CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8487 articles  ·  updated every 4 hours · grows forever

8487Total
4176Full Text
Jun 12, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5506 | lucascaro Wavr Plugin up to 0.2.6 on WordPress Shortcode wave cross site scripting

A vulnerability classified as problematic has been found in lucascaro Wavr Plugin up to 0.2.6 on WordPress. The impacted element is the function wave of the component Shortcode Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-5508 | theyeti WowPress Plugin up to 1.0.0 on WordPress Shortcode wowpress cross site scripting

A vulnerability classified as problematic was found in theyeti WowPress Plugin up to 1.0.0 on WordPress. This affects the function wowpress of the component Shortcode Handler . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-4141 | edckwt Quran Translations Plugin up to 1.7 on WordPress quran_playlist_options cross-site request forgery

A vulnerability, which was classified as problematic , has been found in edckwt Quran Translations Plugin up to 1.7 on WordPress. This impacts the function quran_playlist_options . This manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39362 | InvenTree 1.2.6 remote_image server-side request forgery (GHSA-m9j7-jw3m-fr22)

A vulnerability, which was classified as critical , was found in InvenTree 1.2.6 . Affected is an unknown function. Such manipulation of the argument remote_image leads to server-side request forgery.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
Google patches Chrome vulnerability with in-the-wild exploit (CVE-2026-2441) - Help Net Security

Google patches Chrome vulnerability with in-the-wild exploit (CVE-2026-2441) Help Net Security

Help Net Security Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-14857 | Semtech LR1110/LR1120/LR1121 SPI Interface write-what-where condition (psa-2026-001)

A vulnerability described as problematic has been identified in Semtech LR1110, LR1120 and LR1121 . The impacted element is an unknown function of the component SPI Interface . Such manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39400 | jhuckaby Cronicle up to 0.9.110 Job Details Page create_events cross site scripting (GHSA-36q6-pwxv-j545 / EUVD-2026-19923)

A vulnerability classified as problematic has been found in jhuckaby Cronicle up to 0.9.110 . This affects the function create_events of the component Job Details Page . Performing a manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39356 | drizzle-team drizzle-orm up to 0.45.1 escapeName sql injection (GHSA-gpj5-g38j-94v9)

A vulnerability classified as critical was found in drizzle-team drizzle-orm up to 0.45.1 . This impacts the function escapeName . Executing a manipulation can lead to sql injection. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39382 | dbt-labs dbt-core Comment open-issue-in-repo.yml steps.issue_comment.outputs.comment- os command injection (GHSA-5jxf-vmqr-5g82)

A vulnerability, which was classified as critical , has been found in dbt-labs dbt-core . Affected is an unknown function of the file dbt-labs/actions/blob/main/.github/workflows/open-issue-in-repo.ym…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39374 | makeplane up to 1.2.x IssueBulkUpdateDateEndpoint start_date/target_date authorization (GHSA-4q54-h4x9-m329)

A vulnerability, which was classified as problematic , was found in makeplane plane up to 1.2.x . Affected by this vulnerability is an unknown functionality of the component IssueBulkUpdateDateEndpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34080 | flatpak xdg-dbus-proxy up to 0.1.6 improper validation of unsafe equivalence in input (GHSA-vjp5-hjfm-7677)

A vulnerability has been found in flatpak xdg-dbus-proxy up to 0.1.6 and classified as problematic . Affected by this issue is some unknown functionality. This manipulation causes improper validation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-29181 | open-telemetry opentelemetry-go up to 1.40.x Header Field allocation of resources (GHSA-mh2q-q3fh-2475)

A vulnerability was found in open-telemetry opentelemetry-go up to 1.40.x and classified as problematic . This affects an unknown part of the component Header Field Handler . Such manipulation leads t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39364 | vitejs vite up to 7.3.1/8.0.4 Query Parameter incorrect behavior order: validate before canonicalize (GHSA-v2wj-q39q-566r)

A vulnerability was found in vitejs vite up to 7.3.1/8.0.4 . It has been classified as problematic . This vulnerability affects unknown code of the component Query Parameter Handler . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39395 | sigstore cosign up to 2.6.2/3.0.5 unusual condition (GHSA-w6c6-c85g-mmv6 / EUVD-2026-19919)

A vulnerability was found in sigstore cosign up to 2.6.2/3.0.5 . It has been declared as problematic . This issue affects some unknown processing. Executing a manipulation can lead to improper check f…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39401 | jhuckaby Cronicle up to 0.9.110 update_event authorization (GHSA-5j3v-cq96-xw6v / EUVD-2026-19925)

A vulnerability was found in jhuckaby Cronicle up to 0.9.110 . It has been rated as problematic . Impacted is the function update_event . The manipulation leads to missing authorization. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-14858 | Semtech LR1110/LR1120/LR1121 SPI Interface sensitive information in resource not removed before reuse (psa-2026-001)

A vulnerability categorized as problematic has been discovered in Semtech LR1110, LR1120 and LR1121 . The affected element is an unknown function of the component SPI Interface . The manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-14859 | Semtech LR1110/LR1120/LR1121 risky encryption (psa-2026-001)

A vulnerability identified as problematic has been detected in Semtech LR1110, LR1120 and LR1121 . The impacted element is an unknown function. This manipulation causes risky cryptographic algorithm. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39837 | Wikimedia Cargo Extension up to 3.8.6 on Mediawiki cross site scripting

A vulnerability labeled as problematic has been found in Wikimedia Cargo Extension up to 3.8.6 on Mediawiki. This affects an unknown function. Such manipulation leads to basic cross site scripting. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39361 | OpenObserve up to 0.70.3 mod.rs validate_enrichment_url server-side request forgery (GHSA-gcwf-3p7h-wm79)

A vulnerability marked as critical has been reported in OpenObserve up to 0.70.3 . This impacts the function validate_enrichment_url of the file src/handler/http/request/enrichment_table/mod.rs . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39841 | Wikimedia Cargo Extension up to 3.8.6 on Mediawiki cross site scripting (EUVD-2026-19931)

A vulnerability described as problematic has been identified in Wikimedia Cargo Extension up to 3.8.6 on Mediawiki. Affected is an unknown function. Executing a manipulation can lead to basic cross si…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-56015 | GenieACS 1.2.13 NBI API Endpoint improper authentication

A vulnerability classified as critical has been found in GenieACS 1.2.13 . Affected by this vulnerability is an unknown functionality of the component NBI API Endpoint . The manipulation leads to impr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39840 | Wikimedia Cargo Extension up to 3.8.6 on Mediawiki cross site scripting (EUVD-2026-19929)

A vulnerability classified as problematic was found in Wikimedia Cargo Extension up to 3.8.6 on Mediawiki. Affected by this issue is some unknown functionality. The manipulation results in cross site …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39397 | delmaredigital payload-puck up to 0.6.22 CRUD Endpoint createPuckPlugin authorization (EUVD-2026-19921)

A vulnerability, which was classified as critical , has been found in delmaredigital payload-puck up to 0.6.22 . This affects the function createPuckPlugin of the component CRUD Endpoint . This manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39370 | WWBN AVideo up to 26.0 aVideoEncoder.json.php downloadURL server-side request forgery (GHSA-cmcr-q4jf-p6q9)

A vulnerability, which was classified as critical , was found in WWBN AVideo up to 26.0 . This vulnerability affects unknown code of the file objects/aVideoEncoder.json.php . Such manipulation of the …

VulDB Read →
← Prev 238 / 354 Next →