CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6154 articles  ·  updated every 4 hours · grows forever

6154Total
4058Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-4388 | 10web Form Maker Plugin up to 1.15.40 on WordPress sanitize_text_field Matrix cross site scripting

A vulnerability, which was classified as problematic , was found in 10web Form Maker Plugin up to 1.15.40 on WordPress. This affects the function sanitize_text_field . The manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-0512 | SAP Supplier Relationship Management 713/714/SRM_SERVER 702 SICF cross site scripting

A vulnerability has been found in SAP Supplier Relationship Management 713/714/SRM_SERVER 702 and classified as problematic . This vulnerability affects unknown code of the component SICF Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-34262 | SAP HANA Cockpit/HANA Database Explorer SAP_HANA_COCKPIT 2.0 insufficiently protected credentials

A vulnerability was found in SAP HANA Cockpit and HANA Database Explorer SAP_HANA_COCKPIT 2.0 and classified as problematic . This issue affects some unknown processing. Such manipulation leads to ins…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-39425 | 1Panel-dev MaxKB up to 2.7.x Chatbot Interface /admin/api/workspace/ prologue cross site scripting (GHSA-3rq5-pgm7-pvp4)

A vulnerability was found in 1Panel-dev MaxKB up to 2.7.x . It has been classified as problematic . Impacted is an unknown function of the file /admin/api/workspace/ of the component Chatbot Interface…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-39426 | 1Panel-dev MaxKB up to 2.7.x cross site scripting (GHSA-q2qg-43vq-f2wv)

A vulnerability was found in 1Panel-dev MaxKB up to 2.7.x . It has been declared as problematic . The affected element is an unknown function. Executing a manipulation can lead to cross site scripting…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2025-70936 | vTiger CRM 8.4.0 MailManager _folder cross site scripting

A vulnerability was found in vTiger CRM 8.4.0 . It has been rated as problematic . The impacted element is an unknown function of the component MailManager Module . The manipulation of the argument _f…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-39423 | 1Panel-dev MaxKB up to 2.7.x AI Chat Interface cross site scripting (GHSA-462x-99gf-mp79)

A vulnerability categorized as problematic has been discovered in 1Panel-dev MaxKB up to 2.7.x . This affects an unknown function of the component AI Chat Interface . The manipulation results in cross…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-39422 | 1Panel-dev MaxKB up to 2.7.x Public Chat Interface /ui/chat/ name/icon cross site scripting (GHSA-wf7p-3jq5-q52w)

A vulnerability identified as problematic has been detected in 1Panel-dev MaxKB up to 2.7.x . This impacts an unknown function of the file /ui/chat/ of the component Public Chat Interface . This manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-2582 | vendidero Germanized for WooCommerce Plugin up to 3.20.5 on WordPress Shortcode account_holder code injection

A vulnerability labeled as critical has been found in vendidero Germanized for WooCommerce Plugin up to 3.20.5 on WordPress. Affected is an unknown function of the component Shortcode Handler . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-31908 | Apache APISIX up to 3.15.0 Forward Auth Plugin injection

A vulnerability marked as critical has been reported in Apache APISIX up to 3.15.0 . Affected by this vulnerability is an unknown functionality of the component Forward Auth Plugin . Performing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-31923 | Apache APISIX up to 3.14.x Openid-connect tls_verify cleartext transmission

A vulnerability described as problematic has been identified in Apache APISIX up to 3.14.x . Affected by this issue is some unknown functionality of the component Openid-connect . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-31924 | Apache APISIX up to 3.14.x tencent-cloud-cls cleartext transmission

A vulnerability classified as problematic has been found in Apache APISIX up to 3.14.x . This affects an unknown part of the component tencent-cloud-cls . The manipulation leads to cleartext transmiss…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-33929 | Apache PDFBox Examples up to 2.0.36/3.0.7 ExtractEmbeddedFiles path traversal

A vulnerability classified as critical was found in Apache PDFBox Examples up to 2.0.36/3.0.7 . This vulnerability affects unknown code of the component ExtractEmbeddedFiles . The manipulation results…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-39984 | sigstore timestamp-authority up to 2.0.5 certificate validation

A vulnerability, which was classified as critical , has been found in sigstore timestamp-authority up to 2.0.5 . This issue affects some unknown processing. This manipulation causes improper certifica…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day - CyberScoop

Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day CyberScoop

CyberScoop Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-33534 | EspoCRM up to 9.3.3 fromImageUrl isNotInternalHost server-side request forgery

A vulnerability, which was classified as critical , has been found in EspoCRM up to 9.3.3 . This affects the function HostCheck::isNotInternalHost of the file /api/v1/Attachment/fromImageUrl . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-33657 | EspoCRM up to 9.3.3 post cross site scripting

A vulnerability, which was classified as problematic , was found in EspoCRM up to 9.3.3 . This impacts an unknown function. Such manipulation of the argument post leads to basic cross site scripting. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-32270 | Craft CMS up to 4.10.2/5.5.4 actionPay email/shipping address/billing address information disclosure (GHSA-3vxg-x5f8-f5qf)

A vulnerability has been found in Craft CMS up to 4.10.2/5.5.4 and classified as problematic . Affected is the function actionPay . Performing a manipulation of the argument email/shipping address/bil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-32271 | Craft CMS up to 4.10.2/5.5.4 Commerce TotalRevenue Widget unserialize sql injection

A vulnerability was found in Craft CMS up to 4.10.2/5.5.4 and classified as critical . Affected by this vulnerability is the function unserialize of the component Commerce TotalRevenue Widget . Execut…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-33659 | EspoCRM up to 9.3.3 fromImageUrl dns_get_record server-side request forgery

A vulnerability was found in EspoCRM up to 9.3.3 . It has been classified as critical . Affected by this issue is the function dns_get_record of the file /api/v1/Attachment/fromImageUrl . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2025-51414 | PHPGurukul Online Course Registration 3.1 Profile Picture Upload /my-profile.php unrestricted upload

A vulnerability was found in PHPGurukul Online Course Registration 3.1 . It has been declared as critical . This affects an unknown part of the file /my-profile.php of the component Profile Picture Up…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-32272 | Craft CMS up to 5.5.4/5.6.0 Craft::configure sql injection

A vulnerability was found in Craft CMS up to 5.5.4/5.6.0 . It has been rated as critical . This vulnerability affects the function Craft::configure . This manipulation causes sql injection. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 14, 2026
CVE-2026-31280 | Parani M10 Motorcycle Intercom 2.1.3 Bluetooth RFCOMM Service denial of service (EUVD-2026-22071)

A vulnerability categorized as problematic has been discovered in Parani M10 Motorcycle Intercom 2.1.3 . This issue affects some unknown processing of the component Bluetooth RFCOMM Service . Such man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-30811 | Artica Pandora FMS up to 800 Configuration Endpoint default permission

A vulnerability classified as critical has been found in Artica Pandora FMS up to 800 . Affected by this vulnerability is an unknown functionality of the component Configuration Endpoint . This manipu…

VulDB Read →
← Prev 114 / 257 Next →