CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6482 articles  ·  updated every 4 hours · grows forever

6482Total
4071Full Text
May 26, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-28527 | BlueKitchen BTstack up to 1.8.0 AVRCP Controller out-of-bounds

A vulnerability was found in BlueKitchen BTstack up to 1.8.0 . It has been classified as problematic . This affects the function GET_PLAYER_APPLICATION_SETTING_ATTRIBUTE_TEXT/GET_PLAYER_APPLICATION_SE…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-28528 | BlueKitchen BTstack up to 1.8.0 AVRCP Browsing Target attr_id out-of-bounds

A vulnerability was found in BlueKitchen BTstack up to 1.8.0 . It has been declared as problematic . This vulnerability affects unknown code of the component AVRCP Browsing Target Handler . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-30564 | SourceCodester Sales and Inventory System 1.0 Parameter view_payments.php limit cross site scripting

A vulnerability was found in SourceCodester Sales and Inventory System 1.0 . It has been rated as problematic . This issue affects some unknown processing of the file view_payments.php of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-30566 | SourceCodester Sales and Inventory System 1.0 Parameter view_customers.php limit cross site scripting

A vulnerability categorized as problematic has been discovered in SourceCodester Sales and Inventory System 1.0 . Impacted is an unknown function of the file view_customers.php of the component Parame…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-30565 | SourceCodester Sales and Inventory System 1.0 Parameter view_supplier.php limit cross site scripting

A vulnerability identified as problematic has been detected in SourceCodester Sales and Inventory System 1.0 . The affected element is an unknown function of the file view_supplier.php of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5165 | virtio-win kvm-guest-drivers-windows VirtIO Block Device expired pointer dereference

A vulnerability labeled as critical has been found in virtio-win kvm-guest-drivers-windows . The impacted element is an unknown function of the component VirtIO Block Device . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5164 | virtio-win kvm-guest-drivers-windows RhelDoUnMap buffer overflow

A vulnerability marked as critical has been reported in virtio-win kvm-guest-drivers-windows . This affects the function RhelDoUnMap . The manipulation leads to buffer overflow. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33373 | Zimbra Collaboration Suite 10.0/10.1 cross-site request forgery

A vulnerability described as problematic has been identified in Zimbra Collaboration Suite 10.0/10.1 . This impacts an unknown function. The manipulation results in cross-site request forgery. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-30563 | SourceCodester Sales and Inventory System 1.0 POST Request update_details.php Website cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Sales and Inventory System 1.0 . Affected is an unknown function of the file update_details.php of the component POST Request…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-30082 | IngEstate Server 11.14.0 Software Package List Page Release note cross site scripting

A vulnerability classified as problematic was found in IngEstate Server 11.14.0 . Affected by this vulnerability is an unknown functionality of the component Software Package List Page . Such manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3945 | tinyproxy up to 1.11.3 Chunk strtol integer overflow (EUVD-2026-17066)

A vulnerability was found in tinyproxy up to 1.11.3 . It has been classified as problematic . This issue affects the function strtol of the component Chunk Handler . The manipulation leads to integer …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-15379 | MLflow up to 3.8.1 Model _install_model_dependencies_to_env command injection (EUVD-2025-209121)

A vulnerability was found in MLflow up to 3.8.1 . It has been declared as critical . Impacted is the function _install_model_dependencies_to_env of the component Model Handler . The manipulation resul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5119 | GNOME libsoup HTTP Proxy cleartext transmission (EUVD-2026-17062)

A vulnerability was found in GNOME libsoup . It has been rated as problematic . The affected element is an unknown function of the component HTTP Proxy Handler . This manipulation causes cleartext tra…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-2328 | WAGO Device Sphere/Solution Builder up to 1.2.1 improper filtering of special elements (VDE-2026-010 / EUVD-2026-17064)

A vulnerability categorized as critical has been discovered in WAGO Device Sphere and Solution Builder up to 1.2.1 . The impacted element is an unknown function. Such manipulation leads to improper fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5122 | osrg GoBGP up to 4.3.0 BGP OPEN Message pkg/packet/bgp/bgp.go DecodeFromBytes domainNameLen access control (ID 3343)

A vulnerability identified as problematic has been detected in osrg GoBGP up to 4.3.0 . This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5123 | osrg GoBGP up to 4.3.0 pkg/packet/bgp/bgp.go DecodeFromBytes data[1] off-by-one (ID 3342)

A vulnerability labeled as problematic has been found in osrg GoBGP up to 4.3.0 . This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go . Executing a manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5124 | osrg GoBGP up to 4.3.0 BGP Header pkg/packet/bgp/bgp.go BGPHeader.DecodeFromBytes access control (ID 3340)

A vulnerability marked as problematic has been reported in osrg GoBGP up to 4.3.0 . Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5125 | raine consult-llm-mcp up to 2.5.3 src/server.ts child_process.execSync git_diff.base_ref/git_diff.files os command injection

A vulnerability described as critical has been identified in raine consult-llm-mcp up to 2.5.3 . Affected by this vulnerability is the function child_process.execSync of the file src/server.ts . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5126 | SourceCodester RSS Feed Parser 1.0 file_get_contents server-side request forgery

A vulnerability classified as critical has been found in SourceCodester RSS Feed Parser 1.0 . Affected by this issue is the function file_get_contents . This manipulation causes server-side request fo…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4415 | GIGABYTE Control Center up to 25.07.21.01 path traversal (EUVD-2026-17069)

A vulnerability classified as critical was found in GIGABYTE Control Center up to 25.07.21.01 . This affects an unknown part. Such manipulation leads to relative path traversal. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5121 | libarchive on 32-bit ISO9660 Image Parser heap-based overflow

A vulnerability, which was classified as critical , has been found in libarchive on 32-bit. This vulnerability affects unknown code of the component ISO9660 Image Parser . Performing a manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-25704 | pop-os cosmic-greeter privilege dropping (ID 426 / EUVD-2026-17067)

A vulnerability, which was classified as problematic , was found in pop-os cosmic-greeter . This issue affects some unknown processing. Executing a manipulation can lead to privilege dropping / loweri…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4416 | GIGABYTE Control Center prior 25.12.31.01 Performance Library deserialization

A vulnerability has been found in GIGABYTE Control Center and classified as critical . Impacted is an unknown function of the component Performance Library . The manipulation leads to deserialization.…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-3716 | ESET Protect prior 12.1.1.0 response discrepancy (EUVD-2025-209122)

A vulnerability was found in ESET Protect and classified as problematic . The affected element is an unknown function. The manipulation results in observable response discrepancy. This vulnerability i…

VulDB Read →
← Prev 198 / 271 Next →