Tenda M3 1.0.0.10 Destination /goform/setAdvPolicyData policyType buffer overflow

A vulnerability, which was classified as critical , was found in Tenda M3 1.0.0.10 . This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Dest…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5568 | Akaunting up to 3.1.21 Invoice/Billing notes cross site scripting

A vulnerability has been found in Akaunting up to 3.1.21 and classified as problematic . This issue affects some unknown processing of the component Invoice/Billing . The manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5569 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 Endpoint /Technostrobe/ access control

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 and classified as critical . Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5570 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 /LoginCB index_config improper authentication

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been classified as critical . The affected element is the function index_config of the file /LoginCB . This manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5571 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 Configuration Data /fs File information disclosure

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been declared as problematic . The impacted element is an unknown function of the file /fs of the component Configura…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5572 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 cross-site request forgery

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been rated as problematic . This affects an unknown function. Performing a manipulation results in cross-site request…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5573 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 /fs cwd unrestricted upload

A vulnerability categorized as critical has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . This impacts an unknown function of the file /fs . Executing a manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5574 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 FsBrowseClean deletefile dir/path authorization

A vulnerability identified as problematic has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . Affected is the function deletefile of the component FsBrowseClean . The manipulation of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5575 | SourceCodester/jkev Record Management System 1.0 Login index.php Username sql injection

A vulnerability labeled as critical has been found in SourceCodester/jkev Record Management System 1.0 . Affected by this vulnerability is an unknown functionality of the file index.php of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5576 | SourceCodester/jkev Record Management System 1.0 Add Employee Page save_emp.php unrestricted upload

A vulnerability marked as critical has been reported in SourceCodester/jkev Record Management System 1.0 . Affected by this issue is some unknown functionality of the file save_emp.php of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5577 | Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a details Endpoint uniquemachine_app.py ID sql injection

A vulnerability described as critical has been identified in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a . This affects an unknown part of the file flask/uniquemachine_app.py …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5578 | CodeAstro Online Classroom 1.0 Parameter addassessment.php deleteid sql injection

A vulnerability classified as critical has been found in CodeAstro Online Classroom 1.0 . This vulnerability affects unknown code of the file /OnlineClassroom/addassessment.php of the component Parame…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5579 | CodeAstro Online Classroom 1.0 Parameter updatedetailsfromfaculty.php?myfid=108 fname sql injection

A vulnerability classified as critical was found in CodeAstro Online Classroom 1.0 . This issue affects some unknown processing of the file /OnlineClassroom/updatedetailsfromfaculty.php?myfid=108 of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5580 | CodeAstro Online Classroom 1.0 Parameter addvideos.php videotitle sql injection

A vulnerability, which was classified as critical , has been found in CodeAstro Online Classroom 1.0 . Impacted is an unknown function of the file /OnlineClassroom/addvideos.php of the component Param…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-4896 | wclovers WCFM Plugin up to 6.7.25 on WordPress post/product/page authorization

A vulnerability was found in wclovers WCFM Plugin up to 6.7.25 on WordPress. It has been classified as problematic . This affects the function wcfm_modify_order_status/delete_wcfm_article/delete_wcfm_…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2025-13368 | Xpro Addons Plugin up to 1.4.20 on WordPress Pricing Widget cross site scripting

A vulnerability was found in Xpro Addons Plugin up to 1.4.20 on WordPress. It has been declared as problematic . This impacts an unknown function of the component Pricing Widget . Such manipulation le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2025-15064 | ultimatemember Ultimate Member Plugin up to 2.11.1 on WordPress Setting user description cross site scripting

A vulnerability was found in ultimatemember Ultimate Member Plugin up to 2.11.1 on WordPress. It has been rated as problematic . Affected is an unknown function of the component Setting Handler . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-0552 | mra13 Simple Shopping Cart Plugin up to 5.2.4 on WordPress Shortcode wpsc_display_product cross site scripting

A vulnerability categorized as problematic has been discovered in mra13 Simple Shopping Cart Plugin up to 5.2.4 on WordPress. Affected by this vulnerability is the function wpsc_display_product of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-0664 | wproyal Royal Addons for Elementor Plugin up to 1.7.1049 on WordPress Parameter button_text cross site scripting

A vulnerability identified as problematic has been detected in wproyal Royal Addons for Elementor Plugin up to 1.7.1049 on WordPress. Affected by this issue is some unknown functionality of the compon…

VulDB Read →
← Prev 165 / 266 Next →