CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10056 articles  ·  updated every 4 hours · grows forever

10056Total
4231Full Text
Jun 28, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4540 | projectworlds Online Notes Sharing System 1.0 Parameters /login.php User sql injection

A vulnerability was found in projectworlds Online Notes Sharing System 1.0 and classified as critical . This issue affects some unknown processing of the file /login.php of the component Parameters Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4541 | janmojzis tinyssh up to 20250501 Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification (Issue 101)

A vulnerability was found in janmojzis tinyssh up to 20250501 . It has been classified as problematic . Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4542 | SSCMS 4.7.0 layerImage Endpoint LayerImageController.Submit.cs filePaths path traversal

A vulnerability was found in SSCMS 4.7.0 . It has been declared as critical . The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4543 | Wavlink WL-WN578W2 221110 POST Request /cgi-bin/firewall.cgi dmz_flag/del_flag command injection

A vulnerability was found in Wavlink WL-WN578W2 221110 . It has been rated as critical . The impacted element is an unknown function of the file /cgi-bin/firewall.cgi of the component POST Request Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4544 | Wavlink WL-WN578W2 221110 POST Request /cgi-bin/login.cgi homepage/hostname/login_page cross site scripting

A vulnerability categorized as problematic has been discovered in Wavlink WL-WN578W2 221110 . This affects an unknown function of the file /cgi-bin/login.cgi of the component POST Request Handler . Ex…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
Multiple Hikvision Vulnerabilities Allow Attackers to Disrupt Devices Using Crafted Packets - cyberpress.org

Multiple Hikvision Vulnerabilities Allow Attackers to Disrupt Devices Using Crafted Packets cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4528 | trueleaf ApiFlow 0.9.7 URL Validation http_proxy.service.ts validateUrlSecurity server-side request forgery

A vulnerability was found in trueleaf ApiFlow 0.9.7 . It has been classified as critical . The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_p…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4529 | D-Link DHP-1320 1.00WWB04 SOAP redirect_count_down_page stack-based overflow

A vulnerability was found in D-Link DHP-1320 1.00WWB04 . It has been declared as critical . This affects the function redirect_count_down_page of the component SOAP Handler . Such manipulation leads t…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4530 | apconw Aix-DB up to 1.2.3 terminology_retriever.py Description sql injection

A vulnerability was found in apconw Aix-DB up to 1.2.3 . It has been rated as critical . This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py . Performing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4531 | Free5GC 4.1.0 AMF internal/gmm/handler.go HandleRegistrationComplete denial of service (Issue 792)

A vulnerability categorized as problematic has been discovered in Free5GC 4.1.0 . Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF . Executi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4532 | code-projects Simple Food Ordering System up to 1.0 Database Backup /food/sql/food.sql file access

A vulnerability identified as problematic has been detected in code-projects Simple Food Ordering System up to 1.0 . Affected by this vulnerability is an unknown functionality of the file /food/sql/fo…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4533 | code-projects Simple Food Ordering System 1.0 all-tickets.php Status sql injection

A vulnerability labeled as critical has been found in code-projects Simple Food Ordering System 1.0 . Affected by this issue is some unknown functionality of the file all-tickets.php . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4534 | Tenda FH451 1.0.0.9 /goform/WrlExtraSet formWrlExtraSet GO stack-based overflow

A vulnerability marked as critical has been reported in Tenda FH451 1.0.0.9 . This affects the function formWrlExtraSet of the file /goform/WrlExtraSet . This manipulation of the argument GO causes st…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4535 | Tenda FH451 1.0.0.9 /goform/WrlclientSet GO stack-based overflow

A vulnerability described as critical has been identified in Tenda FH451 1.0.0.9 . This vulnerability affects the function WrlclientSet of the file /goform/WrlclientSet . Such manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4536 | Acrel Environmental Monitoring Cloud Platform 1.1.0 unrestricted upload

A vulnerability classified as critical has been found in Acrel Environmental Monitoring Cloud Platform 1.1.0 . This issue affects some unknown processing. Performing a manipulation results in unrestri…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4537 | Cudy TR1200 R46-2.4.15-20250721-164017 ipsec.lua action_ipsec_conn command injection

A vulnerability classified as critical was found in Cudy TR1200 R46-2.4.15-20250721-164017 . Impacted is the function action_ipsec_conn of the file /usr/bin/lib/lua/luci/controller/ipsec.lua . Executi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4538 | PyTorch 2.10.0 pt2 Loading deserialization (ID 176791)

A vulnerability, which was classified as critical , has been found in PyTorch 2.10.0 . The affected element is an unknown function of the component pt2 Loading Handler . The manipulation leads to dese…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4539 | pygments up to 2.19.2 archetype.py AdlLexer redos (Issue 3058)

A vulnerability, which was classified as problematic , was found in pygments up to 2.19.2 . The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py . The manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
MSHTML Framework Zero-Day Opens Door to Network-Based Security Bypass - gbhackers.com

MSHTML Framework Zero-Day Opens Door to Network-Based Security Bypass gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4067 | nocaredev Ad Short Plugin up to 2.0.1 on WordPress Shortcode ad_func cross site scripting

A vulnerability has been found in nocaredev Ad Short Plugin up to 2.0.1 on WordPress and classified as problematic . Affected is the function ad_func of the component Shortcode Handler . This manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4143 | neo2oo5 Neos Connector for Fakturama Plugin up to 0.0.14 on WordPress Setting ncff_add_plugin_page cross-site request forgery

A vulnerability was found in neo2oo5 Neos Connector for Fakturama Plugin up to 0.0.14 on WordPress and classified as problematic . Affected by this vulnerability is the function ncff_add_plugin_page o…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4161 | revukangaroo Review Map by RevuKangaroo Plugin up to 1.7 on WordPress Setting cross site scripting

A vulnerability was found in revukangaroo Review Map by RevuKangaroo Plugin up to 1.7 on WordPress. It has been classified as problematic . Affected by this issue is some unknown functionality of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4086 | newbiesup WP Random Button Plugin up to 1.0 on WordPress Shortcode random_button_html nocat cross site scripting

A vulnerability was found in newbiesup WP Random Button Plugin up to 1.0 on WordPress. It has been declared as problematic . This affects the function random_button_html of the component Shortcode Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4072 | tstachl WordPress PayPal Donation Plugin up to 1.01 on WordPress Shortcode wordpress_paypal_donation_create cross site scripting

A vulnerability was found in tstachl WordPress PayPal Donation Plugin up to 1.01 on WordPress. It has been rated as problematic . This vulnerability affects the function wordpress_paypal_donation_crea…

VulDB Read →
← Prev 387 / 419 Next →