CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6256 articles  ·  updated every 4 hours · grows forever

6256Total
4061Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-33702 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 lp_ajax_save_item.php authorization

A vulnerability classified as problematic was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . Affected is an unknown function of the file lp_ajax_save_item.php . The manipulation results in authorizat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-33703 | Chamilo LMS up to 2.0.0-RC.2 personal-data userId authorization

A vulnerability, which was classified as problematic , has been found in Chamilo LMS up to 2.0.0-RC.2 . Affected by this vulnerability is an unknown functionality of the file /social-network/personal-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-3446 | Python CPython up to 3.13.12/3.14.3/3.15.0a7 b64decode

A vulnerability, which was classified as problematic , was found in Python CPython up to 3.13.12/3.14.3/3.15.0a7 . Affected by this issue is the function b64decode . Such manipulation leads to an unkn…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
[webapps] D-Link DIR-650IN - Authenticated Command Injection

D-Link DIR-650IN - Authenticated Command Injection

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
[local] NetBT e-Fatura - Privilege Escalation

NetBT e-Fatura - Privilege Escalation

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-31412 | Linux Kernel up to 7.0-rc3 USB check_command_size_in_blocks integer overflow

A vulnerability has been found in Linux Kernel up to 7.0-rc3 and classified as critical . Affected by this vulnerability is the function check_command_size_in_blocks of the component USB Handler . The…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2021-47961 | Synology SSL VPN Client up to 1.4.5-0683 VPN Configuration credentials storage (SA_26_05)

A vulnerability was found in Synology SSL VPN Client up to 1.4.5-0683 and classified as problematic . Affected by this issue is some unknown functionality of the component VPN Configuration Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-6057 | FalkorDB Browser 1.9.3 File Upload API path traversal

A vulnerability was found in FalkorDB Browser 1.9.3 . It has been classified as critical . This affects an unknown part of the component File Upload API . This manipulation causes path traversal. The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-5774 | Canonical Juju up to 2.9.56/3.6.20/4.0.5 API Server race condition (GHSA-7m55-2hr4-pw78)

A vulnerability was found in Canonical Juju up to 2.9.56/3.6.20/4.0.5 . It has been declared as problematic . This vulnerability affects unknown code of the component API Server . Such manipulation le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-4162 | RocketGenius Gravity SMTP Plugin up to 2.1.4 on WordPress authorization

A vulnerability was found in RocketGenius Gravity SMTP Plugin up to 2.1.4 on WordPress. It has been rated as critical . This issue affects some unknown processing. Performing a manipulation results in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-5412 | Canonical Juju up to 2.9.56/3.6.20 CloudSpec API improper authorization (GHSA-w5fq-8965-c969)

A vulnerability categorized as critical has been discovered in Canonical Juju up to 2.9.56/3.6.20 . Impacted is an unknown function of the component CloudSpec API . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2021-47960 | Synology SSL VPN Client up to 1.4.5-0683 Loopback Interface file access (SA_26_05)

A vulnerability identified as problematic has been detected in Synology SSL VPN Client up to 1.4.5-0683 . The affected element is an unknown function of the component Loopback Interface . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-5777 | EGate Atom 3X Projector missing authentication (CIVN-2026-0179)

A vulnerability labeled as critical has been found in EGate Atom 3X Projector . The impacted element is an unknown function. The manipulation results in missing authentication. This vulnerability is c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-6067 | NASM Netwide Assembler 3.02rc5 obj_directive out-of-bounds write

A vulnerability marked as critical has been reported in NASM Netwide Assembler 3.02rc5 . This affects the function obj_directive . This manipulation causes out-of-bounds write. This vulnerability is r…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-6068 | NASM Netwide Assembler 3.02rc5 depend_file use after free

A vulnerability described as critical has been identified in NASM Netwide Assembler 3.02rc5 . This impacts the function depend_file . Such manipulation leads to use after free. This vulnerability is d…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-6069 | NASM Netwide Assembler 3.02rc5 disasm stack-based overflow

A vulnerability classified as critical has been found in NASM Netwide Assembler 3.02rc5 . Affected is the function disasm . Performing a manipulation results in stack-based buffer overflow. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-33092 | Acronis True Image OEM/True Image on macOS Environment Variable external control of setting

A vulnerability classified as critical was found in Acronis True Image OEM and True Image on macOS. Affected by this vulnerability is an unknown functionality of the component Environment Variable Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2025-58920 | Zootemplate Cerato Plugin up to 2.2.18 on WordPress cross site scripting

A vulnerability, which was classified as problematic , has been found in Zootemplate Cerato Plugin up to 2.2.18 on WordPress. Affected by this issue is some unknown functionality. The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40217 | BerriAI LiteLLM test_custom_code unprotected alternate channel

A vulnerability, which was classified as critical , was found in BerriAI LiteLLM bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743f . This affects an unknown part of the file /guardrails…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-36235 | itsourcecode Online Student Enrollment System 1.0 scheduleSubList.php subjcode sql injection

A vulnerability has been found in itsourcecode Online Student Enrollment System 1.0 and classified as critical . This vulnerability affects unknown code of the file scheduleSubList.php . This manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-29861 | PHP-MYSQL-User-Login-System 1.0 login.php Username sql injection

A vulnerability was found in PHP-MYSQL-User-Login-System 1.0 and classified as critical . This issue affects some unknown processing of the file login.php . Such manipulation of the argument Username …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-36234 | itsourcecode Online Student Enrollment System 1.0 newCourse.php coursename sql injection

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 . It has been classified as critical . Impacted is an unknown function of the file newCourse.php . Performing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-23780 | BMC Control-M MFT up to 9.0.22 API Debug Interface path traversal

A vulnerability was found in BMC Control-M MFT up to 9.0.22 . It has been declared as critical . The affected element is an unknown function of the component API Debug Interface . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-36232 | itsourcecode Online Student Enrollment System 1.0 instructorClasses.php classId sql injection

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 . It has been rated as critical . The impacted element is an unknown function of the file instructorClasses.php . The man…

VulDB Read →
← Prev 131 / 261 Next →