CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6147 articles  ·  updated every 4 hours · grows forever

6147Total
4056Full Text
May 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40778 | Majestic Support Plugin up to 1.1.2 on WordPress authorization (EUVD-2026-22905)

A vulnerability classified as critical was found in Majestic Support Plugin up to 1.1.2 on WordPress. Impacted is an unknown function. The manipulation results in missing authorization. This vulnerabi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-28741 | Mattermost up to 10.11.12/11.3.2/11.4.2/11.5.0 cross-site request forgery

A vulnerability, which was classified as problematic , has been found in Mattermost up to 10.11.12/11.3.2/11.4.2/11.5.0 . The affected element is an unknown function. This manipulation causes cross-si…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4145 | Lenovo Software Fix prior 7.5.5.19 argument injection

A vulnerability, which was classified as critical , was found in Lenovo Software Fix . The impacted element is an unknown function. Such manipulation leads to argument injection. This vulnerability is…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-0827 | Lenovo Diagnostics/Vantage prior 5.26.0 link following

A vulnerability has been found in Lenovo Diagnostics and Vantage and classified as critical . This affects an unknown function. Performing a manipulation results in link following. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-25219 | Apache Airflow up to 3.1.7 Azure Service Bus access_key/connection_string information disclosure

A vulnerability was found in Apache Airflow up to 3.1.7 and classified as problematic . This impacts an unknown function of the component Azure Service Bus . Executing a manipulation of the argument a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4134 | Lenovo Software Fix prior 7.5.5.19 Installation uncontrolled search path

A vulnerability was found in Lenovo Software Fix . It has been classified as problematic . Affected is an unknown function of the component Installation Handler . The manipulation leads to uncontrolle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4135 | Lenovo Software Fix prior 7.5.5.19 link following

A vulnerability was found in Lenovo Software Fix . It has been declared as critical . Affected by this vulnerability is an unknown functionality. The manipulation results in link following. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-1636 | Lenovo Service Bridge 4/4.1.0.1/5.0.2.17 uncontrolled search path

A vulnerability was found in Lenovo Service Bridge 4/4.1.0.1/5.0.2.17 . It has been rated as problematic . Affected by this issue is some unknown functionality. This manipulation causes uncontrolled s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4682 | HP DeskJet 2800e All-in-One Printer prior 2612A Web Services for Devices Scan Request stack-based overflow

A vulnerability categorized as critical has been discovered in HP DeskJet 2800e All-in-One Printer, DeskJet 4200 All-in-One Printer, DeskJet Ink Advantage 4200 All-in-One Printer, DeskJet 4200e All-in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2024-53412 | NietThijmen ShoppingCart 0.0.2 Connect Function Port command injection

A vulnerability identified as critical has been detected in NietThijmen ShoppingCart 0.0.2 . This vulnerability affects unknown code of the component Connect Function . Performing a manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4667 | HP OMEN Gaming Hub up to 1101.2602 unnecessary privileges

A vulnerability labeled as critical has been found in HP OMEN Gaming Hub up to 1101.2602 . This issue affects some unknown processing. Executing a manipulation can lead to execution with unnecessary p…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-30364 | CentSDR e40795 Thread1 stack-based overflow

A vulnerability marked as critical has been reported in CentSDR e40795 . Impacted is the function Thread1 . The manipulation leads to stack-based buffer overflow. This vulnerability is referenced as C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
Microsoft April 2026 Patch Tuesday Fixes 168 Flaws, Includes Actively Exploited Zero-Day - cyberpress.org

Microsoft April 2026 Patch Tuesday Fixes 168 Flaws, Includes Actively Exploited Zero-Day cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
Microsoft Patch Tuesday April 2026 Fixes 168 Flaws, Including an Actively Exploited Zero-Day - gbhackers.com

Microsoft Patch Tuesday April 2026 Fixes 168 Flaws, Including an Actively Exploited Zero-Day gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
Windows Active Directory Vulnerability Allows Attackers to Execute Malicious Code - cyberpress.org

Windows Active Directory Vulnerability Allows Attackers to Execute Malicious Code cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5088 | JDEGUEST Apache::API::Password up to 0.5.2 on Perl Crypt::Urandom weak prng (EUVD-2026-22840)

A vulnerability classified as problematic has been found in JDEGUEST Apache::API::Password up to 0.5.2 on Perl. The affected element is the function Crypt::Urandom . The manipulation leads to cryptogr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-3643 | onthemapmarketing Accessibly Plugin up to 3.0.3 on WordPress REST API Endpoint update-widget-options updateWidgetOptions widgetSrc cross site scripting

A vulnerability classified as problematic was found in onthemapmarketing Accessibly Plugin up to 3.0.3 on WordPress. The impacted element is the function updateWidgetOptions of the file /otm-ac/v1/upd…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-1782 | Wpmet MetForm Pro Plugin up to 3.9.7 on WordPress Form Submission mf-calculation input validation

A vulnerability, which was classified as critical , has been found in Wpmet MetForm Pro Plugin up to 3.9.7 on WordPress. This affects an unknown function of the component Form Submission Handler . Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4002 | petjeaf Petje.af Plugin up to 2.1.8 on WordPress ajax_revoke_token cross-site request forgery

A vulnerability, which was classified as problematic , was found in petjeaf Petje.af Plugin up to 2.1.8 on WordPress. This impacts the function ajax_revoke_token . Such manipulation leads to cross-sit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5617 | royalnavneet Login as User Plugin up to 1.0.1 on WordPress handle_return_to_admin authorization (EUVD-2026-22844)

A vulnerability has been found in royalnavneet Login as User Plugin up to 1.0.1 on WordPress and classified as critical . Affected is the function handle_return_to_admin . Performing a manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-3461 | visaacceptancesolutions Visa Acceptance Solutions Plugin up to 2.1.0 on WordPress express_pay_product_page_pay_for_order billing_details authentication bypass

A vulnerability was found in visaacceptancesolutions Visa Acceptance Solutions Plugin up to 2.1.0 on WordPress and classified as critical . Affected by this vulnerability is the function express_pay_p…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-3642 | Forfront e-shot Plugin up to 1.0.2 on WordPress AJAX eshot_form_builder_update_field_data authorization

A vulnerability was found in Forfront e-shot Plugin up to 1.0.2 on WordPress. It has been classified as critical . Affected by this issue is the function eshot_form_builder_update_field_data of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-3649 | colbeinformatik Katalogportal-pdf-sync Widget Plugin up to 1.0.0 on WordPress AJAX katalogportal_popup_shortcode katalogportal_userid authorization

A vulnerability was found in colbeinformatik Katalogportal-pdf-sync Widget Plugin up to 1.0.0 on WordPress. It has been declared as problematic . This affects the function katalogportal_popup_shortcod…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-40897 | Nozomi Guardian/CMC up to 25.x Threat Intelligence authorization

A vulnerability was found in Nozomi Guardian and CMC up to 25.x . It has been rated as problematic . This vulnerability affects unknown code of the component Threat Intelligence . This manipulation ca…

VulDB Read →
← Prev 106 / 257 Next →