CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6225 articles  ·  updated every 4 hours · grows forever

6225Total
4060Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5207 | chrisbadgett LifterLMS Plugin up to 9.2.1 on WordPress edit_post order sql injection

A vulnerability marked as critical has been reported in chrisbadgett LifterLMS Plugin up to 9.2.1 on WordPress. Impacted is the function edit_post . Performing a manipulation of the argument order res…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40198 | STIGTSP Net::CIDR::Lite up to 0.22 on Perl _pack_ipv6 improper validation of syntactic correctness of input

A vulnerability described as critical has been identified in STIGTSP Net::CIDR::Lite up to 0.22 on Perl. The affected element is the function _pack_ipv6 . Executing a manipulation can lead to improper…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40199 | STIGTSP Net::CIDR::Lite up to 0.22 on Perl IPv6 Address _pack_ipv6 length parameter

A vulnerability classified as critical has been found in STIGTSP Net::CIDR::Lite up to 0.22 on Perl. The impacted element is the function _pack_ipv6 of the component IPv6 Address Handler . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-3498 | wpblockart BlockArt Blocks Plugin up to 2.2.15 on WordPress Block Attribute cross site scripting

A vulnerability classified as problematic was found in wpblockart BlockArt Blocks Plugin up to 2.2.15 on WordPress. This affects an unknown function of the component Block Attribute Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5226 | Optimole Plugin up to 4.2.3 on WordPress get_current_url cross site scripting

A vulnerability, which was classified as problematic , has been found in Optimole Plugin up to 4.2.3 on WordPress. This impacts the function get_current_url . This manipulation causes cross site scrip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40354 | Flatpak xdg-desktop-portal up to 1.20.3/1.21.0 g_file_trash symlink (GHSA-rqr9-jwwf-wxgj)

A vulnerability, which was classified as critical , was found in Flatpak xdg-desktop-portal up to 1.20.3/1.21.0 . Affected is the function g_file_trash . Such manipulation leads to symlink following. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
Ingress-NGINX Flaw Enables Arbitrary Code Execution Attacks - gbhackers.com

Ingress-NGINX Flaw Enables Arbitrary Code Execution Attacks gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
Android Security Update Fixes 129 Vulnerabilities, Including Actively Exploited Zero-Day - cyberpress.org

Android Security Update Fixes 129 Vulnerabilities, Including Actively Exploited Zero-Day cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33704 | Chamilo LMS up to 1.11.37 BigUpload Endpoint unrestricted upload (GHSA-phfx-pwwg-945v)

A vulnerability has been found in Chamilo LMS up to 1.11.37 and classified as critical . This affects an unknown part of the component BigUpload Endpoint . Performing a manipulation results in unrestr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40175 | Axios up to 1.14.x response splitting

A vulnerability was found in Axios up to 1.14.x and classified as critical . This vulnerability affects unknown code. Executing a manipulation can lead to http response splitting. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40188 | patrickhener goshs up to 1.0.6/2.0.0-beta.3 missing write protection for parametric data values (GHSA-2943-crp8-38xx)

A vulnerability was found in patrickhener goshs up to 1.0.6/2.0.0-beta.3 . It has been classified as problematic . This issue affects some unknown processing. The manipulation leads to missing write p…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33707 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 Password Reset email password recovery (GHSA-f27g-66gq-g7v2)

A vulnerability was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . It has been declared as problematic . Impacted is an unknown function of the component Password Reset Handler . The manipulation of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33710 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 time random values (GHSA-rpmg-j327-mr39)

A vulnerability was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . It has been rated as problematic . The affected element is the function Time . This manipulation causes insufficiently random values…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-32252 | Chartbrew up to 4.8.x :project_id improper authorization (GHSA-mw4f-cf22-qpcj)

A vulnerability categorized as critical has been discovered in Chartbrew up to 4.8.x . The impacted element is an unknown function of the file /team/:team_id/template/generate/:project_id . Such manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40168 | gitroomhq postiz-app up to 2.21.4 /api/public/stream server-side request forgery

A vulnerability identified as critical has been detected in gitroomhq postiz-app up to 2.21.4 . This affects an unknown function of the file /api/public/stream . Performing a manipulation results in s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40189 | patrickhener goshs up to 2.0.0-beta.3 ACL/basic-auth authorization (GHSA-wvhv-qcqf-f3cx)

A vulnerability labeled as critical has been found in patrickhener goshs up to 2.0.0-beta.3 . This impacts an unknown function of the file ACL/basic-auth . Executing a manipulation can lead to missing…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40190 | langchain-ai langsmith-sdk up to 0.5.17 set prototype pollution

A vulnerability marked as problematic has been reported in langchain-ai langsmith-sdk up to 0.5.17 . Affected is the function Set . The manipulation leads to improperly controlled modification of obje…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-27460 | TandoorRecipes recipes up to 2.6.4 ZIP File Parser data amplification (GHSA-w8pq-4pwf-r2m8)

A vulnerability described as problematic has been identified in TandoorRecipes recipes up to 2.6.4 . Affected by this vulnerability is an unknown functionality of the component ZIP File Parser . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33706 | Chamilo LMS up to 1.11.37 update_user_from_username Status privileges management (GHSA-3gqc-xr75-pcpw)

A vulnerability classified as critical has been found in Chamilo LMS up to 1.11.37 . Affected by this issue is the function update_user_from_username . This manipulation of the argument Status causes …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33736 | Chamilo LMS up to 2.0.0-RC.2 Personal Information /api/users authorization (GHSA-fp2p-fj6c-x3x9)

A vulnerability classified as problematic was found in Chamilo LMS up to 2.0.0-RC.2 . This affects an unknown part of the file /api/users of the component Personal Information Handler . Such manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33705 | Chamilo LMS up to 1.11.37 AJAX Endpoint /main/template/default/ file information disclosure (GHSA-5wjg-8x28-px57)

A vulnerability, which was classified as problematic , has been found in Chamilo LMS up to 1.11.37 . This vulnerability affects unknown code of the file /main/template/default/ of the component AJAX E…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40177 | ajenti up to 0.111 2FA improper authentication (GHSA-3mcx-6wxm-qr8v)

A vulnerability, which was classified as critical , was found in ajenti up to 0.111 . This issue affects some unknown processing of the component 2FA . Executing a manipulation can lead to improper au…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33708 | Chamilo LMS up to 1.11.37 REST API Endpoint get_user_info_from_username authorization (GHSA-qwch-82q9-q999)

A vulnerability has been found in Chamilo LMS up to 1.11.37 and classified as problematic . Impacted is the function get_user_info_from_username of the component REST API Endpoint . The manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40178 | ajenti up to 0.111 improper authentication (GHSA-8647-755q-fw9p)

A vulnerability was found in ajenti up to 0.111 and classified as critical . The affected element is an unknown function. The manipulation results in improper authentication. This vulnerability is cat…

VulDB Read →
← Prev 127 / 260 Next →