CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6147 articles  ·  updated every 4 hours · grows forever

6147Total
4056Full Text
May 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-5491 | DriveLock path traversal

A vulnerability classified as critical has been found in DriveLock . The impacted element is an unknown function. The manipulation leads to path traversal. This vulnerability is documented as CVE-2026…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-5492 | DriveLock path traversal

A vulnerability classified as critical was found in DriveLock . This affects an unknown function. The manipulation results in path traversal. This vulnerability is reported as CVE-2026-5492 . The atta…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3581 | iandunn Basic Google Maps Placemarks Plugin up to 1.10.7 on WordPress authorization (EUVD-2026-23180)

A vulnerability, which was classified as critical , has been found in iandunn Basic Google Maps Placemarks Plugin up to 1.10.7 on WordPress. This impacts an unknown function. This manipulation causes …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3861 | LINE Client up to 26.2.x on iOS Web denial of service

A vulnerability, which was classified as problematic , was found in LINE Client up to 26.2.x on iOS. Affected is an unknown function of the component Web Handler . Such manipulation leads to denial of…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-5050 | jconti Payment Gateway for Redsys & WooCommerce Lite Plugin successful_request signature verification

A vulnerability has been found in jconti Payment Gateway for Redsys & WooCommerce Lite Plugin up to 7.0.0 on WordPress and classified as critical . Affected by this vulnerability is the function succe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3595 | imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress REST API delete_customer inkxe_delete_customer authorization

A vulnerability was found in imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress and classified as critical . Affected by this issue is the function inkxe_delete_customer of the file …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3596 | imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress ink_pd_add_option opt_value authorization

A vulnerability was found in imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress. It has been classified as critical . This affects the function ink_pd_add_option . The manipulation o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3773 | onlineada Accessibility Suite by Ability Plugin up to 4.20 on WordPress scan_id sql injection

A vulnerability was found in onlineada Accessibility Suite by Ability Plugin up to 4.20 on WordPress. It has been declared as critical . This vulnerability affects unknown code. The manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3599 | imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress REST API Endpoint add-item-to-cart product_data options sql injection

A vulnerability was found in imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress. It has been rated as critical . This issue affects the function product_data of the file /wp-json/Ink…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-22617 | Eaton IPP Software up to 1.x Configuration missing secure attribute

A vulnerability categorized as problematic has been discovered in Eaton IPP Software up to 1.x . Impacted is an unknown function of the component Configuration Handler . Such manipulation leads to sen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-22618 | Eaton IPP Software up to 1.x HTTP Response Header security check

A vulnerability identified as problematic has been detected in Eaton IPP Software up to 1.x . The affected element is an unknown function of the component HTTP Response Header Handler . Performing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-22619 | Eaton IPP Software up to 1.x uncontrolled search path

A vulnerability labeled as problematic has been found in Eaton IPP Software up to 1.x . The impacted element is an unknown function. Executing a manipulation can lead to uncontrolled search path. This…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3355 | ivole Customer Reviews for WooCommerce Plugin up to 5.101.0 on WordPress cross site scripting

A vulnerability marked as problematic has been reported in ivole Customer Reviews for WooCommerce Plugin up to 5.101.0 on WordPress. This affects an unknown function. The manipulation leads to cross s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2025-13364 | flippercode WP Maps Plugin up to 4.8.7 on WordPress Shortcode put_wpgm cross site scripting

A vulnerability described as problematic has been identified in flippercode WP Maps Plugin up to 4.8.7 on WordPress. This impacts the function put_wpgm of the component Shortcode Handler . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3876 | specialk Prismatic Plugin up to 3.7.3 on WordPress Shortcode prismatic_decode cross site scripting

A vulnerability classified as problematic has been found in specialk Prismatic Plugin up to 3.7.3 on WordPress. Affected is the function prismatic_decode of the component Shortcode Handler . This mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-41035 | Samba rsync up to 3.4.1 Qsort Call receive_xattr length length parameter

A vulnerability classified as critical was found in Samba rsync up to 3.4.1 . Affected by this vulnerability is the function receive_xattr of the component Qsort Call Handler . Such manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3551 | rafasashi Custom New User Notification Plugin up to 1.2.0 on WordPress register_setting cross site scripting

A vulnerability, which was classified as problematic , has been found in rafasashi Custom New User Notification Plugin up to 1.2.0 on WordPress. Affected by this issue is the function register_setting…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3614 | acyba AcyMailing Plugin up to 10.8.1 on WordPress AJAX wp_ajax_acymailing_router authorization

A vulnerability, which was classified as critical , was found in acyba AcyMailing Plugin up to 10.8.1 on WordPress. This affects the function wp_ajax_acymailing_router of the component AJAX Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-41034 | Ascensio ONLYOFFICE DocumentServer up to 9.2.x XLS pictFmla.cbBufInCtlStm out-of-bounds

A vulnerability has been found in Ascensio ONLYOFFICE DocumentServer up to 9.2.x and classified as problematic . This vulnerability affects the function pictFmla.cbBufInCtlStm of the component XLS Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-1572 | livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress AJAX lae_admin_ajax cross site scripting

A vulnerability was found in livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress and classified as problematic . This issue affects the function lae_admin_ajax of the component AJAX Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-1620 | Livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress Template Name lae_get_template_part filename control

A vulnerability was found in Livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress. It has been classified as critical . Impacted is the function lae_get_template_part of the component T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3875 | wpdevteam BetterDocs Plugin up to 4.3.8 on WordPress Shortcode betterdocs_feedback_form cross site scripting

A vulnerability was found in wpdevteam BetterDocs Plugin up to 4.3.8 on WordPress. It has been declared as problematic . The affected element is the function betterdocs_feedback_form of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-3995 | faridsaniee OPEN-BRAIN Plugin up to 0.5.0 on WordPress Setting sanitize_text_field API key cross site scripting

A vulnerability was found in faridsaniee OPEN-BRAIN Plugin up to 0.5.0 on WordPress. It has been rated as problematic . The impacted element is the function sanitize_text_field of the component Settin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 16, 2026
CVE-2026-41030 | Ascensio ONLYOFFICE DesktopEditors up to 9.2.x Update Service resource transfer

A vulnerability categorized as problematic has been discovered in Ascensio ONLYOFFICE DesktopEditors up to 9.2.x . This affects an unknown function of the component Update Service . Executing a manipu…

VulDB Read →
← Prev 103 / 257 Next →