CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6455 articles  ·  updated every 4 hours · grows forever

6455Total
4070Full Text
May 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5211 | D-Link DNS-1550-04 up to 20260205 /cgi-bin/app_mgr.cgi UPnP_AV_Server_Path_Del f_dir stack-based overflow

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, D…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5212 | D-Link DNS-1550-04 up to 20260205 /cgi-bin/webdav_mgr.cgi Webdav_Upload_File f_file stack-based overflow

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, D…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5214 | D-Link DNS-1550-04 up to 20260205 /cgi-bin/account_mgr.cgi cgi_addgroup_get_group_quota_minsize Name stack-based overflow

A vulnerability categorized as critical has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-34…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5213 | D-Link DNS-1550-04 up to 20260205 /cgi-bin/account_mgr.cgi cgi_adduser_to_session read_list stack-based overflow

A vulnerability identified as critical has been detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L,…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5215 | D-Link DNS-1550-04 up to 20260205 /cgi-bin/network_mgr.cgi cgi_get_ipv6 access control

A vulnerability labeled as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-3…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34054 | Microsoft vcpkg up to 3.6.1#2 OpenSSL uncontrolled search path (GHSA-p322-v6vw-vrq9)

A vulnerability, which was classified as problematic , was found in Microsoft vcpkg up to 3.6.1#2 . Affected by this issue is some unknown functionality of the component OpenSSL . The manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34036 | Dolibarr up to 22.0.4 AJAX Endpoint selectobject.php restrictedArea objectdesc filename control (GHSA-2mfj-r695-5h9r)

A vulnerability has been found in Dolibarr up to 22.0.4 and classified as problematic . This affects the function restrictedArea of the file /core/ajax/selectobject.php of the component AJAX Endpoint …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2025-32957 | baserproject basercms up to 5.2.2 require_once unrestricted upload (GHSA-hv78-cwp4-8r7r)

A vulnerability was found in baserproject basercms up to 5.2.2 and classified as critical . This vulnerability affects the function require_once . Such manipulation leads to unrestricted upload. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34060 | Shopify ruby-lsp up to 0.26.8 vscode/settings.json code injection (GHSA-c4r5-fxqw-vh93)

A vulnerability was found in Shopify ruby-lsp up to 0.26.8 . It has been classified as critical . This issue affects some unknown processing of the file vscode/settings.json . Performing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-1710 | woocommerce WooPayments Plugin up to 10.5.1 on WordPress Setting save_upe_appearance_ajax improper authorization

A vulnerability was found in woocommerce WooPayments Plugin up to 10.5.1 on WordPress. It has been declared as critical . Impacted is the function save_upe_appearance_ajax of the component Setting Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5130 | jhimross Debugger & Troubleshooter Plugin up to 1.3.2 on WordPress wp_debug_troubleshoot_simulate_user cookie cookie validation

A vulnerability was found in jhimross Debugger & Troubleshooter Plugin up to 1.3.2 on WordPress. It has been rated as critical . The affected element is the function wp_debug_troubleshoot_simulate_use…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-32714 | SciTokens up to 1.9.5 str.format sql injection (GHSA-rh5m-2482-966c)

A vulnerability categorized as critical has been discovered in SciTokens up to 1.9.5 . The impacted element is the function str.format . The manipulation results in sql injection. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-32716 | SciTokens up to 1.9.5 improper authorization (GHSA-w8fp-g9rh-34jh)

A vulnerability identified as critical has been detected in SciTokens up to 1.9.5 . This affects an unknown function. This manipulation causes improper authorization. This vulnerability is tracked as …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-32727 | SciTokens up to 1.9.6 path traversal (GHSA-3x2w-63fp-3qvw)

A vulnerability labeled as critical has been found in SciTokens up to 1.9.6 . This impacts an unknown function. Such manipulation leads to path traversal. This vulnerability is listed as CVE-2026-3272…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5115 | PaperCut NG/MF up to 25.0.4 Communication Channel cleartext transmission

A vulnerability marked as problematic has been reported in PaperCut NG and MF up to 25.0.4 . Affected is an unknown function of the component Communication Channel Handler . Performing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34043 | yahoo serialize-javascript up to 7.0.4 Regular Expression resource consumption (GHSA-qj8w-gfj5-8c6v)

A vulnerability described as problematic has been identified in yahoo serialize-javascript up to 7.0.4 . Affected by this vulnerability is an unknown functionality of the component Regular Expression …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34070 | langchain-ai langchain up to 1.2.21 load_prompt/load_prompt_from_config path traversal (GHSA-qh6h-p6c9-ff54)

A vulnerability classified as critical has been found in langchain-ai langchain up to 1.2.21 . Affected by this issue is the function load_prompt/load_prompt_from_config . The manipulation leads to pa…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-4146 | timwhitlock Loco Translate Plugin up to 2.8.2 on WordPress Parameter update_href cross site scripting

A vulnerability classified as problematic was found in timwhitlock Loco Translate Plugin up to 2.8.2 on WordPress. This affects an unknown part of the component Parameter Handler . The manipulation of…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34042 | nektos act up to 0.2.85 Docker Container authorization (ID 294)

A vulnerability, which was classified as critical , has been found in nektos act up to 0.2.85 . This vulnerability affects unknown code of the component Docker Container Handler . This manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-33997 | Moby up to 29.3.0 off-by-one (GHSA-pxq6-2prw-chj9)

A vulnerability, which was classified as problematic , was found in Moby up to 29.3.0 . This issue affects some unknown processing. Such manipulation leads to off-by-one. This vulnerability is traded …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-1834 | vowelweb Ibtana Plugin up to 1.2.5.7 on WordPress Shortcode ive cross site scripting

A vulnerability has been found in vowelweb Ibtana Plugin up to 1.2.5.7 on WordPress and classified as problematic . Impacted is the function ive of the component Shortcode Handler . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30877 | baserproject basercms up to 5.2.2 User Account update os command injection (GHSA-m9g7-rgfc-jcm7)

A vulnerability was found in baserproject basercms up to 5.2.2 and classified as critical . The affected element is the function update of the component User Account Handler . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30878 | baserproject basercms up to 5.2.2 Submission API improper authorization (GHSA-8cr7-r8qw-gp3c)

A vulnerability was found in baserproject basercms up to 5.2.2 . It has been classified as critical . The impacted element is an unknown function of the component Submission API . The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-21861 | baserproject basercms up to 5.2.2 exec os command injection (GHSA-qxmc-6f24-g86g)

A vulnerability was found in baserproject basercms up to 5.2.2 . It has been declared as critical . This affects the function exec . The manipulation results in os command injection. This vulnerabilit…

VulDB Read →
← Prev 192 / 269 Next →