Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Security Intel Hub 23479+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
NocoBase plugin-workflow-javascript Sandbox Escape Vulnerability (CVE-2026-6224)
vuldb.com · 2026-04-18

### Vulnerability Overview - **Vulnerability Name**: nocobase plugin-workflow-javascript up to 2.0.23 Vm.js createSafeConsole sandbox - **Vulnerability ID**: CVE-2026-6224 - **CVSS Score**: 6.6 - **Vu…

Read more
MobaXterm 26.1 Uncontrolled Search Path Vulnerability (CVE-2026-6421)
vuldb.com · 2026-04-18

### Vulnerability Overview - **Vulnerability Name**: Uncontrolled Search Path in MobaXterm Home Edition 26.1 - **Vulnerability ID**: VDB-358020, CVE-2026-6421, GCVE-100-358020 - **CVSSv3 Score**: 7.0 …

Read more
Wavlink WL-WN530H4 OS Command Injection Vulnerability (CVE-2026-6483) Advisory
vuldb.com · 2026-04-18

### Vulnerability Overview - **Vulnerability Name**: Wavlink WL-WN530H4 20220721 /cgi-bin/internet.cgi strcat/sprintf OS command injection - **Vulnerability Type**: OS Command Injection - **Severity**…

Read more
arnob78 Hotel Booking Management System Information Disclosure (CVE-2026-6492)
vuldb.com · 2026-04-18

### Vulnerability Overview - **Vulnerability Name**: arnob78 Hotel Booking Management System Information Disclosure Vulnerability - **CVE ID**: CVE-2026-6492 - **CVSS Score**: 4.7 (CVSS v3) - **Vulner…

Read more
SQL Injection in QueryMine sms 1.0 admin/deletecourse.php (CVE-2026-6490)
vuldb.com · 2026-04-18

### Vulnerability Overview - **Vulnerability Name**: QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593 GET Request Parameter admin/deletecourse.php ID sql injection - **Vulnerability Type**…

Read more
classroombookings Reflected XSS in layout.php (CVE-2026-6486) and Patch
vuldb.com · 2026-04-18

# Vulnerability Overview - **Vulnerability Name**: classroombookings up to 2.17.0 User Display Name layout.php read displayname cross site scripting - **Vulnerability Type**: Cross-Site Scripting (XSS…

Read more
lukevella rally <4.8.0 Reset Password DOM-Based XSS via redirectTo (CVE-2026-6493)
vuldb.com · 2026-04-18

### Vulnerability Overview - **Vulnerability Name**: lukevella rally up to 4.7.4 Reset Password reset-password-form.tsx redirectTo cross site scripting - **Vulnerability Description**: An issue was di…

Read more
SQL Injection in QueryMine sms admin/editcourse.php (CVE-2026-6488)
vuldb.com · 2026-04-18

### Vulnerability Overview - **Vulnerability Name**: QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593 GET Request Parameter admin/editcourse.php ID sql injection - **Vulnerability Type**: …

Read more
Alibaba Cloud ECS IMDS Unauthorized Access Vulnerability and POC
www.aveva.com · 2026-04-18

# Vulnerability Overview **Vulnerability Name**: Unauthorized Access Vulnerability in Alibaba Cloud ECS Instance Metadata Service (IMDS) **Vulnerability Description**: The metadata service (IMDS) of A…

Read more
Unauthenticated SQLi in WooCommerce Product Filter < 31.3 (CVE-2026-3830)
wpscan.com · 2026-04-18

# Vulnerability Summary: Product Filter for WooCommerce by WBW < 31.3 - Unauthenticated SQLi ## Vulnerability Overview * **Vulnerability Type**: Unauthenticated SQL Injection (Unauthenticated SQLi) * …

Read more
CISA Advisory ICSA-26-106-03: Anviz Multiple Products Vulnerabilities Summary
www.cisa.gov · 2026-04-18

# Anviz Multiple Product Vulnerability Summary ## Vulnerability Overview * **Release Date**: April 16, 2026 * **Alert Code**: ICSA-26-106-03 * **CVSS Score**: 9.8 (Critical) * **Risk Description**: Su…

Read more
WordPress Form Maker SQL Injection Vulnerability (CVE-2025-15441) with POC
wpscan.com · 2026-04-18

# WordPress Plugin Form Maker SQL Injection Vulnerability Summary ## Vulnerability Overview - **Vulnerability Name**: Form Maker Forms > Form Options > MySQL Mapping. - Create a query targeting any ta…

Read more
Vision Helpdesk Serialized IDOR and Session Prediction Vulnerability Analysis
websec.net · 2026-04-18

# Vulnerability Summary: Vision Helpdesk Critical Vulnerabilities ## Overview * **Vulnerability Name**: Serialized IDOR and Session Prediction * **Affected Software**: Vision Helpdesk * **Vulnerabilit…

Read more
Adianti Framework 5.5.0/5.6.0 SQL Injection Vulnerability with POC
www.exploit-db.com · 2026-04-18

# Adianti Framework 5.5.0 - SQL Injection Vulnerability ## Vulnerability Overview - **Vulnerability Type**: SQL Injection - **EDB-ID**: 46217 - **Release Date**: 2019-01-21 - **Author**: Joner de Mell…

Read more
SpotFTP Password Recover 2.4.2 'Name' Field Denial of Service Vulnerability (PoC)
www.exploit-db.com · 2026-04-18

# SpotFTP Password Recover 2.4.2 - 'Name' Denial of Service Vulnerability (PoC) ## Vulnerability Overview - **EDB-ID**: 46088 - **Author**: Luis Martinez - **Release Date**: 2019-01-07 - **Vulnerabili…

Read more
R 3.4.4 Local Buffer Overflow Exploit POC (Windows XP SP3)
www.exploit-db.com · 2026-04-18

# R 3.4.4 XP SP3 - Buffer Overflow (Non SEH) ## Vulnerability Overview - **EDB-ID**: 46265 - **Author**: Dino Covotos - **Type**: LOCAL - **Platform**: WINDOWS - **Date**: 2019-01-28 - **Vulnerability…

Read more
BlueAuditor 1.7.2.0 'Key' Local Denial of Service Vulnerability PoC
www.exploit-db.com · 2026-04-18

# BlueAuditor 1.7.2.0 'Key' Denial of Service Vulnerability (PoC) ## Vulnerability Overview - **EDB-ID**: 46087 - **Author**: Luis Martinez - **Release Date**: 2019-01-07 - **Platform**: Windows - **V…

Read more
RGui 3.5.0 Local Buffer Overflow Exploit (SEH/DEP Bypass)
www.exploit-db.com · 2026-04-18

# RGui 3.5.0 - Local Buffer Overflow Vulnerability (SEH/DEP Bypass) ## Vulnerability Overview * **Vulnerability Title**: RGui 3.5.0 - Local Buffer Overflow (SEH)(DEP Bypass) * **EDB-ID**: 46107 * **Au…

Read more
CF Image Hosting Script 1.6.5 Unauthenticated Data Deletion via Insecure Direct Object Reference
www.exploit-db.com · 2026-04-18

# CF Image Hosting Script 1.6.5 Vulnerability Summary ## Vulnerability Overview - **Vulnerability Title**: CF Image Hosting Script 1.6.5 - (Delete all Pictures) Privilege Escalation - **EDB-ID**: 4609…

Read more
Newsbull Haber Script 1.0.0 SQL Injection Vulnerability and POC
www.exploit-db.com · 2026-04-18

# Newsbull Haber Script 1.0.0 SQL Injection Vulnerability ## Vulnerability Overview Newsbull Haber Script 1.0.0 contains a SQL injection vulnerability, which allows attackers to obtain database inform…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.