CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5930 articles  ·  updated every 4 hours · grows forever

5930Total
4046Full Text
May 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-32964 | silex SD-330AC/AMC Manager Configuration crlf injection

A vulnerability was found in silex SD-330AC and AMC Manager and classified as problematic . This affects an unknown function of the component Configuration Handler . The manipulation results in crlf i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-32963 | silex SD-330AC/AMC Manager Web cross site scripting

A vulnerability was found in silex SD-330AC and AMC Manager . It has been classified as problematic . This impacts an unknown function of the component Web Handler . This manipulation causes cross sit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-32958 | silex SD-330AC/AMC Manager Firmware Update hard-coded key

A vulnerability was found in silex SD-330AC and AMC Manager . It has been declared as problematic . Affected is an unknown function of the component Firmware Update Handler . Such manipulation leads t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-6648 | Qibo CMS 1.0 Internal Message cross site scripting

A vulnerability was found in Qibo CMS 1.0 . It has been rated as problematic . Affected by this vulnerability is an unknown functionality of the component Internal Message Module . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-6649 | Qibo CMS 1.0 /index/image/headers starts server-side request forgery

A vulnerability categorized as critical has been discovered in Qibo CMS 1.0 . Affected by this issue is some unknown functionality of the file /index/image/headers . Executing a manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-6650 | Z-BlogPHP 1.7.5 ZBA File app_upload.php App::UnPack unrestricted upload

A vulnerability identified as critical has been detected in Z-BlogPHP 1.7.5 . This affects the function App::UnPack of the file /zb_users/plugin/AppCentre/app_upload.php of the component ZBA File Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-6651 | erponline.xyz ERP Online up to 4.0.0 Inventory Edit Item Page Item Name cross site scripting

A vulnerability labeled as problematic has been found in erponline.xyz ERP Online up to 4.0.0 . This vulnerability affects unknown code of the component Inventory Edit Item Page . The manipulation of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-6652 | Pagekit CMS up to 1.0.18 StringStorage Template PhpEngine.php evaluate eval injection

A vulnerability marked as critical has been reported in Pagekit CMS up to 1.0.18 . This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorag…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6607 | lm-sys fastchat up to 0.2.36 Worker API Endpoint api_generate resource consumption (Issue 3833)

A vulnerability identified as problematic has been detected in lm-sys fastchat up to 0.2.36 . This issue affects the function api_generate of the component Worker API Endpoint . The manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6608 | lm-sys fastchat up to 0.2.36 Arena Side-by-Side View add_text control flow (Issue 3834)

A vulnerability labeled as problematic has been found in lm-sys fastchat up to 0.2.36 . Impacted is the function add_text of the component Arena Side-by-Side View Handler . The manipulation results in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6609 | liangliangyy DjangoBlog up to 2.1.0.0 oauth/views.py form_valid oauthid improper authorization

A vulnerability marked as critical has been reported in liangliangyy DjangoBlog up to 2.1.0.0 . The affected element is the function form_valid of the file oauth/views.py . This manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6610 | liangliangyy DjangoBlog up to 2.1.0.0 Setting djangoblog/settings.py USER/PASSWORD hard-coded credentials

A vulnerability described as critical has been identified in liangliangyy DjangoBlog up to 2.1.0.0 . The impacted element is an unknown function of the file djangoblog/settings.py of the component Set…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6611 | liangliangyy DjangoBlog up to 2.1.0.0 File Upload Endpoint djangoblog/settings.py SECRET_KEY hard-coded key

A vulnerability classified as problematic has been found in liangliangyy DjangoBlog up to 2.1.0.0 . This affects an unknown function of the file djangoblog/settings.py of the component File Upload End…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6612 | TransformerOptimus SuperAGI up to 0.0.14 Agent Execution Endpoint agent_execution.py get_agent_execution/update_agent_execution agent_execution_id authorization

A vulnerability classified as critical was found in TransformerOptimus SuperAGI up to 0.0.14 . This impacts the function get_agent_execution/update_agent_execution of the file superagi/controllers/age…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6613 | TransformerOptimus SuperAGI up to 0.0.14 agent.py delete_agent/stop_schedule/get_schedule_data agent_id authorization

A vulnerability, which was classified as critical , has been found in TransformerOptimus SuperAGI up to 0.0.14 . Affected is the function delete_agent/stop_schedule/get_schedule_data of the file super…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6614 | TransformerOptimus SuperAGI up to 0.0.14 project.py authorization

A vulnerability, which was classified as critical , was found in TransformerOptimus SuperAGI up to 0.0.14 . Affected by this vulnerability is the function get_project/update_project/get_projects_organ…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6615 | TransformerOptimus SuperAGI up to 0.0.14 Multipart Upload resources.py upload Name path traversal

A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14 and classified as critical . Affected by this issue is the function Upload of the file superagi/controllers/resources.py of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6616 | TransformerOptimus SuperAGI up to 0.0.14 WebScraperTool webpage_extractor.py server-side request forgery

A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14 and classified as critical . This affects the function extract_with_bs4/extract_with_3k/extract_with_lxml of the file superagi/hel…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6617 | langgenius dify up to 0.6.9 ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema url server-side request forgery

A vulnerability was found in langgenius dify up to 0.6.9 . It has been classified as critical . This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/too…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6618 | langgenius dify up to 1.13.3 ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle url server-side request forgery

A vulnerability was found in langgenius dify up to 1.13.3 . It has been declared as critical . This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6619 | langgenius dify up to 1.13.3 ImagePreview image-preview.tsx openInNewTab filename cross site scripting

A vulnerability was found in langgenius dify up to 1.13.3 . It has been rated as problematic . Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.ts…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6620 | SonicCloudOrg sonic-server up to 2.0.0 File Upload Endpoint FileTool.java upload Type path traversal

A vulnerability categorized as critical has been discovered in SonicCloudOrg sonic-server up to 2.0.0 . The affected element is the function Upload of the file FileTool.java of the component File Uplo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6621 | 1024bit extend-deep up to 0.1.6 index.js __proto__ prototype pollution

A vulnerability identified as critical has been detected in 1024bit extend-deep up to 0.1.6 . The impacted element is an unknown function of the file index.js . This manipulation of the argument __pro…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6622 | BichitroGan ISP Billing Software 2025.3.20 Customer edit cross site scripting

A vulnerability labeled as problematic has been found in BichitroGan ISP Billing Software 2025.3.20 . This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer H…

VulDB Read →
← Prev 81 / 248 Next →