CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6533 articles  ·  updated every 4 hours · grows forever

6533Total
4073Full Text
May 26, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-31945 | danny-avila LibreChat up to 0.8.2/0.8.2-rc2/0.8.3-rc1 DNS Resolution server-side request forgery (GHSA-rgjq-4q58-m3q8)

A vulnerability described as critical has been identified in danny-avila LibreChat up to 0.8.2/0.8.2-rc2/0.8.3-rc1 . This impacts an unknown function of the component DNS Resolution Handler . Such man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2025-15381 | MLflow access control

A vulnerability classified as critical has been found in MLflow . Affected is an unknown function. Performing a manipulation results in improper access controls. This vulnerability is known as CVE-202…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33882 | Statamic CMS up to 5.73.15/6.7.1 Markdown Preview Endpoint improper authentication (GHSA-cvh3-23vq-w7h4)

A vulnerability classified as critical was found in Statamic CMS up to 5.73.15/6.7.1 . Affected by this vulnerability is an unknown functionality of the component Markdown Preview Endpoint . Executing…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33884 | Statamic CMS up to 5.73.15/6.7.1 authorization (GHSA-8vwx-ccf6-5wg2)

A vulnerability, which was classified as problematic , has been found in Statamic CMS up to 5.73.15/6.7.1 . Affected by this issue is some unknown functionality. The manipulation leads to incorrect au…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33883 | Statamic CMS up to 5.73.15/6.7.1 user:reset_password_form cross site scripting (GHSA-3jg4-p23x-p4qx)

A vulnerability, which was classified as problematic , was found in Statamic CMS up to 5.73.15/6.7.1 . This affects an unknown part. The manipulation of the argument user:reset_password_form results i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33885 | Statamic CMS up to 5.73.15/6.7.1 redirect (GHSA-7f74-7q5w-hj4r)

A vulnerability has been found in Statamic CMS up to 5.73.15/6.7.1 and classified as problematic . This vulnerability affects unknown code. This manipulation causes open redirect. The identification o…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33886 | Statamic CMS up to 5.73.15/6.7.1 Application Configuration information disclosure (GHSA-gcqf-5x9f-hq7f)

A vulnerability was found in Statamic CMS up to 5.73.15/6.7.1 and classified as problematic . This issue affects some unknown processing of the component Application Configuration . Such manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33739 | fogproject up to 1.5.10.1812 Parameter cross site scripting (GHSA-8m2f-4x7g-p8f3)

A vulnerability was found in fogproject up to 1.5.10.1812 . It has been classified as problematic . Impacted is an unknown function of the component Parameter Handler . Performing a manipulation resul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33044 | home-assistant core prior 2026.01 cross site scripting (GHSA-r584-6283-p7xc)

A vulnerability was found in home-assistant core . It has been declared as problematic . The affected element is an unknown function. Executing a manipulation can lead to cross site scripting. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33979 | AhmedAdelFahim express-xss-sanitizer up to 2.0.1 req.body/req.query/req.headers/req.params permissive list of allowed inputs (GHSA-3843-rr4g-m8jq)

A vulnerability was found in AhmedAdelFahim express-xss-sanitizer up to 2.0.1 . It has been rated as critical . The impacted element is an unknown function. The manipulation of the argument req.body/r…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33875 | Gematik app-Authenticator up to 4.15.x verification of source (GHSA-qg87-cf56-2rmr)

A vulnerability categorized as critical has been discovered in Gematik app-Authenticator up to 4.15.x . This affects an unknown function. The manipulation results in improper verification of source of…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-34205 | home-assistant up to 17.1 Internal Docker Bridge Interface communication channel to intended endpoints (GHSA-gh5m-4m97-c95h)

A vulnerability identified as critical has been detected in home-assistant up to 17.1 . This impacts an unknown function of the component Internal Docker Bridge Interface . This manipulation causes im…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33045 | home-assistant core prior 2026.01 cross site scripting (GHSA-46j8-vpx8-6p72)

A vulnerability labeled as problematic has been found in home-assistant core . Affected is an unknown function. Such manipulation leads to cross site scripting. This vulnerability is documented as CVE…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33993 | locutusjs locutus up to 3.0.24 unserialize prototype pollution

A vulnerability marked as problematic has been reported in locutusjs locutus up to 3.0.24 . Affected by this vulnerability is the function unserialize . Performing a manipulation results in improperly…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33992 | pyLoad up to 0.5.0b3.dev92 Network Configuration server-side request forgery

A vulnerability described as critical has been identified in pyLoad . Affected by this issue is some unknown functionality of the component Network Configuration Handler . Executing a manipulation can…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-4248 | ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress usermeta:password_reset_link improper authorization (EUVD-2026-16901)

A vulnerability classified as critical has been found in ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress. This affects an unknown part. The manipulation of the argument usermeta:passwo…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33936 | tlsfuzzer python-ecdsa up to 0.19.1 ECDSA.der.remove_octet_string denial of service (EUVD-2026-16856)

A vulnerability classified as problematic was found in tlsfuzzer python-ecdsa up to 0.19.1 . This vulnerability affects the function ECDSA.der.remove_octet_string . The manipulation results in denial …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33991 | LabRedesCefetRJ WeGIA up to 3.6.6 deletar_tag.php deletar_tag $_REQUEST sql injection (EUVD-2026-16884)

A vulnerability, which was classified as critical , has been found in LabRedesCefetRJ WeGIA up to 3.6.6 . This issue affects the function deletar_tag of the file html/socio/sistema/deletar_tag.php . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33996 | benmcollins libjwt up to 3.2.x JWK Parser null pointer dereference (EUVD-2026-16899)

A vulnerability, which was classified as problematic , was found in benmcollins libjwt up to 3.2.x . Impacted is an unknown function of the component JWK Parser . Such manipulation leads to null point…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33981 | dgtlmoon changedetection.io up to 0.54.6 Environment Variable SALTED_PASS/PLAYWRIGHT_DRIVER_URL/HTTP_PROXY information disclosure (GHSA-58r7-4wr5-hfx8)

A vulnerability has been found in dgtlmoon changedetection.io up to 0.54.6 and classified as problematic . The affected element is an unknown function of the component Environment Variable Handler . P…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33989 | mobile-next mobile-mcp up to 0.0.48 Fileystem Operation saveTo/output path traversal (GHSA-3p2m-h2v6-g9mx)

A vulnerability was found in mobile-next mobile-mcp up to 0.0.48 and classified as critical . The impacted element is the function mobile_save_screenshot/mobile_start_screen_recording of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33994 | locutusjs locutus up to 3.0.24 Query prototype pollution

A vulnerability was found in locutusjs locutus up to 3.0.24 . It has been classified as problematic . This affects an unknown function of the component Query Handler . The manipulation leads to improp…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2025-15445 | Restaurant Cafeteria Plugin up to 0.4.6 on WordPress Setting authorization

A vulnerability was found in Restaurant Cafeteria Plugin up to 0.4.6 on WordPress. It has been declared as critical . This impacts an unknown function of the component Setting Handler . The manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-4987 | brainstormforce SureForms Plugin up to 2.5.2 on WordPress Setting create_payment_intent form_id improper authentication

A vulnerability was found in brainstormforce SureForms Plugin up to 2.5.2 on WordPress. It has been rated as critical . Affected is the function create_payment_intent of the component Setting Handler …

VulDB Read →
← Prev 205 / 273 Next →