CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6116 articles  ·  updated every 4 hours · grows forever

6116Total
4055Full Text
May 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3773 | onlineada Accessibility Suite by Ability Plugin up to 4.20 on WordPress scan_id sql injection

A vulnerability was found in onlineada Accessibility Suite by Ability Plugin up to 4.20 on WordPress. It has been declared as critical . This vulnerability affects unknown code. The manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3599 | imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress REST API Endpoint add-item-to-cart product_data options sql injection

A vulnerability was found in imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress. It has been rated as critical . This issue affects the function product_data of the file /wp-json/Ink…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-22617 | Eaton IPP Software up to 1.x Configuration missing secure attribute

A vulnerability categorized as problematic has been discovered in Eaton IPP Software up to 1.x . Impacted is an unknown function of the component Configuration Handler . Such manipulation leads to sen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-22618 | Eaton IPP Software up to 1.x HTTP Response Header security check

A vulnerability identified as problematic has been detected in Eaton IPP Software up to 1.x . The affected element is an unknown function of the component HTTP Response Header Handler . Performing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-22619 | Eaton IPP Software up to 1.x uncontrolled search path

A vulnerability labeled as problematic has been found in Eaton IPP Software up to 1.x . The impacted element is an unknown function. Executing a manipulation can lead to uncontrolled search path. This…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3355 | ivole Customer Reviews for WooCommerce Plugin up to 5.101.0 on WordPress cross site scripting

A vulnerability marked as problematic has been reported in ivole Customer Reviews for WooCommerce Plugin up to 5.101.0 on WordPress. This affects an unknown function. The manipulation leads to cross s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2025-13364 | flippercode WP Maps Plugin up to 4.8.7 on WordPress Shortcode put_wpgm cross site scripting

A vulnerability described as problematic has been identified in flippercode WP Maps Plugin up to 4.8.7 on WordPress. This impacts the function put_wpgm of the component Shortcode Handler . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3876 | specialk Prismatic Plugin up to 3.7.3 on WordPress Shortcode prismatic_decode cross site scripting

A vulnerability classified as problematic has been found in specialk Prismatic Plugin up to 3.7.3 on WordPress. Affected is the function prismatic_decode of the component Shortcode Handler . This mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-41035 | Samba rsync up to 3.4.1 Qsort Call receive_xattr length length parameter

A vulnerability classified as critical was found in Samba rsync up to 3.4.1 . Affected by this vulnerability is the function receive_xattr of the component Qsort Call Handler . Such manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3551 | rafasashi Custom New User Notification Plugin up to 1.2.0 on WordPress register_setting cross site scripting

A vulnerability, which was classified as problematic , has been found in rafasashi Custom New User Notification Plugin up to 1.2.0 on WordPress. Affected by this issue is the function register_setting…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3614 | acyba AcyMailing Plugin up to 10.8.1 on WordPress AJAX wp_ajax_acymailing_router authorization

A vulnerability, which was classified as critical , was found in acyba AcyMailing Plugin up to 10.8.1 on WordPress. This affects the function wp_ajax_acymailing_router of the component AJAX Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-41034 | Ascensio ONLYOFFICE DocumentServer up to 9.2.x XLS pictFmla.cbBufInCtlStm out-of-bounds

A vulnerability has been found in Ascensio ONLYOFFICE DocumentServer up to 9.2.x and classified as problematic . This vulnerability affects the function pictFmla.cbBufInCtlStm of the component XLS Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-1572 | livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress AJAX lae_admin_ajax cross site scripting

A vulnerability was found in livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress and classified as problematic . This issue affects the function lae_admin_ajax of the component AJAX Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-1620 | Livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress Template Name lae_get_template_part filename control

A vulnerability was found in Livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress. It has been classified as critical . Impacted is the function lae_get_template_part of the component T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3875 | wpdevteam BetterDocs Plugin up to 4.3.8 on WordPress Shortcode betterdocs_feedback_form cross site scripting

A vulnerability was found in wpdevteam BetterDocs Plugin up to 4.3.8 on WordPress. It has been declared as problematic . The affected element is the function betterdocs_feedback_form of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3995 | faridsaniee OPEN-BRAIN Plugin up to 0.5.0 on WordPress Setting sanitize_text_field API key cross site scripting

A vulnerability was found in faridsaniee OPEN-BRAIN Plugin up to 0.5.0 on WordPress. It has been rated as problematic . The impacted element is the function sanitize_text_field of the component Settin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-41030 | Ascensio ONLYOFFICE DesktopEditors up to 9.2.x Update Service resource transfer

A vulnerability categorized as problematic has been discovered in Ascensio ONLYOFFICE DesktopEditors up to 9.2.x . This affects an unknown function of the component Update Service . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
NAVTOR patches critical NavBox flaws after Cydome disclosure - Splash247

NAVTOR patches critical NavBox flaws after Cydome disclosure Splash247

Splash247 Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-53444 | DeluxeThemes Userpro Plugin up to 5.1.10 on WordPress cross-site request forgery

A vulnerability marked as problematic has been reported in DeluxeThemes Userpro Plugin up to 5.1.10 on WordPress. This affects an unknown function. This manipulation causes cross-site request forgery.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-20147 | Cisco Identity Services Engine Software command injection (cisco-sa-ise-rce-traversal-8bYndVrZ)

A vulnerability described as critical has been identified in Cisco Identity Services Engine Software and ISE Passive Identity Connector . This impacts an unknown function. Such manipulation leads to c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-20180 | Cisco Identity Services Engine Software up to 3.5.0 path traversal (cisco-sa-ise-rce-4fverepv)

A vulnerability classified as critical has been found in Cisco Identity Services Engine Software . Affected is an unknown function. Performing a manipulation results in path traversal. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-20186 | Cisco Identity Services Engine Software up to 3.4.0 command injection (cisco-sa-ise-rce-4fverepv)

A vulnerability classified as critical was found in Cisco Identity Services Engine Software . Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to command i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-20148 | Cisco Identity Services Engine Software HTTP path traversal (cisco-sa-ise-rce-traversal-8bYndVrZ)

A vulnerability, which was classified as critical , has been found in Cisco Identity Services Engine Software and ISE Passive Identity Connector . Affected by this issue is some unknown functionality …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-20152 | Cisco Secure Web Appliance up to 15.2.5-013 Authentication Service authentication bypass (cisco-sa-wsa-auth-bypass-6YZkTQhd)

A vulnerability, which was classified as problematic , was found in Cisco Secure Web Appliance . This affects an unknown part of the component Authentication Service . The manipulation results in auth…

VulDB Read →
← Prev 102 / 255 Next →