CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6154 articles  ·  updated every 4 hours · grows forever

6154Total
4058Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2025-66769 | Nitro PDF Pro 14.41.1.4 on Windows XFA null pointer dereference

A vulnerability classified as problematic was found in Nitro PDF Pro 14.41.1.4 on Windows. Affected by this issue is some unknown functionality of the component XFA Handler . Such manipulation leads t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2025-69624 | Nitro PDF Pro up to 14.41.1.4 on Windows app.alert null pointer dereference

A vulnerability, which was classified as problematic , has been found in Nitro PDF Pro up to 14.41.1.4 on Windows. This affects the function app.alert . Performing a manipulation results in null point…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-30806 | Artica Pandora FMS up to 800 os command injection

A vulnerability, which was classified as critical , was found in Artica Pandora FMS up to 800 . This vulnerability affects unknown code. Executing a manipulation can lead to os command injection. The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-36937 | SourceCodester Online Resort Management System 1.0 view_details.php sql injection

A vulnerability has been found in SourceCodester Online Resort Management System 1.0 and classified as critical . This issue affects some unknown processing of the file /orms/admin/reservations/view_d…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-36938 | SourceCodester Online Resort Management System 1.0 view_room.php sql injection

A vulnerability was found in SourceCodester Online Resort Management System 1.0 and classified as critical . Impacted is an unknown function of the file /orms/admin/rooms/view_room.php . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-6231 | MongoDB C Driver up to 1.30.4/2.0.1 bson_validate input validation

A vulnerability was found in MongoDB C Driver up to 1.30.4/2.0.1 . It has been classified as problematic . The affected element is the function bson_validate . This manipulation causes improper input …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-30813 | Artica Pandora FMS up to 800 sql injection

A vulnerability was found in Artica Pandora FMS up to 800 . It has been declared as critical . The impacted element is an unknown function. Such manipulation leads to sql injection. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-34186 | Artica Pandora FMS up to 800 Custom Fields sql injection

A vulnerability was found in Artica Pandora FMS up to 800 . It has been rated as critical . This affects an unknown function of the component Custom Fields Handler . Performing a manipulation results …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-30812 | Artica Pandora FMS up to 800 cross site scripting

A vulnerability categorized as problematic has been discovered in Artica Pandora FMS up to 800 . This impacts an unknown function. Executing a manipulation can lead to cross site scripting. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-39940 | ChurchCRM up to 6.x DonatedItemEditor.php redirect (GHSA-5g52-rvjf-6wwf)

A vulnerability identified as problematic has been detected in ChurchCRM up to 6.x . Affected is an unknown function of the file DonatedItemEditor.php . The manipulation leads to open redirect. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-36948 | SourceCodester Online Thesis Archiving System 1.0 /otas/view_archive.php sql injection

A vulnerability labeled as critical has been found in SourceCodester Online Thesis Archiving System 1.0 . Affected by this vulnerability is an unknown functionality of the file /otas/view_archive.php …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-36950 | SourceCodester Online Thesis Archiving System 1.0 projects_per_department.php sql injection

A vulnerability marked as critical has been reported in SourceCodester Online Thesis Archiving System 1.0 . Affected by this issue is some unknown functionality of the file /otas/projects_per_departme…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-36952 | SourceCodester Online Thesis Archiving System 1.0 manage_curriculum.php sql injection

A vulnerability described as critical has been identified in SourceCodester Online Thesis Archiving System 1.0 . This affects an unknown part of the file /otas/admin/curriculum/manage_curriculum.php .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-33555 | HAProxy up to 3.3.5 HTTP3 Parser length parameter

A vulnerability classified as problematic has been found in HAProxy up to 3.3.5 . This vulnerability affects unknown code of the component HTTP3 Parser . Performing a manipulation results in improper …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-23891 | Decidim up to 0.30.4/0.31.0 Name cross site scripting (GHSA-fc46-r95f-hq7g)

A vulnerability classified as problematic was found in Decidim up to 0.30.4/0.31.0 . This issue affects some unknown processing. Executing a manipulation of the argument Name can lead to cross site sc…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-40038 | Pachno 1.0.6 getParameter cross site scripting (ZSL-2026-5980)

A vulnerability, which was classified as problematic , has been found in Pachno 1.0.6 . Impacted is the function Request::getRawParameter/Request::getParameter . The manipulation of the argument value…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-40041 | Pachno 1.0.6 cross-site request forgery (ZSL-2026-5983)

A vulnerability, which was classified as problematic , was found in Pachno 1.0.6 . The affected element is an unknown function. The manipulation results in cross-site request forgery. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-40040 | Pachno 1.0.6 /uploadfile unrestricted upload (ZSL-2026-5982)

A vulnerability has been found in Pachno 1.0.6 and classified as critical . The impacted element is an unknown function of the file /uploadfile . This manipulation causes unrestricted upload. The iden…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-40039 | Pachno 1.0.6 return_to authentication bypass (ZSL-2026-5981)

A vulnerability was found in Pachno 1.0.6 and classified as problematic . This affects an unknown function. Such manipulation of the argument return_to leads to authentication bypass by primary weakne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-29955 | KubePlus 4.14 kubeconfiggenerator /registercrd subprocess.Popen chartName command injection

A vulnerability was found in KubePlus 4.14 . It has been classified as critical . This impacts the function subprocess.Popen of the file /registercrd of the component kubeconfiggenerator . Performing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-40044 | Pachno 1.0.6 deserialization (ZSL-2026-5986)

A vulnerability was found in Pachno 1.0.6 . It has been declared as critical . Affected is an unknown function. Executing a manipulation can lead to deserialization. This vulnerability is tracked as C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-32316 | jqlang jq up to 1.8.1 jvp_string_append/jvp_string_copy_replace_bad heap-based overflow (GHSA-q3h9-m34w-h76f)

A vulnerability was found in jqlang jq up to 1.8.1 . It has been rated as critical . Affected by this vulnerability is the function jvp_string_append/jvp_string_copy_replace_bad . The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2025-3756 | ABB AC800M IEC 61850 Communication Stack improper validation of specified quantity in input

A vulnerability categorized as critical has been discovered in ABB AC800M, Symphony Plus SD, Symphony Plus MR and S+ Operations . Affected by this issue is some unknown functionality of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 13, 2026
CVE-2026-31048 | Pyro 3.x Pickled privilege escalation

A vulnerability identified as problematic has been detected in Pyro 3.x . This affects an unknown part of the component Pickled Handler . This manipulation causes privilege escalation. This vulnerabil…

VulDB Read →
← Prev 115 / 257 Next →