CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10243 articles  ·  updated every 4 hours · grows forever

10243Total
4232Full Text
Jun 30, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13533 | agentejo Cockpit CMS up to 0.12.2 htaccess /config/config.yaml Spyc::YAMLLoad file access

A vulnerability described as problematic has been identified in agentejo Cockpit CMS up to 0.12.2 . Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13534 | CherryHQ cherry-studio up to 1.9.7 CherryIN Preload API MemoryService.ts sha256 state authorization (Issue 15411)

A vulnerability classified as problematic has been found in CherryHQ cherry-studio up to 1.9.7 . This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13535 | CodeAstro Human Resource Management System 1.0 View Endpoint Employee_model.php GetFileInfo ID sql injection

A vulnerability classified as critical was found in CodeAstro Human Resource Management System 1.0 . This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employe…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13536 | GotoHTTP up to 10.2 /reg.12x sn cross site scripting

A vulnerability, which was classified as problematic , has been found in GotoHTTP up to 10.2 . This issue affects some unknown processing of the file /reg.12x . The manipulation of the argument sn lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13537 | CodeAstro Human Resource Management System 1.0 cross-site request forgery

A vulnerability, which was classified as problematic , was found in CodeAstro Human Resource Management System 1.0 . Impacted is an unknown function. The manipulation results in cross-site request for…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13538 | Wavlink WL-NU516U1-A M16U1_V240425 POST Parameter /cgi-bin/wireless.cgi sub_401D68 SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 command injection

A vulnerability has been found in Wavlink WL-NU516U1-A M16U1_V240425 and classified as critical . The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POS…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13539 | Wavlink WL-NU516U1-A M16U1_V240425 POST Parameter /cgi-bin/wireless.cgi sub_407504 Guest_ssid stack-based overflow

A vulnerability was found in Wavlink WL-NU516U1-A M16U1_V240425 and classified as critical . The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Par…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13540 | GitBucket up to 4.46.1 RepositoryCreationService.scala Git.cloneRepository.setURI url server-side request forgery (Issue 4044)

A vulnerability was found in GitBucket up to 4.46.1 . It has been classified as critical . This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/Reposi…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13541 | itsourcecode Hospital Management System 1.0 doctorchangepassword.php newpassword sql injection

A vulnerability was found in itsourcecode Hospital Management System 1.0 . It has been declared as critical . This impacts an unknown function of the file /doctorchangepassword.php . Executing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13542 | itsourcecode Hospital Management System 1.0 /doctorprofile.php doctorname sql injection

A vulnerability was found in itsourcecode Hospital Management System 1.0 . It has been rated as critical . Affected is an unknown function of the file /doctorprofile.php . The manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13543 | Documenso up to 2.11.0 Google OAuth Login handle-oauth-callback-url.ts improper authentication (Issue 2758)

A vulnerability categorized as critical has been discovered in Documenso up to 2.11.0 . Affected by this vulnerability is an unknown functionality of the file packages/auth/server/lib/utils/handle-oau…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13544 | Feehi CMS up to 2.1.1 API /api/users access control (Issue 88)

A vulnerability identified as critical has been detected in Feehi CMS up to 2.1.1 . Affected by this issue is some unknown functionality of the file /api/users of the component API . This manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13545 | D-Link DCS-935L 1.10.01 POST Parameter setconf.cgi sub_400E40 UID os command injection

A vulnerability labeled as critical has been found in D-Link DCS-935L 1.10.01 . This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler . Such manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13546 | Feehi CMS up to 2.1.1 REST API Endpoint /api/articles missing authentication (Issue 87)

A vulnerability marked as critical has been reported in Feehi CMS up to 2.1.1 . This vulnerability affects unknown code of the file /api/articles of the component REST API Endpoint . Performing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13547 | Hanwang e-Face General Management Platform 6.3.5.4 upload.do File unrestricted upload

A vulnerability described as critical has been identified in Hanwang e-Face General Management Platform 6.3.5.4 . This issue affects some unknown processing of the file /manage/resourceUpload/upload.d…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13548 | itsourcecode Hospital Management System 1.0 /doctortimings.php editid sql injection

A vulnerability classified as critical has been found in itsourcecode Hospital Management System 1.0 . Impacted is an unknown function of the file /doctortimings.php . The manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13549 | CodeAstro Complaint Management System 1.0 Report Endpoint Report.php deletereport authorization

A vulnerability classified as problematic was found in CodeAstro Complaint Management System 1.0 . The affected element is the function deletereport of the file application/controllers/Report.php of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13550 | itsourcecode Baptism Information Management System 1.0 /delbaptism.php ID sql injection

A vulnerability, which was classified as critical , has been found in itsourcecode Baptism Information Management System 1.0 . The impacted element is an unknown function of the file /delbaptism.php .…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13551 | itsourcecode Baptism Information Management System 1.0 /editBaptism.php ID sql injection

A vulnerability, which was classified as critical , was found in itsourcecode Baptism Information Management System 1.0 . This affects an unknown function of the file /editBaptism.php . Such manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CISA, researchers warn of escalating attacks using Cisco Catalyst SD-WAN flaws - Cybersecurity Dive

CISA, researchers warn of escalating attacks using Cisco Catalyst SD-WAN flaws Cybersecurity Dive

Cybersecurity Dive Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-8095 | nmedia Frontend File Manager Plugin up to 23.6 on WordPress AJAX wp-config.php sanitize_key wpfm_dir_path file inclusion

A vulnerability classified as problematic was found in nmedia Frontend File Manager Plugin up to 23.6 on WordPress. Impacted is the function sanitize_key of the file wp-config.php of the component AJA…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58049 | FFmpeg Media libavcodec/rasc.c out-of-bounds write

A vulnerability, which was classified as critical , has been found in FFmpeg . The affected element is an unknown function of the file libavcodec/rasc.c of the component Media Handler . The manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58053 | Gitea act_runner up to 0.262.0 Docker Backend privileges management

A vulnerability, which was classified as critical , was found in Gitea act_runner up to 0.262.0 . The impacted element is an unknown function of the component Docker Backend . The manipulation results…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58051 | libssh2 up to 1.11.1 SSH uninitialized resource

A vulnerability has been found in libssh2 up to 1.11.1 and classified as problematic . This affects an unknown function of the component SSH Handler . This manipulation causes uninitialized resource. …

VulDB Read →
← Prev 8 / 427 Next →