CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8690 articles  ·  updated every 4 hours · grows forever

8690Total
4179Full Text
Jun 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5568 | Akaunting up to 3.1.21 Invoice/Billing notes cross site scripting

A vulnerability has been found in Akaunting up to 3.1.21 and classified as problematic . This issue affects some unknown processing of the component Invoice/Billing . The manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5569 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 Endpoint /Technostrobe/ access control

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 and classified as critical . Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5570 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 /LoginCB index_config improper authentication

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been classified as critical . The affected element is the function index_config of the file /LoginCB . This manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5571 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 Configuration Data /fs File information disclosure

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been declared as problematic . The impacted element is an unknown function of the file /fs of the component Configura…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5572 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 cross-site request forgery

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . It has been rated as problematic . This affects an unknown function. Performing a manipulation results in cross-site request…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5573 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 /fs cwd unrestricted upload

A vulnerability categorized as critical has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . This impacts an unknown function of the file /fs . Executing a manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5574 | Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 FsBrowseClean deletefile dir/path authorization

A vulnerability identified as problematic has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30 . Affected is the function deletefile of the component FsBrowseClean . The manipulation of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5575 | SourceCodester/jkev Record Management System 1.0 Login index.php Username sql injection

A vulnerability labeled as critical has been found in SourceCodester/jkev Record Management System 1.0 . Affected by this vulnerability is an unknown functionality of the file index.php of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5576 | SourceCodester/jkev Record Management System 1.0 Add Employee Page save_emp.php unrestricted upload

A vulnerability marked as critical has been reported in SourceCodester/jkev Record Management System 1.0 . Affected by this issue is some unknown functionality of the file save_emp.php of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5577 | Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a details Endpoint uniquemachine_app.py ID sql injection

A vulnerability described as critical has been identified in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a . This affects an unknown part of the file flask/uniquemachine_app.py …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5578 | CodeAstro Online Classroom 1.0 Parameter addassessment.php deleteid sql injection

A vulnerability classified as critical has been found in CodeAstro Online Classroom 1.0 . This vulnerability affects unknown code of the file /OnlineClassroom/addassessment.php of the component Parame…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5579 | CodeAstro Online Classroom 1.0 Parameter updatedetailsfromfaculty.php?myfid=108 fname sql injection

A vulnerability classified as critical was found in CodeAstro Online Classroom 1.0 . This issue affects some unknown processing of the file /OnlineClassroom/updatedetailsfromfaculty.php?myfid=108 of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5580 | CodeAstro Online Classroom 1.0 Parameter addvideos.php videotitle sql injection

A vulnerability, which was classified as critical , has been found in CodeAstro Online Classroom 1.0 . Impacted is an unknown function of the file /OnlineClassroom/addvideos.php of the component Param…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-4896 | wclovers WCFM Plugin up to 6.7.25 on WordPress post/product/page authorization

A vulnerability was found in wclovers WCFM Plugin up to 6.7.25 on WordPress. It has been classified as problematic . This affects the function wcfm_modify_order_status/delete_wcfm_article/delete_wcfm_…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2025-13368 | Xpro Addons Plugin up to 1.4.20 on WordPress Pricing Widget cross site scripting

A vulnerability was found in Xpro Addons Plugin up to 1.4.20 on WordPress. It has been declared as problematic . This impacts an unknown function of the component Pricing Widget . Such manipulation le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2025-15064 | ultimatemember Ultimate Member Plugin up to 2.11.1 on WordPress Setting user description cross site scripting

A vulnerability was found in ultimatemember Ultimate Member Plugin up to 2.11.1 on WordPress. It has been rated as problematic . Affected is an unknown function of the component Setting Handler . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-0552 | mra13 Simple Shopping Cart Plugin up to 5.2.4 on WordPress Shortcode wpsc_display_product cross site scripting

A vulnerability categorized as problematic has been discovered in mra13 Simple Shopping Cart Plugin up to 5.2.4 on WordPress. Affected by this vulnerability is the function wpsc_display_product of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-0664 | wproyal Royal Addons for Elementor Plugin up to 1.7.1049 on WordPress Parameter button_text cross site scripting

A vulnerability identified as problematic has been detected in wproyal Royal Addons for Elementor Plugin up to 1.7.1049 on WordPress. Affected by this issue is some unknown functionality of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-0737 | gn_themes WP Shortcodes Plugin up to 7.4.7 on WordPress Shortcode su_lightbox src cross site scripting

A vulnerability labeled as problematic has been found in gn_themes WP Shortcodes Plugin up to 7.4.7 on WordPress. This affects the function su_lightbox of the component Shortcode Handler . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-0738 | gn_themes WP Shortcodes Plugin up to 7.4.8 on WordPress Shortcode su_slide_link cross site scripting

A vulnerability marked as problematic has been reported in gn_themes WP Shortcodes Plugin up to 7.4.8 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-2600 | roxnor ElementsKit Elementor Addons Plugin up to 3.7.9 on WordPress Simple Tab Widget ekit_tab_title cross site scripting

A vulnerability described as problematic has been identified in roxnor ElementsKit Elementor Addons Plugin up to 3.7.9 on WordPress. This issue affects some unknown processing of the component Simple …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-2437 | wptravelengine WP Travel Engine Plugin up to 6.7.5 on WordPress Shortcode wte_trip_tax cross site scripting

A vulnerability classified as problematic has been found in wptravelengine WP Travel Engine Plugin up to 6.7.5 on WordPress. Impacted is the function wte_trip_tax of the component Shortcode Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-2826 | stellarwp Kadence Blocks Plugin up to 3.6.3 on WordPress REST API Endpoint process_pattern upload_files authorization

A vulnerability classified as critical was found in stellarwp Kadence Blocks Plugin up to 3.6.3 on WordPress. The affected element is the function upload_files of the file process_pattern of the compo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-3445 | properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin process_checkout authorization

A vulnerability, which was classified as critical , has been found in properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin up to…

VulDB Read →
← Prev 262 / 363 Next →