CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6368 articles  ·  updated every 4 hours · grows forever

6368Total
4066Full Text
May 24, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-0737 | gn_themes WP Shortcodes Plugin up to 7.4.7 on WordPress Shortcode su_lightbox src cross site scripting

A vulnerability labeled as problematic has been found in gn_themes WP Shortcodes Plugin up to 7.4.7 on WordPress. This affects the function su_lightbox of the component Shortcode Handler . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-0738 | gn_themes WP Shortcodes Plugin up to 7.4.8 on WordPress Shortcode su_slide_link cross site scripting

A vulnerability marked as problematic has been reported in gn_themes WP Shortcodes Plugin up to 7.4.8 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-2600 | roxnor ElementsKit Elementor Addons Plugin up to 3.7.9 on WordPress Simple Tab Widget ekit_tab_title cross site scripting

A vulnerability described as problematic has been identified in roxnor ElementsKit Elementor Addons Plugin up to 3.7.9 on WordPress. This issue affects some unknown processing of the component Simple …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-2437 | wptravelengine WP Travel Engine Plugin up to 6.7.5 on WordPress Shortcode wte_trip_tax cross site scripting

A vulnerability classified as problematic has been found in wptravelengine WP Travel Engine Plugin up to 6.7.5 on WordPress. Impacted is the function wte_trip_tax of the component Shortcode Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-2826 | stellarwp Kadence Blocks Plugin up to 3.6.3 on WordPress REST API Endpoint process_pattern upload_files authorization

A vulnerability classified as critical was found in stellarwp Kadence Blocks Plugin up to 3.6.3 on WordPress. The affected element is the function upload_files of the file process_pattern of the compo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-3445 | properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin process_checkout authorization

A vulnerability, which was classified as critical , has been found in properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin up to…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5425 | trustindex Widgets for Social Photo Feed Plugin up to 1.7.9 on WordPress feed_data cross site scripting

A vulnerability, which was classified as problematic , was found in trustindex Widgets for Social Photo Feed Plugin up to 1.7.9 on WordPress. This affects an unknown function. The manipulation of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
Critical Fortinet FortiClient EMS Vulnerability Allows Remote Code Execution - gbhackers.com

Critical Fortinet FortiClient EMS Vulnerability Allows Remote Code Execution gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket - The Hacker News

ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
Google Issues Zero-Day Attack Alert For 3.5 Billion Chrome Users - Forbes

Google Issues Zero-Day Attack Alert For 3.5 Billion Chrome Users Forbes

Forbes Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-34228 | Emlog up to 2.6.7 Backend Upgrade Interface cross-site request forgery (GHSA-2rcc-jg83-34vp)

A vulnerability has been found in Emlog up to 2.6.7 and classified as problematic . Affected by this vulnerability is an unknown functionality of the component Backend Upgrade Interface . This manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-34934 | MervinPraison PraisonAI up to 4.5.89 get_all_user_threads sql injection (GHSA-9cq8-3v94-434g)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.89 and classified as critical . Affected by this issue is the function get_all_user_threads . Such manipulation leads to sql injection. T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-34935 | MervinPraison PraisonAI up to 4.5.68 anyio.open_process mcp os command injection (GHSA-9gm9-c8mq-vq7m)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.68 . It has been classified as critical . This affects the function anyio.open_process . Performing a manipulation of the argument mcp re…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2017-20238 | Belden Hirschmann Industrial HiVision up to 06.0.05/06.0.5/07.00 Web Interface improper authorization

A vulnerability was found in Belden Hirschmann Industrial HiVision up to 06.0.05/06.0.5/07.00 . It has been declared as critical . This vulnerability affects unknown code of the component Web Interfac…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-34052 | jupyterhub ltiauthenticator up to 1.6.2 memory leak (GHSA-8mxq-7xr7-2fxj)

A vulnerability was found in jupyterhub ltiauthenticator up to 1.6.2 . It has been rated as problematic . This issue affects some unknown processing. The manipulation leads to memory leak. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-33175 | jupyterhub oauthenticator up to 17.3.x usrname_claim improper authentication (GHSA-rrvg-cxh4-qhrv)

A vulnerability categorized as critical has been discovered in jupyterhub oauthenticator up to 17.3.x . Impacted is an unknown function. The manipulation of the argument usrname_claim results in impro…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-33709 | Jupyter Notbook up to 5.4.3 Jupyterhub redirect (GHSA-3vff-hjqv-m7h8)

A vulnerability identified as problematic has been detected in Jupyter Notbook up to 5.4.3 . The affected element is an unknown function of the component Jupyterhub . This manipulation causes open red…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2016-15058 | Belden Hirschmann HiLCOS Classic Platform up to 05.3.06/05.3.6/09.0.05/09.0.5 SNMP password recoverable

A vulnerability labeled as critical has been found in Belden Hirschmann HiLCOS Classic Platform up to 05.3.06/05.3.6/09.0.05/09.0.5 . The impacted element is an unknown function of the component SNMP …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-35043 | BentoML up to 1.4.37 command injection

A vulnerability marked as critical has been reported in BentoML up to 1.4.37 . This affects an unknown function. Performing a manipulation results in command injection. This vulnerability is known as …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-35042 | nearform fast-jwt crit Header Extension data authenticity

A vulnerability described as problematic has been identified in nearform fast-jwt . This impacts an unknown function of the component crit Header Extension . Executing a manipulation can lead to insuf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-33752 | curl_cffi prior 0.15.0 redirect

A vulnerability classified as problematic has been found in curl_cffi . Affected is an unknown function. The manipulation leads to open redirect. This vulnerability is uniquely identified as CVE-2026-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5526 | Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1 /bin/httpd access control

A vulnerability classified as critical was found in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1 . Affected by this vulnerability is an unknown functionality of the file /bin/httpd . The manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5527 | Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53 ECDSA P-256 Private Key /etc/www/pem/server.key hard-coded key

A vulnerability, which was classified as problematic , has been found in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53 . Affected by this issue is some unknown functionality of the file /etc/www/pem/ser…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5528 | MoussaabBadla code-screenshot-mcp up to 0.1.0 HTTP Interface os command injection

A vulnerability, which was classified as critical , was found in MoussaabBadla code-screenshot-mcp up to 0.1.0 . This affects an unknown part of the component HTTP Interface . Such manipulation leads …

VulDB Read →
← Prev 166 / 266 Next →