CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5931 articles  ·  updated every 4 hours · grows forever

5931Total
4046Full Text
May 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6573 | PHPEMS 11.0 Instant Exam Creation exams.master.php temppage uploadfile server-side request forgery

A vulnerability, which was classified as critical , was found in PHPEMS 11.0 . This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-41242 | protobufjs protobuf.js up to 7.5.4/8.0.0 Type code injection (GHSA-xq3m-2v4x-88gg / EUVD-2026-23678)

A vulnerability has been found in protobufjs protobuf.js up to 7.5.4/8.0.0 and classified as critical . This vulnerability affects unknown code. This manipulation of the argument Type causes code inje…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
CVE-2026-6574 | osuuu LightPicture up to 1.2.2 API Upload Endpoint /public/install/lp.sql key hard-coded credentials

A vulnerability was found in osuuu LightPicture up to 1.2.2 and classified as critical . This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 19, 2026
Critical FortiClient EMS Vulnerability Allows Remote Malicious Code Execution - cyberpress.org

Critical FortiClient EMS Vulnerability Allows Remote Malicious Code Execution cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6559 | Wavlink WL-WN579A3 220323 /cgi-bin/login.cgi sub_401F80 Hostname cross site scripting

A vulnerability was found in Wavlink WL-WN579A3 220323 . It has been classified as problematic . This affects the function sub_401F80 of the file /cgi-bin/login.cgi . This manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6560 | H3C Magic B0 up to 100R002 /goform/aspForm Edit_BasicSSID param buffer overflow

A vulnerability was found in H3C Magic B0 up to 100R002 . It has been declared as critical . This vulnerability affects the function Edit_BasicSSID of the file /goform/aspForm . Such manipulation of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6561 | EyouCMS up to 1.7.1 Index.php edit_adminlogo filename unrestricted upload

A vulnerability was found in EyouCMS up to 1.7.1 . It has been rated as critical . This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php . Performing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6562 | dameng100 muucmf 1.9.5.20260309 /index/Search/index.html getListByPage keyword sql injection

A vulnerability categorized as critical has been discovered in dameng100 muucmf 1.9.5.20260309 . Impacted is the function getListByPage of the file /index/Search/index.html . Executing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6563 | H3C Magic B1 up to 100R004 /goform/aspForm SetAPWifiorLedInfoById param buffer overflow

A vulnerability identified as critical has been detected in H3C Magic B1 up to 100R004 . The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm . The manipulation of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6564 | EMQ EMQX Enterprise up to 6.1.0 Session Handling improper authorization

A vulnerability labeled as critical has been found in EMQ EMQX Enterprise up to 6.1.0 . The impacted element is an unknown function of the component Session Handling . The manipulation results in impr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6568 | kodcloud KodExplorer up to 4.52 Public Share share.class.php initShareOld path path traversal

A vulnerability marked as critical has been reported in kodcloud KodExplorer up to 4.52 . This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6569 | kodcloud KodExplorer up to 4.52 fileGet Endpoint share.class.php fileUrl improper authentication

A vulnerability described as critical has been identified in kodcloud KodExplorer up to 4.52 . This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet En…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6570 | kodcloud KodExplorer up to 4.52 systemMember.class.php initInstall path authorization

A vulnerability classified as problematic has been found in kodcloud KodExplorer up to 4.52 . Affected is the function initInstall of the file /app/controller/systemMember.class.php . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6571 | kodcloud KodExplorer up to 4.52 systemRole.class.php roleGroupAction group_role authorization

A vulnerability classified as critical was found in kodcloud KodExplorer up to 4.52 . Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6572 | Collabora KodExplorer up to 4.52 fileUpload Endpoint share.class.php improper authorization

A vulnerability, which was classified as critical , has been found in Collabora KodExplorer up to 4.52 . Affected by this issue is some unknown functionality of the file /app/controller/share.class.ph…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
Apache ActiveMQ CVE-2026-34197: Critical vulnerability in the KEV catalog - SecNews.gr

Apache ActiveMQ CVE-2026-34197: Critical vulnerability in the KEV catalog SecNews.gr

SecNews.gr Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-2986 | ajay Contextual Related Posts Plugin up to 4.2.1 on WordPress other_attributes cross site scripting (EUVD-2026-23674)

A vulnerability was found in ajay Contextual Related Posts Plugin up to 4.2.1 on WordPress and classified as problematic . Affected by this issue is some unknown functionality. The manipulation of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40881 | Zebra addr Message resource consumption

A vulnerability classified as problematic was found in Zebra . This affects an unknown function of the component addr Message Handler . Such manipulation leads to resource consumption. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40880 | Zebra Cached Mempool Verification comparison using wrong factors

A vulnerability, which was classified as problematic , has been found in Zebra . This impacts an unknown function of the component Cached Mempool Verification . Performing a manipulation results in co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-0894 | vanderwijk Content Blocks Plugin up to 3.3.9 on WordPress Custom Post Widget content_block cross site scripting

A vulnerability, which was classified as problematic , was found in vanderwijk Content Blocks Plugin up to 3.3.9 on WordPress. Affected is the function content_block of the component Custom Post Widge…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-2505 | elzahlan Categories Images Plugin up to 3.3.1 on WordPress Shortcode z_taxonomy_image cross site scripting

A vulnerability has been found in elzahlan Categories Images Plugin up to 3.3.1 on WordPress and classified as problematic . Affected by this vulnerability is the function z_taxonomy_image of the comp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched - The Hacker News

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40490 | AsyncHttpClient async-http-client up to 2.14.4/3.0.8 on Basic/Digest Header Authorization information disclosure (GHSA-cmxv-58fp-fm3g)

A vulnerability described as problematic has been identified in AsyncHttpClient async-http-client up to 2.14.4/3.0.8 on Basic/Digest. Affected by this vulnerability is an unknown functionality of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40492 | HappySeaFox sail XWD Codec pixmap_depth out-of-bounds write (GHSA-526v-vm72-4v64)

A vulnerability classified as critical has been found in HappySeaFox sail . Affected by this issue is the function pixmap_depth of the component XWD Codec . Performing a manipulation results in out-of…

VulDB Read →
← Prev 84 / 248 Next →