CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6338 articles  ·  updated every 4 hours · grows forever

6338Total
4066Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35046 | TandoorRecipes recipes up to 2.6.3 bleach.clean cross site scripting (GHSA-9hhh-g2fc-r8x2)

A vulnerability, which was classified as problematic , was found in TandoorRecipes recipes up to 2.6.3 . Affected by this vulnerability is the function bleach.clean . Executing a manipulation can lead…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-0049 | Google Android 14/15/16/16-qpr2 LocalImageResolver.java onHeaderDecoded resource consumption

A vulnerability has been found in Google Android 14/15/16/16-qpr2 and classified as problematic . Affected by this issue is the function onHeaderDecoded of the file LocalImageResolver.java . The manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35166 | gohugoio hugo up to 0.159.1 Link cross site scripting (GHSA-mcv8-8m8x-48pg)

A vulnerability was found in gohugoio hugo up to 0.159.1 and classified as problematic . This affects an unknown part of the component Link Handler . The manipulation results in cross site scripting. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35175 | Ajenti up to 2.2.14 auth_users authorization (GHSA-73jv-44c3-j5p2)

A vulnerability was found in Ajenti up to 2.2.14 . It has been classified as critical . This vulnerability affects the function auth_users . This manipulation causes missing authorization. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-30613 | AZIOT 1.1.9 UART Interface information disclosure

A vulnerability was found in AZIOT 1.1.9 . It has been declared as problematic . This issue affects some unknown processing of the component UART Interface . Such manipulation leads to information dis…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35173 | xenocrat chyrp-lite prior 2026.01 authorization (GHSA-8c3h-rh2j-fxr9)

A vulnerability was found in xenocrat chyrp-lite . It has been rated as problematic . Impacted is an unknown function. Performing a manipulation results in authorization bypass. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35177 | vim up to 9.2.0279 zip.vim Plugin path traversal (GHSA-jc86-w7vm-8p24)

A vulnerability categorized as critical has been discovered in vim up to 9.2.0279 . The affected element is an unknown function of the component zip.vim Plugin . Executing a manipulation can lead to p…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2025-61166 | SigningHub User 10.0 URL redirect

A vulnerability identified as problematic has been detected in SigningHub User 10.0 . The impacted element is an unknown function of the component URL Handler . The manipulation leads to open redirect…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2025-48651 | Google Android privilege escalation

A vulnerability labeled as problematic has been found in Google Android . This affects an unknown function. The manipulation results in privilege escalation. This vulnerability was named CVE-2025-4865…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-33817 | etcd bbolt Branch Page out-of-bounds (ID 4923)

A vulnerability marked as problematic has been reported in etcd bbolt . This impacts an unknown function of the component Branch Page Handler . This manipulation causes out-of-bounds read. The identif…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[webapps] WordPress Madara - Local File Inclusion

WordPress Madara - Local File Inclusion

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[webapps] RiteCMS 3.1.0 - Authenticated Remote Code Execution

RiteCMS 3.1.0 - Authenticated Remote Code Execution

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[webapps] WBCE CMS 1.6.4 - Remote Code Execution

WBCE CMS 1.6.4 - Remote Code Execution

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[webapps] Zhiyuan OA - arbitrary file upload leading

Zhiyuan OA - arbitrary file upload leading

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[webapps] Grafana 11.6.0 - SSRF

Grafana 11.6.0 - SSRF

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[webapps] ASP.net 8.0.10 - Bypass

ASP.net 8.0.10 - Bypass

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[local] Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation

Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[local] Windows Kernel - Elevation of Privilege

Windows Kernel - Elevation of Privilege

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[webapps] Fortinet FortiWeb v8.0.1 - Auth Bypass

Fortinet FortiWeb v8.0.1 - Auth Bypass

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
[local] is-localhost-ip 2.0.0 - SSRF

is-localhost-ip 2.0.0 - SSRF

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-3524 | Mattermost Legal Hold Plugin up to 1.1.4 API authorization

A vulnerability has been found in Mattermost Legal Hold Plugin up to 1.1.4 and classified as critical . Affected is an unknown function of the component API Handler . This manipulation causes missing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5705 | code-projects Online Hotel Booking 1.0 Booking Endpoint /booknow.php roomname cross site scripting

A vulnerability was found in code-projects Online Hotel Booking 1.0 and classified as problematic . Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update - CyberSecurityNews

MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5668 | Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f add%20notice.php $_SERVER['PHP_SELF'] cross site scripting (Issue 239)

A vulnerability, which was classified as problematic , has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f . This affects an unknown part of the file /…

VulDB Read →
← Prev 156 / 265 Next →