CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6147 articles  ·  updated every 4 hours · grows forever

6147Total
4056Full Text
May 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-30995 | Slah CMS up to 1.5.0 vereador_ver.php ID sql injection

A vulnerability was found in Slah CMS up to 1.5.0 . It has been declared as critical . This impacts an unknown function of the file vereador_ver.php . The manipulation of the argument ID results in sq…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-63029 | WC Lovers WCFM Marketplace Plugin up to 3.7.1 on WordPress sql injection

A vulnerability was found in WC Lovers WCFM Marketplace Plugin up to 3.7.1 on WordPress. It has been rated as critical . Affected is an unknown function. This manipulation causes sql injection. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-6372 | Plisio Accept Cryptocurrencies with Plugin up to 2.0.5 on WordPress authorization

A vulnerability categorized as critical has been discovered in Plisio Accept Cryptocurrencies with Plugin up to 2.0.5 on WordPress. Affected by this vulnerability is an unknown functionality. Such man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-6290 | Rapid7 Velociraptor up to 0.75.7/0.76.2 query authorization

A vulnerability identified as problematic has been detected in Rapid7 Velociraptor up to 0.75.7/0.76.2 . Affected by this issue is the function Query . Performing a manipulation results in incorrect a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-15610 | OpenText RightFax up to 25.4.2.347 on Windows deserialization (KB0861863)

A vulnerability labeled as critical has been found in OpenText RightFax up to 25.4.2.347 on Windows. This affects an unknown part. Executing a manipulation can lead to deserialization. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33212 | weblate up to 5.16 Tasks API access control

A vulnerability marked as critical has been reported in weblate up to 5.16 . This vulnerability affects unknown code of the component Tasks API . The manipulation leads to improper access controls. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33214 | weblate up to 5.16 Translation Memory API /api/memory/ authorization

A vulnerability described as problematic has been identified in weblate up to 5.16 . This issue affects some unknown processing of the file /api/memory/ of the component Translation Memory API . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-3590 | Mattermost up to 10.11.12/11.3.2/11.4.2/11.5.0 toctou (EUVD-2026-22915)

A vulnerability marked as critical has been reported in Mattermost up to 10.11.12/11.3.2/11.4.2/11.5.0 . Affected is an unknown function. This manipulation causes time-of-check time-of-use. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40728 | BlockArt Magazine Blocks Plugin up to 1.8.3 on WordPress authorization

A vulnerability described as critical has been identified in BlockArt Magazine Blocks Plugin up to 1.8.3 on WordPress. Affected by this vulnerability is an unknown functionality. Such manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40742 | Nelio AB Testing Plugin up to 8.2.8 on WordPress authorization

A vulnerability classified as critical has been found in Nelio AB Testing Plugin up to 8.2.8 on WordPress. Affected by this issue is some unknown functionality. Performing a manipulation results in mi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40730 | ThemeGrill Demo Importer Plugin up to 2.0.0.6 on WordPress authorization

A vulnerability classified as critical was found in ThemeGrill Demo Importer Plugin up to 2.0.0.6 on WordPress. This affects an unknown part. Executing a manipulation can lead to missing authorization…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40740 | Themeum Tutor LMS Plugin up to 3.9.7 on WordPress authorization

A vulnerability, which was classified as critical , has been found in Themeum Tutor LMS Plugin up to 3.9.7 on WordPress. This vulnerability affects unknown code. The manipulation leads to missing auth…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40737 | VillaTheme COMPE Plugin up to 1.1.4 on WordPress authorization

A vulnerability, which was classified as critical , was found in VillaTheme COMPE Plugin up to 1.1.4 on WordPress. This issue affects some unknown processing. The manipulation results in authorization…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40744 | Beaver Builder Plugin up to 2.10.1.2 on WordPress sql injection

A vulnerability has been found in Beaver Builder Plugin up to 2.10.1.2 on WordPress and classified as critical . Impacted is an unknown function. This manipulation causes sql injection. This vulnerabi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33805 | fastify reply-from/http-proxy prior 12.6.2 Header rewriteRequestHeaders Connection http headers for scripting syntax

A vulnerability was found in fastify reply-from and http-proxy and classified as critical . The affected element is the function rewriteRequestHeaders of the component Header Handler . Such manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40729 | bPlugins 3D viewer Plugin up to 1.8.5 on WordPress authorization

A vulnerability was found in bPlugins 3D viewer Plugin up to 1.8.5 on WordPress. It has been classified as critical . The impacted element is an unknown function. Performing a manipulation results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40745 | bdthemes Element Pack Elementor Addons Plugin up to 8.4.2 on WordPress sql injection

A vulnerability was found in bdthemes Element Pack Elementor Addons Plugin up to 8.4.2 on WordPress. It has been declared as critical . This affects an unknown function. Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40786 | Long Watch Studio MyRewards Plugin up to 5.7.3 on WordPress authorization (EUVD-2026-22910)

A vulnerability was found in Long Watch Studio MyRewards Plugin up to 5.7.3 on WordPress. It has been rated as critical . This impacts an unknown function. The manipulation leads to missing authorizat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40784 | Mahmudul Hasan Arif FluentBoards Plugin up to 1.91.2 on WordPress authorization

A vulnerability categorized as critical has been discovered in Mahmudul Hasan Arif FluentBoards Plugin up to 1.91.2 on WordPress. Affected is an unknown function. The manipulation results in authoriza…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40763 | WP Royal Royal Elementor Addons Plugin up to 1.7.1056 on WordPress authorization (EUVD-2026-22902)

A vulnerability identified as critical has been detected in WP Royal Royal Elementor Addons Plugin up to 1.7.1056 on WordPress. Affected by this vulnerability is an unknown functionality. This manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40734 | Zahlan Categories Images Plugin up to 3.3.1 on WordPress cross site scripting

A vulnerability labeled as problematic has been found in Zahlan Categories Images Plugin up to 3.3.1 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to cros…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-1852 | WooBeWoo Product Pricing Table Plugin up to 1.1.0 on WordPress updateLabel cross-site request forgery (EUVD-2026-22911)

A vulnerability marked as problematic has been reported in WooBeWoo Product Pricing Table Plugin up to 1.1.0 on WordPress. This affects the function updateLabel . Performing a manipulation results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-27769 | Mattermost up to 10.11.12/11.4.x Conntexted Workspaces Feature authorization

A vulnerability described as problematic has been identified in Mattermost up to 10.11.12/11.4.x . This vulnerability affects unknown code of the component Conntexted Workspaces Feature . Executing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40764 | Syed Balkhi Contact Form by WPForms Plugin up to 1.10.0.2 on WordPress cross-site request forgery (EUVD-2026-22903)

A vulnerability classified as problematic has been found in Syed Balkhi Contact Form by WPForms Plugin up to 1.10.0.2 on WordPress. This issue affects some unknown processing. The manipulation leads t…

VulDB Read →
← Prev 105 / 257 Next →