CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5930 articles  ·  updated every 4 hours · grows forever

5930Total
4046Full Text
May 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6623 | BichitroGan ISP Billing Software 2025.3.20 Profile Page users-view cross site scripting

A vulnerability marked as problematic has been reported in BichitroGan ISP Billing Software 2025.3.20 . This impacts an unknown function of the file /?_route=settings/users-view/ of the component Prof…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6624 | BichitroGan ISP Billing Software 2025.3.20 Pool List Interface /?\_route=pool/add cross site scripting

A vulnerability described as problematic has been identified in BichitroGan ISP Billing Software 2025.3.20 . Affected is an unknown function of the file /?\_route=pool/add of the component Pool List I…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6625 | moxi624 Mogu Blog v2 up to 5.2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgery

A vulnerability classified as critical has been found in moxi624 Mogu Blog v2 up to 5.2 . Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_pictur…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6626 | Cockpit-HQ Cockpit up to 2.13.5 Asset Handler/Aggregate data query logic injection

A vulnerability classified as critical was found in Cockpit-HQ Cockpit up to 2.13.5 . Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6628 | phili67 Ecclesia CRM up to 8.0.0 Query Viewer /v2/query/view/ ValidateInput custom sql injection

A vulnerability, which was classified as critical , has been found in phili67 Ecclesia CRM up to 8.0.0 . This affects the function ValidateInput of the file /v2/query/view/ of the component Query View…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6629 | Metasoft 美特软件 MetaCRM up to 6.4.0 Interface sql.jsp Statement.executeUpdate sql sql injection

A vulnerability, which was classified as critical , was found in Metasoft 美特软件 MetaCRM up to 6.4.0 . This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6630 | Tenda F451 1.0.0.7_cn_svn7958 httpd /goform/GstDhcpSetSer fromGstDhcpSetSer dips buffer overflow

A vulnerability has been found in Tenda F451 1.0.0.7_cn_svn7958 and classified as critical . This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6631 | Tenda F451 1.0.0.7_cn_svn7958 httpd webExcptypemanFilter fromwebExcptypemanFilter page buffer overflow

A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958 and classified as critical . Impacted is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component http…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6632 | Tenda F451 1.0.0.7_cn_svn7958 httpd /goform/SafeClientFilter fromSafeClientFilter menufacturer/Go buffer overflow

A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958 . It has been classified as critical . The affected element is the function fromSafeClientFilter of the file /goform/SafeClientFilter of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6633 | Yifang CMS up to 2.0.5 Extended Management L_rbac_admin.php store Account cross site scripting

A vulnerability was found in Yifang CMS up to 2.0.5 . It has been declared as problematic . The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_adm…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6634 | usememos up to 0.22.1 UpdateInstanceSetting src/App.tsx memos_access_token additionalStyle/additionalScript improper authorization

A vulnerability was found in usememos memos up to 0.22.1 . It has been rated as critical . This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6635 | rowboatlabs rowboat up to 0.1.67 tools_webhook app.py tool_call X-Tools-JWE improper authentication

A vulnerability categorized as critical has been discovered in rowboatlabs rowboat up to 0.1.67 . This impacts the function tool_call of the file apps/experimental/tools_webhook/app.py of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6636 | p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b API buildCache.js Bun.serve pathname path traversal

A vulnerability identified as critical has been detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b . Affected is the function Bun.serve of the file buildCache.js of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6596 | langflow-ai langflow up to 1.1.0 API Endpoint endpoints.py create_upload_file unrestricted upload

A vulnerability described as critical has been identified in langflow-ai langflow up to 1.1.0 . This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoint…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6597 | langflow-ai langflow up to 1.8.3 Flow Using API core.py remove_api_keys/has_api_terms credentials storage

A vulnerability classified as problematic has been found in langflow-ai langflow up to 1.8.3 . Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6598 | langflow-ai langflow up to 1.8.3 Project Creation Endpoint projects.py create_project/encrypt_auth_settings cleartext storage in file

A vulnerability classified as problematic was found in langflow-ai langflow up to 1.8.3 . The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6599 | langflow-ai langflow up to 1.8.3 Model Context Protocol Configuration API mcp_projects.py get_client_ip/install_mcp_config X-Forwarded-For injection

A vulnerability, which was classified as critical , has been found in langflow-ai langflow up to 1.8.3 . The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/b…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6600 | langflow-ai langflow up to 1.8.3 Frontend React Component Rendering edit-message.tsx cross site scripting

A vulnerability, which was classified as problematic , was found in langflow-ai langflow up to 1.8.3 . This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6601 | Lagom WHMCS Template up to 2.4.2 Datatables resource consumption

A vulnerability has been found in Lagom WHMCS Template up to 2.4.2 and classified as problematic . This impacts an unknown function of the component Datatables . The manipulation leads to resource con…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6602 | rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4 his_admin_account.php ad_dpic unrestricted upload

A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4 and classified as critical . Affected is an unknown function of the file /backend/admin/hi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6603 | modelscope agentscope up to 1.0.18 _python.py execute_python_code/execute_shell_command code injection

A vulnerability was found in modelscope agentscope up to 1.0.18 . It has been classified as critical . Affected by this vulnerability is the function execute_python_code/execute_shell_command of the f…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6604 | modelscope agentscope up to 1.0.18 Cloud Metadata Endpoint _openai_tools.py _parse_url/prepare_image/openai_audio_to_text image_url/audio_file_url server-side request forgery

A vulnerability was found in modelscope agentscope up to 1.0.18 . It has been declared as critical . Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file sr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6605 | modelscope agentscope up to 1.0.18 Internal Service _common.py _get_bytes_from_web_url server-side request forgery

A vulnerability was found in modelscope agentscope up to 1.0.18 . It has been rated as critical . This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6606 | modelscope agentscope up to 1.0.18 _agent_base.py _process_audio_block url server-side request forgery

A vulnerability categorized as critical has been discovered in modelscope agentscope up to 1.0.18 . This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent…

VulDB Read →
← Prev 82 / 248 Next →