CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8412 articles  ·  updated every 4 hours · grows forever

8412Total
4173Full Text
Jun 11, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-20127: Cisco Catalyst SD-WAN Controller/Manager Zero-Day Authentication Bypass Vulnerability Exploited in the Wild - Security Boulevard

CVE-2026-20127: Cisco Catalyst SD-WAN Controller/Manager Zero-Day Authentication Bypass Vulnerability Exploited in the Wild Security Boulevard

Security Boulevard Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-1830 | davidfcarr Quick Playground Plugin up to 1.3.1 on WordPress REST API Endpoint authorization (EUVD-2026-20843)

A vulnerability, which was classified as critical , has been found in davidfcarr Quick Playground Plugin up to 1.3.1 on WordPress. This impacts an unknown function of the component REST API Endpoint .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-3568 | inspireui MStore API Plugin up to 4.18.3 on WordPress flutter-user.php update_user_profile meta_data authorization

A vulnerability, which was classified as critical , was found in inspireui MStore API Plugin up to 4.18.3 on WordPress. Affected is the function update_user_profile of the file controllers/flutter-use…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4336 | rustaurius Ultimate FAQ Accordion Plugin up to 2.4.7 on WordPress View.FAQ.class.php cross site scripting (EUVD-2026-20845)

A vulnerability has been found in rustaurius Ultimate FAQ Accordion Plugin up to 2.4.7 on WordPress and classified as problematic . Affected by this vulnerability is an unknown functionality of the fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5357 | codename065 Download Manager Plugin up to 3.3.52 on WordPress Shortcode members.php sid cross site scripting

A vulnerability was found in codename065 Download Manager Plugin up to 3.3.52 on WordPress and classified as problematic . Affected by this issue is some unknown functionality of the file members.php …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4326 | webilia Vertex Addons for Elementor Plugin up to 1.6.4 on WordPress activate_required_plugins authorization

A vulnerability was found in webilia Vertex Addons for Elementor Plugin up to 1.6.4 on WordPress. It has been classified as critical . This affects the function activate_required_plugins . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4124 | oliverfriedmann Ziggeo Plugin up to 3.1.1 on WordPress Setting current_user_can authorization

A vulnerability was found in oliverfriedmann Ziggeo Plugin up to 3.1.1 on WordPress. It has been declared as critical . This vulnerability affects the function current_user_can of the component Settin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-3574 | uxdexperts Experto Dashboard for WooCommerce Plugin up to 1.0.4 on WordPress register_setting cross site scripting

A vulnerability was found in uxdexperts Experto Dashboard for WooCommerce Plugin up to 1.0.4 on WordPress. It has been rated as problematic . This issue affects the function register_setting . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4429 | photoweblog OSM Plugin up to 6.1.15 on WordPress Shortcode file_color_list cross site scripting

A vulnerability categorized as problematic has been discovered in photoweblog OSM Plugin up to 6.1.15 on WordPress. Impacted is the function file_color_list of the component Shortcode Handler . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5742 | stiofansisland UsersWP Plugin up to 1.2.60 on WordPress cross site scripting (EUVD-2026-20846)

A vulnerability identified as problematic has been detected in stiofansisland UsersWP Plugin up to 1.2.60 on WordPress. The affected element is an unknown function. Performing a manipulation results i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40024 | sleuthkit The Sleuth Kit up to 4.14.0 tsk_recover path traversal

A vulnerability classified as critical has been found in sleuthkit The Sleuth Kit up to 4.14.0 . Affected by this issue is the function tsk_recover . This manipulation causes path traversal. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40025 | sleuthkit The Sleuth Kit up to 4.14.0 APFS File Parser wrapped_key_parser out-of-bounds

A vulnerability classified as critical was found in sleuthkit The Sleuth Kit up to 4.14.0 . This affects the function wrapped_key_parser of the component APFS File Parser . Such manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40026 | sleuthkit The Sleuth Kit up to 4.14.0 Image Parser parse_susp len_id/len_des/len_src out-of-bounds

A vulnerability, which was classified as problematic , has been found in sleuthkit The Sleuth Kit up to 4.14.0 . This vulnerability affects the function parse_susp of the component Image Parser . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40027 | abrignoni ALEAPP up to 3.4.0 NQ_Vault.py file_name_from path traversal

A vulnerability, which was classified as critical , was found in abrignoni ALEAPP up to 3.4.0 . This issue affects some unknown processing of the file NQ_Vault.py . Executing a manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39882 | open-telemetry opentelemetry-go up to 1.42.x Configured Collector Endpoint traces/metrics/logs memory allocation (GHSA-w8rr-5gcm-pp58)

A vulnerability has been found in open-telemetry opentelemetry-go up to 1.42.x and classified as problematic . Impacted is an unknown function of the file traces/metrics/logs of the component Configur…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39412 | harttle liquidjs up to 10.25.3 sort_natural information disclosure (GHSA-rv5g-f82m-qrvv)

A vulnerability was found in harttle liquidjs up to 10.25.3 and classified as problematic . The affected element is the function sort_natural . The manipulation results in information disclosure. This…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-1516 | GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 code injection

A vulnerability was found in GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . It has been classified as critical . The impacted element is an unknown function. This manipulation causes code inj…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-1752 | GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 authorization

A vulnerability was found in GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . It has been declared as problematic . This affects an unknown function. Such manipulation leads to incorrect author…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-2104 | GitLab Community Edition/Enterprise Edition up to 18.8.8/18.9.4/18.10.2 authorization

A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . It has been rated as problematic . This impacts an unknown function. Performing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-2619 | GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 Private Project authorization (EUVD-2026-20799)

A vulnerability categorized as problematic has been discovered in GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . Affected is an unknown function of the component Private Project Handler . Exe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4332 | GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 Analytics Dashboard cross site scripting (EUVD-2026-20800)

A vulnerability identified as problematic has been detected in GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . Affected by this vulnerability is an unknown functionality of the component Analy…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-3199 | Sonatype Nexus Repository up to 3.90.x deserialization

A vulnerability labeled as critical has been found in Sonatype Nexus Repository up to 3.90.x . Affected by this issue is some unknown functionality. The manipulation results in deserialization. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5173 | GitLab Community Edition/Enterprise Edition up to 18.8.8/18.9.4/18.10.2 Websocket Connection routine (EUVD-2026-20802)

A vulnerability marked as critical has been reported in GitLab Community Edition and Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . This affects an unknown part of the component Websocket Connection…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40029 | khyrenz parseusbs up to 1.8 LNK File Parser parseUSBs.py os.popen os command injection

A vulnerability described as critical has been identified in khyrenz parseusbs up to 1.8 . This vulnerability affects the function os.popen of the file parseUSBs.py of the component LNK File Parser . …

VulDB Read →
← Prev 228 / 351 Next →