CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10213 articles  ·  updated every 4 hours · grows forever

10213Total
4232Full Text
Jun 30, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13567 | code-projects Online Music Site 1.0 POST Request /Frontend/Feedback.php fname/femail/faddress/fmessage cross site scripting

A vulnerability was found in code-projects Online Music Site 1.0 and classified as problematic . This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler .…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13568 | SourceCodester Inventory Management System 1.0 User Registration Endpoint /api/users_handler.php role access control

A vulnerability was found in SourceCodester Inventory Management System 1.0 . It has been classified as critical . This vulnerability affects unknown code of the file /api/users_handler.php of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13569 | weng-xianhu EyouCMS up to 1.7.1 API /index.php click_like sql injection (Issue 68)

A vulnerability was found in weng-xianhu EyouCMS up to 1.7.1 . It has been declared as critical . This issue affects some unknown processing of the file /index.php of the component API . Such manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13570 | SourceCodester Inventory Management System 1.0 User Registration Endpoint /api/users_handler.php full_name cross site scripting

A vulnerability was found in SourceCodester Inventory Management System 1.0 . It has been rated as problematic . Impacted is an unknown function of the file /api/users_handler.php of the component Use…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13571 | SourceCodester Simple Food Ordering System 1.0 /cart.php item_price logic error

A vulnerability categorized as critical has been discovered in SourceCodester Simple Food Ordering System 1.0 . The affected element is an unknown function of the file /cart.php . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13572 | itsourcecode Hospital Management System 1.0 /insertbillingrecord.php patientid sql injection

A vulnerability identified as critical has been detected in itsourcecode Hospital Management System 1.0 . The impacted element is an unknown function of the file /insertbillingrecord.php . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13573 | llvm llvm-project up to 22.1.6 ValueSymbolTable ValueSymbolTable.cpp llvm::StringMap::insert stack-based overflow (Issue 199187)

A vulnerability labeled as problematic has been found in llvm llvm-project up to 22.1.6 . This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13574 | llvm llvm-project up to 22.1.6 Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow (Issue 199191)

A vulnerability marked as problematic has been reported in llvm llvm-project up to 22.1.6 . This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13523 | GPAC up to 26.02.0 ISOBMFF Parser base_encoding.c data amplification (Issue 3588)

A vulnerability, which was classified as problematic , was found in GPAC up to 26.02.0 . This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser . Executing …

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13524 | CherryHQ cherry-studio up to 1.9.6 MCP OAuth Local Callback Server callback.ts code improper authorization (Issue 15372)

A vulnerability has been found in CherryHQ cherry-studio up to 1.9.6 and classified as critical . This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13525 | CodeAstro Human Resource Management System 1.0 Update_Earn_Leave Endpoint Employee_model.php emselectByCode emid sql injection

A vulnerability was found in CodeAstro Human Resource Management System 1.0 and classified as critical . This issue affects the function emselectByCode of the file application/models/Employee_model.ph…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13526 | SourceCodester Class and Exam Timetabling System 1.0 /edit_class.php ID sql injection

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0 . It has been classified as critical . Impacted is an unknown function of the file /edit_class.php . This manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13527 | SourceCodester Class and Exam Timetabling System 1.0 /preview4.php course_year_section sql injection

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0 . It has been declared as critical . The affected element is an unknown function of the file /preview4.php . Such mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13528 | YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal (Issue 1146)

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT . It has been rated as critical . The impacted element is the function generateUploadPath of the file yudao-…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13529 | YzmCMS up to 7.5 index.php siteurl sql injection

A vulnerability categorized as critical has been discovered in YzmCMS up to 7.5 . This affects an unknown function of the file /application/install/index.php . Executing a manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13530 | itsourcecode Hospital Management System 1.0 Appointment /appointmentdetail.php editid sql injection

A vulnerability identified as critical has been detected in itsourcecode Hospital Management System 1.0 . This impacts an unknown function of the file /appointmentdetail.php of the component Appointme…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13531 | itsourcecode Hospital Management System 1.0 /department.php editid sql injection

A vulnerability labeled as critical has been found in itsourcecode Hospital Management System 1.0 . Affected is an unknown function of the file /department.php . The manipulation of the argument editi…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13532 | itsourcecode Hospital Management System 1.0 /departmentDoctor.php deptid sql injection

A vulnerability marked as critical has been reported in itsourcecode Hospital Management System 1.0 . Affected by this vulnerability is an unknown functionality of the file /departmentDoctor.php . Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13533 | agentejo Cockpit CMS up to 0.12.2 htaccess /config/config.yaml Spyc::YAMLLoad file access

A vulnerability described as problematic has been identified in agentejo Cockpit CMS up to 0.12.2 . Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13534 | CherryHQ cherry-studio up to 1.9.7 CherryIN Preload API MemoryService.ts sha256 state authorization (Issue 15411)

A vulnerability classified as problematic has been found in CherryHQ cherry-studio up to 1.9.7 . This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13535 | CodeAstro Human Resource Management System 1.0 View Endpoint Employee_model.php GetFileInfo ID sql injection

A vulnerability classified as critical was found in CodeAstro Human Resource Management System 1.0 . This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employe…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13536 | GotoHTTP up to 10.2 /reg.12x sn cross site scripting

A vulnerability, which was classified as problematic , has been found in GotoHTTP up to 10.2 . This issue affects some unknown processing of the file /reg.12x . The manipulation of the argument sn lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13537 | CodeAstro Human Resource Management System 1.0 cross-site request forgery

A vulnerability, which was classified as problematic , was found in CodeAstro Human Resource Management System 1.0 . Impacted is an unknown function. The manipulation results in cross-site request for…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13538 | Wavlink WL-NU516U1-A M16U1_V240425 POST Parameter /cgi-bin/wireless.cgi sub_401D68 SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 command injection

A vulnerability has been found in Wavlink WL-NU516U1-A M16U1_V240425 and classified as critical . The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POS…

VulDB Read →
← Prev 6 / 426 Next →