CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8378 articles  ·  updated every 4 hours · grows forever

8378Total
4170Full Text
Jun 11, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5443 | Orthanc DICOM Server up to 1.12.10 DICOM Image Parser integer overflow

A vulnerability classified as critical was found in Orthanc DICOM Server up to 1.12.10 . The impacted element is an unknown function of the component DICOM Image Parser . Such manipulation leads to in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5445 | Orthanc DICOM Server up to 1.12.10 Image Parser DicomImageDecoder.cpp DecodeLookupTable out-of-bounds

A vulnerability, which was classified as problematic , has been found in Orthanc DICOM Server up to 1.12.10 . This affects the function DecodeLookupTable of the file DicomImageDecoder.cpp of the compo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-33005 | Apache OpenMeetings up to 8.x FileWebService insufficient permissions or privileges

A vulnerability, which was classified as problematic , was found in Apache OpenMeetings up to 8.x . This impacts an unknown function of the component FileWebService . Executing a manipulation can lead…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-33266 | Apache OpenMeetings up to 8.x a one-way hash with a predictable salt

A vulnerability has been found in Apache OpenMeetings up to 8.x and classified as problematic . Affected is an unknown function. The manipulation leads to use of a one-way hash with a predictable salt…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34020 | Apache OpenMeetings up to 8.x REST Login Endpoint username/password information disclosure

A vulnerability was found in Apache OpenMeetings up to 8.x and classified as problematic . Affected by this vulnerability is an unknown functionality of the component REST Login Endpoint . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34757 | libpng up to 1.6.56 Chunk Setter API png_set_hIST use after free

A vulnerability labeled as critical has been found in libpng up to 1.6.56 . The impacted element is the function png_set_hIST of the component Chunk Setter API . Executing a manipulation can lead to u…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34538 | Apache Airflow up to 3.1.8 DagRun Wait Endpoint exposure of resource

A vulnerability marked as critical has been reported in Apache Airflow up to 3.1.8 . This affects an unknown function of the component DagRun Wait Endpoint . The manipulation leads to exposure of reso…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34177 | Canonical LXD up to 5.0.6/5.21.4/6.7.x permissions.go isVMLowLevelOptionForbidden incomplete blacklist

A vulnerability described as critical has been identified in Canonical LXD up to 5.0.6/5.21.4/6.7.x . This impacts the function isVMLowLevelOptionForbidden of the file lxd/project/limits/permissions.g…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34178 | Canonical LXD up to 5.0.6/5.21.4/6.7.x Backup Import backup/index.yaml input validation

A vulnerability classified as critical has been found in Canonical LXD up to 5.0.6/5.21.4/6.7.x . Affected is an unknown function of the file backup/index.yaml of the component Backup Import . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34179 | Canonical LXD up to 5.0.6/5.21.4/6.7.x TLS Certificate lxd/certificates.go doCertificateUpdate Type dynamically-determined object attributes

A vulnerability classified as critical was found in Canonical LXD up to 5.0.6/5.21.4/6.7.x . Affected by this vulnerability is the function doCertificateUpdate of the file lxd/certificates.go of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5959 | GL.iNet GL-RM1/GL-RM10/GL-RM10RC/GL-RM1PE 1.8.1 Factory Reset improper authentication

A vulnerability, which was classified as critical , has been found in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1 . Affected by this issue is some unknown functionality of the component Fact…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5960 | code-projects Patient Record Management System 1.0 SQL Database Backup File /db/hcpms.sql information disclosure

A vulnerability, which was classified as problematic , was found in code-projects Patient Record Management System 1.0 . This affects an unknown part of the file /db/hcpms.sql of the component SQL Dat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5961 | code-projects Simple IT Discussion Forum 1.0 /topic-details.php post_id sql injection

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0 and classified as critical . This vulnerability affects unknown code of the file /topic-details.php . The manipulation of…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5962 | Tenda CH22 1.0.0.6(468) httpd R7WebsSecurityHandlerfunction path traversal

A vulnerability was found in Tenda CH22 1.0.0.6(468) and classified as critical . This issue affects the function R7WebsSecurityHandlerfunction of the component httpd . The manipulation results in pat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-20127: Cisco Catalyst SD-WAN Controller/Manager Zero-Day Authentication Bypass Vulnerability Exploited in the Wild - Security Boulevard

CVE-2026-20127: Cisco Catalyst SD-WAN Controller/Manager Zero-Day Authentication Bypass Vulnerability Exploited in the Wild Security Boulevard

Security Boulevard Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-1830 | davidfcarr Quick Playground Plugin up to 1.3.1 on WordPress REST API Endpoint authorization (EUVD-2026-20843)

A vulnerability, which was classified as critical , has been found in davidfcarr Quick Playground Plugin up to 1.3.1 on WordPress. This impacts an unknown function of the component REST API Endpoint .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-3568 | inspireui MStore API Plugin up to 4.18.3 on WordPress flutter-user.php update_user_profile meta_data authorization

A vulnerability, which was classified as critical , was found in inspireui MStore API Plugin up to 4.18.3 on WordPress. Affected is the function update_user_profile of the file controllers/flutter-use…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4336 | rustaurius Ultimate FAQ Accordion Plugin up to 2.4.7 on WordPress View.FAQ.class.php cross site scripting (EUVD-2026-20845)

A vulnerability has been found in rustaurius Ultimate FAQ Accordion Plugin up to 2.4.7 on WordPress and classified as problematic . Affected by this vulnerability is an unknown functionality of the fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5357 | codename065 Download Manager Plugin up to 3.3.52 on WordPress Shortcode members.php sid cross site scripting

A vulnerability was found in codename065 Download Manager Plugin up to 3.3.52 on WordPress and classified as problematic . Affected by this issue is some unknown functionality of the file members.php …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4326 | webilia Vertex Addons for Elementor Plugin up to 1.6.4 on WordPress activate_required_plugins authorization

A vulnerability was found in webilia Vertex Addons for Elementor Plugin up to 1.6.4 on WordPress. It has been classified as critical . This affects the function activate_required_plugins . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4124 | oliverfriedmann Ziggeo Plugin up to 3.1.1 on WordPress Setting current_user_can authorization

A vulnerability was found in oliverfriedmann Ziggeo Plugin up to 3.1.1 on WordPress. It has been declared as critical . This vulnerability affects the function current_user_can of the component Settin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-3574 | uxdexperts Experto Dashboard for WooCommerce Plugin up to 1.0.4 on WordPress register_setting cross site scripting

A vulnerability was found in uxdexperts Experto Dashboard for WooCommerce Plugin up to 1.0.4 on WordPress. It has been rated as problematic . This issue affects the function register_setting . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4429 | photoweblog OSM Plugin up to 6.1.15 on WordPress Shortcode file_color_list cross site scripting

A vulnerability categorized as problematic has been discovered in photoweblog OSM Plugin up to 6.1.15 on WordPress. Impacted is the function file_color_list of the component Shortcode Handler . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5742 | stiofansisland UsersWP Plugin up to 1.2.60 on WordPress cross site scripting (EUVD-2026-20846)

A vulnerability identified as problematic has been detected in stiofansisland UsersWP Plugin up to 1.2.60 on WordPress. The affected element is an unknown function. Performing a manipulation results i…

VulDB Read →
← Prev 226 / 350 Next →