CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6116 articles  ·  updated every 4 hours · grows forever

6116Total
4055Full Text
May 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-24749 | SilverStripe Assets Module up to 2.4.4/3.1.2 getSourceURL authorization (GHSA-jgcf-rf45-2f8v)

A vulnerability identified as problematic has been detected in SilverStripe Assets Module up to 2.4.4/3.1.2 . The impacted element is the function DBFile::getURL/DBFile::getSourceURL . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-33082 | DataEase up to 2.10.20 exportDataset expressionTree sql injection (GHSA-xxpw-2c8q-g693)

A vulnerability labeled as critical has been found in DataEase up to 2.10.20 . This affects an unknown function of the file /de2api/datasetTree/exportDataset . The manipulation of the argument express…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-33083 | DataEase up to 2.10.20 enumValueDs Order2SQLObj sql injection (GHSA-f443-95cf-m837)

A vulnerability marked as critical has been reported in DataEase up to 2.10.20 . This impacts the function Order2SQLObj of the file /de2api/datasetData/enumValueDs . This manipulation causes sql injec…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-33084 | DataEase up to 2.10.20 DatasetDataManage Service Layer enumValueObj sort sql injection

A vulnerability described as critical has been identified in DataEase up to 2.10.20 . Affected is an unknown function of the file /de2api/datasetData/enumValueObj of the component DatasetDataManage Se…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-33121 | DataEase up to 2.10.20 API deTableName sql injection

A vulnerability classified as critical has been found in DataEase up to 2.10.20 . Affected by this vulnerability is an unknown functionality of the component API . Performing a manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-2336 | Microchip IStaX up to 2026.2 webstax_auth entropy

A vulnerability classified as problematic was found in Microchip IStaX up to 2026.2 . Affected by this issue is some unknown functionality. Executing a manipulation of the argument webstax_auth can le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2025-43935 | Dell PowerScale OneFS up to 9.12.0.0 denial of service (dsa-2025-347)

A vulnerability, which was classified as problematic , has been found in Dell PowerScale OneFS up to 9.12.0.0 . This affects an unknown part. The manipulation leads to denial of service. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
Weekly Vulnerabilities Report: AI, VMware, ICS & EV Flaws - Cyble

Weekly Vulnerabilities Report: AI, VMware, ICS & EV Flaws Cyble

Cyble Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-31843 | goodoneuz pay-uz up to 2.2.24 Endpoint update Route::any access control

A vulnerability was found in goodoneuz pay-uz up to 2.2.24 and classified as critical . The impacted element is the function Route::any of the file /payment/api/editable/update of the component Endpoi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3155 | OneSignal Plugin up to 3.8.0 on WordPress authorization (EUVD-2026-23219)

A vulnerability was found in OneSignal Plugin up to 3.8.0 on WordPress. It has been classified as problematic . This affects an unknown function. Performing a manipulation results in missing authoriza…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3489 | designinvento DirectoryPress Plugin up to 3.6.26 on WordPress packages sql injection (EUVD-2026-23223)

A vulnerability was found in designinvento DirectoryPress Plugin up to 3.6.26 on WordPress. It has been declared as critical . This impacts an unknown function. Executing a manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-6414 | fastify static up to 9.1.0 url encoding (GHSA-x428-ghpx-8j92)

A vulnerability was found in fastify static up to 9.1.0 . It has been rated as problematic . Affected is an unknown function. The manipulation leads to improper handling of url encoding. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3369 | codesolz Better Find and Replace Plugin up to 1.7.9 on WordPress Uploaded Image Title cross site scripting (EUVD-2026-23221)

A vulnerability categorized as problematic has been discovered in codesolz Better Find and Replace Plugin up to 1.7.9 on WordPress. Affected by this vulnerability is an unknown functionality of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2025-15621 | Sparx Systems Sparx Enterprise Architect up to 16.1.1627/17.1.1713 OAuth2 Credential insufficiently protected credentials (EUVD-2025-209499)

A vulnerability identified as problematic has been detected in Sparx Systems Sparx Enterprise Architect up to 16.1.1627/17.1.1713 . Affected by this issue is some unknown functionality of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-4160 | techjewel Fluent Forms Plugin 6.1.21 on WordPress AJAX Endpoint submission_id authorization

A vulnerability labeled as critical has been found in techjewel Fluent Forms Plugin 6.1.21 on WordPress. This affects an unknown part of the component AJAX Endpoint . Such manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-6410 | fastify static up to 9.1.0 Directory Listing dirList.path path traversal (GHSA-pr96-94w5-mx2h)

A vulnerability marked as critical has been reported in fastify static up to 9.1.0 . This vulnerability affects the function dirList.path of the component Directory Listing Handler . Performing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-31987 | Apache Airflow up to 3.1.x JWT Token log file (ID 62428)

A vulnerability described as problematic has been identified in Apache Airflow up to 3.1.x . This issue affects some unknown processing of the component JWT Token Handler . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-5785 | Zoho ManageEngine PAM360 Query Report sql injection

A vulnerability classified as critical has been found in Zoho ManageEngine PAM360 and ManageEngine Password Manager Pro . Impacted is an unknown function of the component Query Report Module . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-2840 | onlineoptimisation Email Encoder Plugin up to 2.4.4 on WordPress eeb_mailto cross site scripting

A vulnerability classified as problematic was found in onlineoptimisation Email Encoder Plugin up to 2.4.4 on WordPress. The affected element is the function eeb_mailto . The manipulation results in c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-33804 | fastify middie up to 9.3.1 interpretation conflict

A vulnerability, which was classified as problematic , has been found in fastify middie up to 9.3.1 . The impacted element is an unknown function. This manipulation causes interpretation conflict. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-6270 | fastify middie up to 9.3.1 interpretation conflict (GHSA-hrwm-hgmj-7p9c)

A vulnerability, which was classified as critical , was found in fastify middie up to 9.3.1 . This affects an unknown function. Such manipulation leads to interpretation conflict. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-30459 | Daylight Studio FuelCMS 1.5.2 Forgot Password Feature password recovery

A vulnerability has been found in Daylight Studio FuelCMS 1.5.2 and classified as problematic . This impacts an unknown function of the component Forgot Password Feature . Performing a manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
Microsoft Office CVE-2026-21509 Zero-Day: Emergency Patch Released to Counter Active Exploitation - Rescana

Microsoft Office CVE-2026-21509 Zero-Day: Emergency Patch Released to Counter Active Exploitation Rescana

Rescana Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More - The Hacker News

⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More The Hacker News

The Hacker News Read →
← Prev 100 / 255 Next →