CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6513 articles  ·  updated every 4 hours · grows forever

6513Total
4072Full Text
May 26, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5125 | raine consult-llm-mcp up to 2.5.3 src/server.ts child_process.execSync git_diff.base_ref/git_diff.files os command injection

A vulnerability described as critical has been identified in raine consult-llm-mcp up to 2.5.3 . Affected by this vulnerability is the function child_process.execSync of the file src/server.ts . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5126 | SourceCodester RSS Feed Parser 1.0 file_get_contents server-side request forgery

A vulnerability classified as critical has been found in SourceCodester RSS Feed Parser 1.0 . Affected by this issue is the function file_get_contents . This manipulation causes server-side request fo…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4415 | GIGABYTE Control Center up to 25.07.21.01 path traversal (EUVD-2026-17069)

A vulnerability classified as critical was found in GIGABYTE Control Center up to 25.07.21.01 . This affects an unknown part. Such manipulation leads to relative path traversal. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5121 | libarchive on 32-bit ISO9660 Image Parser heap-based overflow

A vulnerability, which was classified as critical , has been found in libarchive on 32-bit. This vulnerability affects unknown code of the component ISO9660 Image Parser . Performing a manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-25704 | pop-os cosmic-greeter privilege dropping (ID 426 / EUVD-2026-17067)

A vulnerability, which was classified as problematic , was found in pop-os cosmic-greeter . This issue affects some unknown processing. Executing a manipulation can lead to privilege dropping / loweri…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4416 | GIGABYTE Control Center prior 25.12.31.01 Performance Library deserialization

A vulnerability has been found in GIGABYTE Control Center and classified as critical . Impacted is an unknown function of the component Performance Library . The manipulation leads to deserialization.…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-3716 | ESET Protect prior 12.1.1.0 response discrepancy (EUVD-2025-209122)

A vulnerability was found in ESET Protect and classified as problematic . The affected element is an unknown function. The manipulation results in observable response discrepancy. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5128 | ArthurFiorette steam-trader 2.1.1 API Endpoint /users information disclosure

A vulnerability was found in ArthurFiorette steam-trader 2.1.1 . It has been classified as problematic . The impacted element is an unknown function of the file /users of the component API Endpoint . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-7741 | Yokogawa Electric CENTUM VP up to R5.04.20/R6.12.00/R7.01.00 hard-coded password (EUVD-2025-209116)

A vulnerability, which was classified as problematic , was found in Yokogawa Electric CENTUM VP up to R5.04.20/R6.12.00/R7.01.00 . This impacts an unknown function. The manipulation results in use of …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-0558 | parisneo lollms up to 2.1.x Endpoint /api/files/extract-text get_current_active_user improper authentication

A vulnerability has been found in parisneo lollms up to 2.1.x and classified as critical . Affected is the function get_current_active_user of the file /api/files/extract-text of the component Endpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4176 | SHAY perl up to 5.43.8 Compress Compress::Raw vulnerable third-party component (EUVD-2026-17044)

A vulnerability was found in SHAY perl up to 5.43.8 and classified as problematic . Affected by this vulnerability is the function Compress::Raw in the library Compress . Such manipulation leads to de…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-0560 | parisneo lollms up to 2.1.x export-content _download_image_to_temp server-side request forgery

A vulnerability was found in parisneo lollms up to 2.1.x . It has been classified as critical . Affected by this issue is the function _download_image_to_temp of the file /api/files/export-content . P…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-0562 | parisneo lollms up to 2.1.x respond_request authorization

A vulnerability was found in parisneo lollms up to 2.1.x . It has been declared as critical . This affects the function respond_request . Executing a manipulation can lead to incorrect authorization. …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4946 | NSA Ghidra up to 12.0.2 Binary os command injection (GHSA-mc3p-mq2p-xw6v / EUVD-2026-17042)

A vulnerability was found in NSA Ghidra up to 12.0.2 . It has been rated as critical . This vulnerability affects unknown code of the component Binary Handler . The manipulation leads to os command in…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-15036 | MLflow up to 3.8.x dbconnect_artifact_cache.py extract_archive_to_dir path traversal (EUVD-2025-209119)

A vulnerability categorized as critical has been discovered in MLflow up to 3.8.x . This issue affects the function extract_archive_to_dir of the file mlflow/pyfunc/dbconnect_artifact_cache.py . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3124 | wpchill Download Monitor Plugin up to 5.1.7 on WordPress executePayment authorization (EUVD-2026-17052)

A vulnerability identified as critical has been detected in wpchill Download Monitor Plugin up to 5.1.7 on WordPress. Impacted is the function executePayment . This manipulation causes authorization b…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-2370 | GitLab Community Edition/Enterprise Edition up to 18.8.6/18.9.2/18.10.0 parameters (EUVD-2026-17046)

A vulnerability labeled as critical has been found in GitLab Community Edition and Enterprise Edition up to 18.8.6/18.9.2/18.10.0 . The affected element is an unknown function. Such manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33691 | OWASP coreruleset up to 3.3.8/4.24.x Whitespace case sensitivity

A vulnerability marked as problematic has been reported in OWASP coreruleset up to 3.3.8/4.24.x . The impacted element is an unknown function of the component Whitespace Handler . Performing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21710 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 req.headersDistinct denial of service

A vulnerability described as problematic has been identified in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . This affects an unknown function. Executing a manipulation of the argument req.headersDis…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21711 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 UDS Server permission

A vulnerability classified as critical has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . This impacts an unknown function of the component UDS Server Handler . The manipulation leads to…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21712 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 URL node_url.cc url.format assertion

A vulnerability classified as problematic was found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . Affected is the function url.format of the file node_url.cc of the component URL Handler . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21713 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 HMAC Verification crypto_hmac.cc memcmp comparison

A vulnerability, which was classified as problematic , has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . Affected by this vulnerability is the function memcmp of the file crypto_hmac.cc…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21714 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 HTTP/2 Server resource consumption

A vulnerability, which was classified as problematic , was found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . Affected by this issue is some unknown functionality of the component HTTP2 Server . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21717 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 V8 Handler JSON.parse denial of service

A vulnerability has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 and classified as problematic . This affects the function JSON.parse of the component V8 Handler . Performing a manipulat…

VulDB Read →
← Prev 200 / 272 Next →