CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6318 articles  ·  updated every 4 hours · grows forever

6318Total
4065Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-4338 | Automattic ActivityPub Plugin up to 8.0.1 on WordPress drafts/scheduled/pending information disclosure

A vulnerability described as problematic has been identified in Automattic ActivityPub Plugin up to 8.0.1 on WordPress. This vulnerability affects unknown code of the file drafts/scheduled/pending . S…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5082 | TOKUHIROM Amon2::Plugin::Web::CSRFDefender up to 7.03 on Perl /dev/urandom rand generation of predictable numbers or identifiers

A vulnerability classified as problematic has been found in TOKUHIROM Amon2::Plugin::Web::CSRFDefender up to 7.03 on Perl. This issue affects the function rand of the file /dev/urandom . Performing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-3535 | mlfactory DSGVO Google Web Fonts GDPR Plugin up to 1.1 on WordPress CSS File DSGVOGWPdownloadGoogleFonts unrestricted upload

A vulnerability classified as critical was found in mlfactory DSGVO Google Web Fonts GDPR Plugin up to 1.1 on WordPress. Impacted is the function DSGVOGWPdownloadGoogleFonts of the component CSS File …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5169 | udamadu Inquiry form to posts or pages Plugin up to 1.0 on WordPress Setting inq_form.php update_option cross site scripting

A vulnerability, which was classified as problematic , has been found in udamadu Inquiry form to posts or pages Plugin up to 1.0 on WordPress. The affected element is the function update_option of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-4808 | tidevapps Gerador de Certificados Plugin up to 1.3.6 on WordPress moveUploadedFile unrestricted upload

A vulnerability, which was classified as critical , was found in tidevapps Gerador de Certificados Plugin up to 1.3.6 on WordPress. The impacted element is the function moveUploadedFile . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-3477 | projectzealous01 PZ Frontend Manager Plugin up to 1.0.6 on WordPress AJAX Endpoint pzfm_user_request_action_callback dataType authorization

A vulnerability has been found in projectzealous01 PZ Frontend Manager Plugin up to 1.0.6 on WordPress and classified as problematic . This affects the function pzfm_user_request_action_callback of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-3594 | imprintnext Riaxe Product Customizer Plugin up to 2.4 on WordPress REST API Endpoint orders information disclosure

A vulnerability was found in imprintnext Riaxe Product Customizer Plugin up to 2.4 on WordPress and classified as problematic . This impacts an unknown function of the file /wp-json/InkXEProductDesign…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-3480 | burlingtonbytes WP Blockade Plugin up to 0.9.14 on WordPress Shortcode render_shortcode_preview authorization

A vulnerability was found in burlingtonbytes WP Blockade Plugin up to 0.9.14 on WordPress. It has been classified as problematic . Affected is the function render_shortcode_preview of the component Sh…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-3781 | tnomi Attendance Manager Plugin up to 0.6.2 on WordPress attmgr_off sql injection

A vulnerability was found in tnomi Attendance Manager Plugin up to 0.6.2 on WordPress. It has been declared as critical . Affected by this vulnerability is an unknown functionality. Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5167 | Masteriyo LMS Plugin up to 2.1.7 on WordPress Webhook Endpoint handle_webhook order_id authorization

A vulnerability was found in Masteriyo LMS Plugin up to 2.1.7 on WordPress. It has been rated as critical . Affected by this issue is the function handle_webhook of the component Webhook Endpoint . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-2838 | idealwebdesignlk Whole Enquiry Cart for WooCommerce Plugin up to 1.2.1 on WordPress woowhole_success_msg cross site scripting

A vulnerability categorized as problematic has been discovered in idealwebdesignlk Whole Enquiry Cart for WooCommerce Plugin up to 1.2.1 on WordPress. This affects the function woowhole_success_msg . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-1794 | johanaarstein AM LottiePlayer Plugin up to 3.6.0 on WordPress SVG File Parser cross site scripting

A vulnerability identified as problematic has been detected in johanaarstein AM LottiePlayer Plugin up to 3.6.0 on WordPress. This vulnerability affects unknown code of the component SVG File Parser .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-4871 | pstruik Sports Club Management Plugin up to 1.12.9 on WordPress Shortcode scm_member_data cross site scripting

A vulnerability labeled as problematic has been found in pstruik Sports Club Management Plugin up to 1.12.9 on WordPress. This issue affects the function scm_member_data of the component Shortcode Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-3142 | uniquecodergmailcom Pinterest Site Verification plugin using Meta Tag up to 1.8 on WordPress post_var cross site scripting

A vulnerability marked as problematic has been reported in uniquecodergmailcom Pinterest Site Verification plugin using Meta Tag up to 1.8 on WordPress. Impacted is an unknown function. Performing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-3618 | bestweblayout Columns by BestWebSoft Plugin up to 1.0.3 on WordPress Shortcode shortcode_atts ID cross site scripting

A vulnerability described as problematic has been identified in bestweblayout Columns by BestWebSoft Plugin up to 1.0.3 on WordPress. The affected element is the function shortcode_atts of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5506 | lucascaro Wavr Plugin up to 0.2.6 on WordPress Shortcode wave cross site scripting

A vulnerability classified as problematic has been found in lucascaro Wavr Plugin up to 0.2.6 on WordPress. The impacted element is the function wave of the component Shortcode Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5508 | theyeti WowPress Plugin up to 1.0.0 on WordPress Shortcode wowpress cross site scripting

A vulnerability classified as problematic was found in theyeti WowPress Plugin up to 1.0.0 on WordPress. This affects the function wowpress of the component Shortcode Handler . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-4141 | edckwt Quran Translations Plugin up to 1.7 on WordPress quran_playlist_options cross-site request forgery

A vulnerability, which was classified as problematic , has been found in edckwt Quran Translations Plugin up to 1.7 on WordPress. This impacts the function quran_playlist_options . This manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39362 | InvenTree 1.2.6 remote_image server-side request forgery (GHSA-m9j7-jw3m-fr22)

A vulnerability, which was classified as critical , was found in InvenTree 1.2.6 . Affected is an unknown function. Such manipulation of the argument remote_image leads to server-side request forgery.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
Google patches Chrome vulnerability with in-the-wild exploit (CVE-2026-2441) - Help Net Security

Google patches Chrome vulnerability with in-the-wild exploit (CVE-2026-2441) Help Net Security

Help Net Security Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-14857 | Semtech LR1110/LR1120/LR1121 SPI Interface write-what-where condition (psa-2026-001)

A vulnerability described as problematic has been identified in Semtech LR1110, LR1120 and LR1121 . The impacted element is an unknown function of the component SPI Interface . Such manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39400 | jhuckaby Cronicle up to 0.9.110 Job Details Page create_events cross site scripting (GHSA-36q6-pwxv-j545 / EUVD-2026-19923)

A vulnerability classified as problematic has been found in jhuckaby Cronicle up to 0.9.110 . This affects the function create_events of the component Job Details Page . Performing a manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39356 | drizzle-team drizzle-orm up to 0.45.1 escapeName sql injection (GHSA-gpj5-g38j-94v9)

A vulnerability classified as critical was found in drizzle-team drizzle-orm up to 0.45.1 . This impacts the function escapeName . Executing a manipulation can lead to sql injection. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39382 | dbt-labs dbt-core Comment open-issue-in-repo.yml steps.issue_comment.outputs.comment- os command injection (GHSA-5jxf-vmqr-5g82)

A vulnerability, which was classified as critical , has been found in dbt-labs dbt-core . Affected is an unknown function of the file dbt-labs/actions/blob/main/.github/workflows/open-issue-in-repo.ym…

VulDB Read →
← Prev 147 / 264 Next →