CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6147 articles  ·  updated every 4 hours · grows forever

6147Total
4056Full Text
May 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-52641 | HCL AION 2.0 File information disclosure (KB0130007)

A vulnerability categorized as problematic has been discovered in HCL AION 2.0 . This issue affects some unknown processing of the component File Handler . Such manipulation leads to information discl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5694 | aerin Quick Interest Slider Plugin up to 3.1.5 on WordPress loan-amount/loan-period cross site scripting (EUVD-2026-22845)

A vulnerability identified as problematic has been detected in aerin Quick Interest Slider Plugin up to 3.1.5 on WordPress. Impacted is an unknown function. Performing a manipulation of the argument l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-3659 | bappidgreat WP Circliful Plugin up to 1.2 on WordPress Shortcode circliful_shortcode cross site scripting

A vulnerability labeled as problematic has been found in bappidgreat WP Circliful Plugin up to 1.2 on WordPress. The affected element is the function circliful_shortcode of the component Shortcode Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-3998 | webmindpt WM JqMath Plugin up to 1.3 on WordPress Shortcode generate_jqMathFormula style cross site scripting

A vulnerability marked as problematic has been reported in webmindpt WM JqMath Plugin up to 1.3 on WordPress. The impacted element is the function generate_jqMathFormula of the component Shortcode Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4011 | dgwyer Power Charts Plugin up to 0.1.0 on WordPress Shortcode pc_shortcode ID cross site scripting

A vulnerability described as problematic has been identified in dgwyer Power Charts Plugin up to 0.1.0 on WordPress. This affects the function pc_shortcode of the component Shortcode Handler . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4005 | Coachific Shortcode Plugin up to 1.0 on WordPress sanitize_text_field userhash cross site scripting

A vulnerability classified as problematic has been found in Coachific Shortcode Plugin up to 1.0 on WordPress. This impacts the function sanitize_text_field of the component Shortcode Handler . This m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-4091 | faridsaniee OPEN-BRAIN Plugin up to 0.5.0 on WordPress Setting func_page_main cross-site request forgery

A vulnerability classified as problematic was found in faridsaniee OPEN-BRAIN Plugin up to 0.5.0 on WordPress. Affected is the function func_page_main of the component Setting Handler . Such manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5717 | knighthawk VI Include Post By Plugin up to 0.4.200706 on WordPress Shortcode include-post-by-cat cross site scripting (EUVD-2026-22847)

A vulnerability, which was classified as problematic , has been found in knighthawk VI Include Post By Plugin up to 0.4.200706 on WordPress. Affected by this vulnerability is the function include-post…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-40899 | Nozomi Guardian/CMC up to 25.x Assets Page/Nodes Page cross site scripting

A vulnerability, which was classified as problematic , was found in Nozomi Guardian and CMC up to 25.x . Affected by this issue is some unknown functionality of the component Assets Page/Nodes Page . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-3505 | Legion of the Bouncy Castle BC-JAVA up to 1.83 allocation of resources

A vulnerability has been found in Legion of the Bouncy Castle BC-JAVA up to 1.83 and classified as critical . This affects an unknown part. The manipulation leads to allocation of resources. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-0636 | Legion of the Bouncy Castle BC-JAVA up to 1.83 LDAPStoreHelper.java ldap injection

A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.83 and classified as critical . This vulnerability affects unknown code of the file LDAPStoreHelper.java . The manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-14813 | Legion of the Bouncy Castle BC-JAVA up to 1.83 risky encryption

A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.83 . It has been classified as problematic . This issue affects some unknown processing. This manipulation causes risky cryptog…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5588 | Legion of the Bouncy Castle BC-JAVA up to 1.83 risky encryption

A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.83 . It has been declared as problematic . Impacted is an unknown function. Such manipulation leads to risky cryptographic algo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5598 | Legion of the Bouncy Castle BC-JAVA up to 1.83 Private Key covert timing channel

A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.83 . It has been rated as problematic . The affected element is an unknown function of the component Private Key Handler . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33808 | fastify express up to 4.0.4 interpretation conflict

A vulnerability categorized as critical has been discovered in fastify express up to 4.0.4 . The impacted element is an unknown function. Executing a manipulation can lead to interpretation conflict. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33807 | fastify express up to 4.0.4 onRegister interpretation conflict

A vulnerability identified as critical has been detected in fastify express up to 4.0.4 . This affects the function onRegister . The manipulation leads to interpretation conflict. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2024-33618 | Bosch DIVAR IP all-in-one 6000 up to 12.0.1 Network Interface resource consumption

A vulnerability labeled as problematic has been found in Bosch BVMS, BVMS Viewer, DIVAR IP all-in-one 7000 R3, DIVAR IP 7000 R2, DIVAR IP all-in-one 5000, DIVAR IP all-in-one 7000, DIVAR IP all-in-one…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
Active Exploitation of Zero-Day Vulnerability in Google Chrome - Cyber Security Agency of Singapore

Active Exploitation of Zero-Day Vulnerability in Google Chrome Cyber Security Agency of Singapore

Cyber Security Agency of Singapore Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33018 | saitoha libsixel up to 1.8.6 SIXEL Encoder load_gif use after free

A vulnerability marked as critical has been reported in saitoha libsixel up to 1.8.6 . This impacts the function load_gif of the component SIXEL Encoder . The manipulation leads to use after free. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33020 | saitoha libsixel up to 1.8.6 SIXEL Encoder sixel_frame_convert_to_rgb888 heap-based overflow

A vulnerability described as critical has been identified in saitoha libsixel up to 1.8.6 . Affected is the function sixel_frame_convert_to_rgb888 of the component SIXEL Encoder . The manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33146 | docmost up to 0.70.2 Public Search Endpoint /api/search/share-search improper authorization (GHSA-qq4c-8rjr-w42c)

A vulnerability classified as critical has been found in docmost up to 0.70.2 . Affected by this vulnerability is an unknown functionality of the file /api/search/share-search of the component Public …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-34212 | docmost up to 0.70.x cross site scripting (GHSA-cf68-cff9-hq4w)

A vulnerability classified as problematic was found in docmost up to 0.70.x . Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40091 | authzed spicedb up to 1.51.0 log file

A vulnerability, which was classified as problematic , has been found in authzed spicedb up to 1.51.0 . This affects an unknown part. Performing a manipulation results in sensitive information in log …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-54550 | Apache Airflow up to 3.1.x example_xcom code injection

A vulnerability, which was classified as critical , was found in Apache Airflow up to 3.1.x . This vulnerability affects the function example_xcom . Executing a manipulation can lead to code injection…

VulDB Read →
← Prev 107 / 257 Next →