CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5713 articles  ·  updated every 4 hours · grows forever

5713Total
4036Full Text
May 17, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7224 | SourceCodester Pizzafy Ecommerce System 1.0 ajax.php?action=delete_cart ID sql injection

A vulnerability identified as critical has been detected in SourceCodester Pizzafy Ecommerce System 1.0 . This affects the function delete_cart of the file /admin/ajax.php?action=delete_cart . Perform…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7225 | SourceCodester Pizzafy Ecommerce System 1.0 ajax.php?action=delete_menu ID sql injection

A vulnerability labeled as critical has been found in SourceCodester Pizzafy Ecommerce System 1.0 . This vulnerability affects the function delete_menu of the file /admin/ajax.php?action=delete_menu .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7226 | SourceCodester Pizzafy Ecommerce System 1.0 ajax.php?action=login2 e-mail sql injection

A vulnerability marked as critical has been reported in SourceCodester Pizzafy Ecommerce System 1.0 . This issue affects the function login2 of the file /admin/ajax.php?action=login2 . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7227 | SourceCodester Pizzafy Ecommerce System 1.0 ajax.php?action=login e-mail sql injection

A vulnerability described as critical has been identified in SourceCodester Pizzafy Ecommerce System 1.0 . Impacted is the function Login of the file /admin/ajax.php?action=login . The manipulation of…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7228 | SourceCodester Pizzafy Ecommerce System 1.0 ajax.php?action=get_cart_count ID sql injection

A vulnerability classified as critical has been found in SourceCodester Pizzafy Ecommerce System 1.0 . The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-41464 | ProjeQtor up to 12.4.3 Password Hash objectDetail.php authorization

A vulnerability classified as problematic was found in ProjeQtor up to 12.4.3 . The impacted element is an unknown function of the file objectDetail.php of the component Password Hash Handler . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7229 | code-projects Coaching Management System 1.0 POST reply.php complaintreply sql injection

A vulnerability, which was classified as critical , has been found in code-projects Coaching Management System 1.0 . This affects an unknown function of the file /cims/modules/admin/reply.php of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-41465 | ProjeQtor up to 12.4.3 dynamicDialog.php logname path traversal

A vulnerability, which was classified as critical , was found in ProjeQtor up to 12.4.3 . This impacts an unknown function of the file dynamicDialog.php . Executing a manipulation of the argument logn…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-41463 | ProjeQtor up to 12.4.3 Archive Extraction path traversal

A vulnerability has been found in ProjeQtor up to 12.4.3 and classified as critical . Affected is an unknown function of the component Archive Extraction Handler . The manipulation leads to path trave…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-41466 | ProjeQtor up to 12.4.3 Security.php checkValidHtmlText cross site scripting

A vulnerability was found in ProjeQtor up to 12.4.3 and classified as problematic . Affected by this vulnerability is the function checkValidHtmlText of the file Security.php . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-30352 | leonvanzyl autocoder 79d02a Command /devserver/start privilege escalation

A vulnerability was found in leonvanzyl autocoder 79d02a . It has been classified as critical . Affected by this issue is some unknown functionality of the file /devserver/start of the component Comma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-30351 | leonvanzyl autocoder 79d02a URL path traversal

A vulnerability was found in leonvanzyl autocoder 79d02a . It has been declared as critical . This affects an unknown part of the component URL Handler . Such manipulation leads to path traversal. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-41462 | ProjeQtor up to 12.4.3 Authentication Endpoint Username sql injection

A vulnerability was found in ProjeQtor up to 12.4.3 . It has been rated as critical . This vulnerability affects unknown code of the component Authentication Endpoint . Performing a manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2025-54505 | AMD EPYC 7001 Processors/EPYC Embedded 3000 Processors Floating Point information disclosure

A vulnerability categorized as problematic has been discovered in AMD EPYC 7001 Processors and EPYC Embedded 3000 Processors . This issue affects some unknown processing of the component Floating Poin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-41467 | ProjeQtor up to 12.4.3 File checkValidFileName cross site scripting

A vulnerability identified as problematic has been detected in ProjeQtor up to 12.4.3 . Impacted is the function checkValidFileName of the component File Handler . The manipulation leads to cross site…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7230 | SourceCodester Safety Anger Pad 1.0 angerDisplay cross site scripting

A vulnerability labeled as problematic has been found in SourceCodester Safety Anger Pad 1.0 . The affected element is an unknown function. The manipulation of the argument angerDisplay results in cro…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7150 | dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b MCP Tool server.py generate_favicon_from_url image_url server-side request forgery

A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b and classified as critical . This issue affects the function generate_favicon_from_url of the file src/a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7151 | Tenda HG3 2.0 /boaform/formIPv6Routing formUploadConfig destNet stack-based overflow

A vulnerability was found in Tenda HG3 2.0 . It has been classified as critical . Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing . This manipulation of the argument des…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7152 | Totolink A8000RU 7.1cu.643_b20200521 CGI /cgi-bin/cstecgi.cgi setTelnetCfg telnet_enabled os command injection

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521 . It has been declared as critical . The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7153 | Totolink A8000RU 7.1cu.643_b20200521 CGI /cgi-bin/cstecgi.cgi setMiniuiHomeInfoShow sys_info os command injection

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521 . It has been rated as critical . The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7154 | Totolink A8000RU 7.1cu.643_b20200521 CGI /cgi-bin/cstecgi.cgi setAdvancedInfoShow tty_server os command injection

A vulnerability categorized as critical has been discovered in Totolink A8000RU 7.1cu.643_b20200521 . This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CG…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7155 | Totolink A8000RU 7.1cu.643_b20200521 CGI /cgi-bin/cstecgi.cgi setLoginPasswordCfg admpass os command injection

A vulnerability identified as critical has been detected in Totolink A8000RU 7.1cu.643_b20200521 . This impacts the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7156 | Totolink A8000RU 7.1cu.643_b20200521 CGI /cgi-bin/cstecgi.cgi CsteSystem HTTP os command injection

A vulnerability labeled as critical has been found in Totolink A8000RU 7.1cu.643_b20200521 . Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7157 | disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc aider_ai_code server.py relative_editable_files command injection

A vulnerability marked as critical has been reported in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc . Affected by this vulnerability is an unknown functionality of the file …

VulDB Read →
← Prev 44 / 239 Next →