CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6482 articles  ·  updated every 4 hours · grows forever

6482Total
4071Full Text
May 26, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33643 | SchemaHero 0.23.0 Parameter column.go mysqlColumnAsInsert column sql injection (EUVD-2026-17137)

A vulnerability described as critical has been identified in SchemaHero 0.23.0 . This issue affects the function mysqlColumnAsInsert in the library plugins/mysql/lib/column.go of the component Paramet…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-30077 | OpenAirInterface 2.2.0 AMF denial of service

A vulnerability classified as problematic has been found in OpenAirInterface 2.2.0 . Impacted is an unknown function of the component AMF . The manipulation leads to denial of service. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3689 | OpenClaw information disclosure

A vulnerability classified as problematic was found in OpenClaw . The affected element is an unknown function. The manipulation results in information disclosure. This vulnerability was named CVE-2026…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3690 | OpenClaw Canvas improper authentication

A vulnerability, which was classified as critical , has been found in OpenClaw . The impacted element is an unknown function of the component Canvas . This manipulation causes improper authentication.…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3691 | OpenClaw Client PKCE Verifier information disclosure

A vulnerability, which was classified as problematic , was found in OpenClaw . This affects an unknown function of the component Client PKCE Verifier . Such manipulation leads to information disclosur…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-27018 | gotenberg Chromium Deny-List path traversal

A vulnerability has been found in gotenberg and classified as critical . This impacts an unknown function of the component Chromium Deny-List . Performing a manipulation results in path traversal. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33030 | 0xJacky Nginx-UI Private Key credentials storage

A vulnerability was found in 0xJacky Nginx-UI and classified as problematic . Affected is an unknown function of the component Private Key Handler . Executing a manipulation can lead to unprotected st…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33533 | nicolargo glances XML-RPC Server cross-domain policy

A vulnerability was found in nicolargo glances . It has been classified as problematic . Affected by this vulnerability is an unknown functionality of the component XML-RPC Server . The manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3991 | Broadcom Data Loss Prevention up to 16.1 MP1/25.1 Windows Endpoint inclusion of functionality from untrusted control sphere

A vulnerability was found in Broadcom Data Loss Prevention up to 16.1 MP1/25.1 . It has been declared as critical . Affected by this issue is some unknown functionality of the component Windows Endpoi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33027 | 0xJacky nginx-ui up to 2.3.3 path traversal (GHSA-m8p8-53vf-8357)

A vulnerability was found in 0xJacky nginx-ui up to 2.3.3 . It has been rated as critical . This affects an unknown part. This manipulation causes path traversal. This vulnerability is registered as C…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33028 | 0xJacky nginx-ui up to 2.3.3 app.ini race condition (GHSA-m468-xcm6-fxg4)

A vulnerability categorized as problematic has been discovered in 0xJacky nginx-ui up to 2.3.3 . This vulnerability affects unknown code of the file app.ini . Such manipulation leads to race condition…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33029 | 0xJacky nginx-ui up to 2.3.3 Web Interface denial of service (GHSA-cp8r-8jvw-v3qg)

A vulnerability identified as problematic has been detected in 0xJacky nginx-ui up to 2.3.3 . This issue affects some unknown processing of the component Web Interface . Performing a manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-34714 | Vim up to 9.2.0271 File os command injection

A vulnerability labeled as critical has been found in Vim up to 9.2.0271 . Impacted is an unknown function of the component File Handler . Executing a manipulation can lead to os command injection. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3502 | TrueConf Client Application Update code download

A vulnerability marked as problematic has been reported in TrueConf Client . The affected element is an unknown function of the component Application Update Handler . The manipulation leads to downloa…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33032 | 0xJacky nginx-ui up to 2.3.5 Model Context Protocol /mcp AuthRequired missing authentication (GHSA-h6c2-x2m2-mwhf)

A vulnerability described as critical has been identified in 0xJacky nginx-ui up to 2.3.5 . The impacted element is the function AuthRequired of the file /mcp of the component Model Context Protocol .…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-29925 | Invoice Ninja 5.12.46/5.12.48 CheckDatabaseRequest.php server-side request forgery

A vulnerability classified as critical has been found in Invoice Ninja 5.12.46/5.12.48 . This affects an unknown function of the file CheckDatabaseRequest.php . This manipulation causes server-side re…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-29924 | Grav CMS up to 1.7.x SVG File xml external entity reference

A vulnerability classified as problematic was found in Grav CMS up to 1.7.x . This impacts an unknown function of the component SVG File Handler . Such manipulation leads to xml external entity refere…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5176 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setSyslogCfg provided command injection

A vulnerability, which was classified as critical , has been found in Totolink A3300R 17.0.0cu.557_b20221024 . Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5177 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setWiFiBasicCfg rxRate command injection

A vulnerability, which was classified as critical , was found in Totolink A3300R 17.0.0cu.557_b20221024 . Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cg…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5178 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setIptvCfg vlanPriLan3 command injection

A vulnerability has been found in Totolink A3300R 17.0.0cu.557_b20221024 and classified as critical . Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5179 | SourceCodester Simple Doctors Appointment System 1.0 /admin/login.php Username sql injection

A vulnerability was found in SourceCodester Simple Doctors Appointment System 1.0 and classified as critical . This affects an unknown part of the file /admin/login.php . The manipulation of the argum…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5180 | SourceCodester Simple Doctors Appointment System 1.0 ajax.php?action=login2 email sql injection

A vulnerability was found in SourceCodester Simple Doctors Appointment System 1.0 . It has been classified as critical . This vulnerability affects unknown code of the file /admin/ajax.php?action=logi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5181 | SourceCodester Simple Doctors Appointment System up to 1.0 ajax.php?action=save_category img unrestricted upload

A vulnerability was found in SourceCodester Simple Doctors Appointment System up to 1.0 . It has been declared as critical . This issue affects some unknown processing of the file /doctors_appointment…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5182 | SourceCodester Teacher Record System 1.0 Parameter searchteacher sql injection

A vulnerability was found in SourceCodester Teacher Record System 1.0 . It has been rated as critical . Impacted is an unknown function of the file Teacher Record System of the component Parameter Han…

VulDB Read →
← Prev 196 / 271 Next →