CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5930 articles  ·  updated every 4 hours · grows forever

5930Total
4046Full Text
May 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6588 | serge-chat serge up to 1.4TB Model API Endpoint model.py download_model/delete_model missing authentication

A vulnerability was found in serge-chat serge up to 1.4TB and classified as critical . The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6589 | ComfyUI up to 0.13.0 server.py create_origin_only_middleware cross-site request forgery

A vulnerability was found in ComfyUI up to 0.13.0 . It has been classified as problematic . This affects the function create_origin_only_middleware of the file server.py . The manipulation leads to cr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6590 | ComfyUI up to 0.13.0 Model Preview Endpoint app/model_manager.py get_model_preview path traversal

A vulnerability was found in ComfyUI up to 0.13.0 . It has been declared as critical . This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6591 | ComfyUI up to 0.13.0 LoadImage Node folder_paths.py folder_paths.get_annotated_filepath Name path traversal

A vulnerability was found in ComfyUI up to 0.13.0 . It has been rated as critical . Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6592 | ComfyUI up to 0.13.0 userdata Endpoint app/user_manager.py getuserdata cross site scripting

A vulnerability categorized as problematic has been discovered in ComfyUI up to 0.13.0 . Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component use…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6593 | ComfyUI up to 0.13.0 View Endpoint server.py cross site scripting

A vulnerability identified as problematic has been detected in ComfyUI up to 0.13.0 . Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint . Perfor…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6594 | brikcss merge up to 1.3.0 __proto__/constructor.prototype/prototype prototype pollution

A vulnerability labeled as problematic has been found in brikcss merge up to 1.3.0 . This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6595 | ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59 HTTP GET Parameter buslocation.php bus_id sql injection

A vulnerability marked as critical has been reported in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59 . This vulnerability affects unknown code of the fil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-0868 | turn2honey EMC Plugin up to 4.4 on WordPress calendly cross site scripting

A vulnerability was found in turn2honey EMC Plugin up to 4.4 on WordPress. It has been classified as problematic . Impacted is the function calendly . Performing a manipulation results in cross site s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6576 | liangliangyy DjangoBlog up to 2.1.0.0 WeChat Bot Interface commonapi.py CommandHandler Source command injection

A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0 . It has been declared as critical . The affected element is the function CommandHandler of the file servermanager/api/commonapi.py o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6577 | liangliangyy DjangoBlog up to 2.1.0.0 logtracks Endpoint owntracks/views.py missing authentication

A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0 . It has been rated as critical . The impacted element is an unknown function of the file owntracks/views.py of the component logtrac…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6578 | liangliangyy DjangoBlog up to 2.1.0.0 Setting djangoblog/settings.py SECRET_KEY hard-coded credentials

A vulnerability categorized as critical has been discovered in liangliangyy DjangoBlog up to 2.1.0.0 . This affects an unknown function of the file djangoblog/settings.py of the component Setting Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6579 | liangliangyy DjangoBlog up to 2.1.0.0 Clean Endpoint blog/views.py missing authentication

A vulnerability identified as critical has been detected in liangliangyy DjangoBlog up to 2.1.0.0 . This impacts an unknown function of the file blog/views.py of the component Clean Endpoint . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6580 | liangliangyy DjangoBlog up to 2.1.0.0 Amap API Call owntracks/views.py key hard-coded key

A vulnerability labeled as critical has been found in liangliangyy DjangoBlog up to 2.1.0.0 . Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler . Su…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6581 | H3C Magic B1 up to 100R004 /goform/aspForm SetMobileAPInfoById param buffer overflow

A vulnerability marked as critical has been reported in H3C Magic B1 up to 100R004 . Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6582 | TransformerOptimus SuperAGI up to 0.0.14 Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authentication

A vulnerability described as critical has been identified in TransformerOptimus SuperAGI up to 0.0.14 . Affected by this issue is the function get_vector_db_details of the file superagi/controllers/ve…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6583 | TransformerOptimus SuperAGI up to 0.0.14 API Key Management Endpoint api_key.py delete_api_key/edit_api_key authorization

A vulnerability classified as problematic has been found in TransformerOptimus SuperAGI up to 0.0.14 . This affects the function delete_api_key/edit_api_key of the file superagi/controllers/api_key.py…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6584 | TransformerOptimus SuperAGI up to 0.0.14 User Update Endpoint user.py update_user user_id authorization

A vulnerability classified as problematic was found in TransformerOptimus SuperAGI up to 0.0.14 . This vulnerability affects the function update_user of the file superagi/controllers/user.py of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6585 | TransformerOptimus SuperAGI up to 0.0.14 Organisation Update Endpoint organisation.py update_organisation organisation_id authorization

A vulnerability, which was classified as problematic , has been found in TransformerOptimus SuperAGI up to 0.0.14 . This issue affects the function update_organisation of the file superagi/controllers…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6586 | TransformerOptimus SuperAGI up to 0.0.14 Budget Endpoint budget.py get_budget/update_budget authorization

A vulnerability, which was classified as critical , was found in TransformerOptimus SuperAGI up to 0.0.14 . Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6587 | vibrantlabsai RAGAS up to 0.4.3 Collections util.py _try_process_local_file/_try_process_url retrieved_contexts server-side request forgery

A vulnerability has been found in vibrantlabsai RAGAS up to 0.4.3 and classified as critical . The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metri…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
Microsoft drops its second-largest monthly batch of defects on record - CyberScoop

Microsoft drops its second-largest monthly batch of defects on record CyberScoop

CyberScoop Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CISA Warns of Chrome 0-Day Vulnerability Actively Exploited in Attacks - CyberSecurityNews

CISA Warns of Chrome 0-Day Vulnerability Actively Exploited in Attacks CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6573 | PHPEMS 11.0 Instant Exam Creation exams.master.php temppage uploadfile server-side request forgery

A vulnerability, which was classified as critical , was found in PHPEMS 11.0 . This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creati…

VulDB Read →
← Prev 83 / 248 Next →