CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8808 articles  ·  updated every 4 hours · grows forever

8808Total
4182Full Text
Jun 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-4350 | Perfmatters Plugin up to 2.5.9.1 on WordPress PMCS::action_handler delete path traversal

A vulnerability described as critical has been identified in Perfmatters Plugin up to 2.5.9.1 on WordPress. Affected by this vulnerability is the function PMCS::action_handler . The manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2025-7024 | Airbus PSS TETRA Connectivity Server 7.0 on Windows File default permission

A vulnerability classified as critical has been found in Airbus PSS TETRA Connectivity Server 7.0 on Windows. Affected by this issue is some unknown functionality of the component File Handler . This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
MSHTML Zero-Day in Windows Exploited by APT28 Prior to Feb 2026 Security Update - gbhackers.com

MSHTML Zero-Day in Windows Exploited by APT28 Prior to Feb 2026 Security Update gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-33105 | Microsoft Azure Kubernetes Service improper authorization (EUVD-2026-18562)

A vulnerability was found in Microsoft Azure Kubernetes Service . It has been declared as critical . Affected is an unknown function. Such manipulation leads to improper authorization. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-32173 | Microsoft Azure SRE Agent Gateway improper authentication (EUVD-2026-18558)

A vulnerability was found in Microsoft Azure SRE Agent Gateway . It has been rated as critical . Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-32211 | Microsoft Azure Web Apps MCP Server missing authentication (EUVD-2026-18560)

A vulnerability categorized as critical has been discovered in Microsoft Azure Web Apps . Affected by this issue is some unknown functionality of the component MCP Server . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-32213 | Microsoft Azure AI Foundry improper authorization (EUVD-2026-18561)

A vulnerability identified as critical has been detected in Microsoft Azure AI Foundry . This affects an unknown part. The manipulation leads to improper authorization. This vulnerability is traded as…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-26135 | Microsoft Azure Custom Locations Resource Provider server-side request forgery

A vulnerability labeled as critical has been found in Microsoft Azure Custom Locations Resource Provider . This vulnerability affects unknown code. The manipulation results in server-side request forg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-33107 | Microsoft Azure Databricks server-side request forgery (EUVD-2026-18564)

A vulnerability marked as critical has been reported in Microsoft Azure Databricks . This issue affects some unknown processing. This manipulation causes server-side request forgery. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5462 | Wahoo Fitness SYSTM App up to 7.2.1 on Android com.WahooFitness.SYSTM BuildConfig.java SEGMENT_WRITE_KEY hard-coded key

A vulnerability described as problematic has been identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android. Impacted is an unknown function of the file com/WahooFitness/SYSTM/BuildConfig.java of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
APT28 Exploits MSHTML Zero-Day Ahead of February 2026 Patch Tuesday - cyberpress.org

APT28 Exploits MSHTML Zero-Day Ahead of February 2026 Patch Tuesday cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34758 | oneuptime up to 10.0.41 Notification missing authentication (GHSA-q253-6wcm-h8hp)

A vulnerability was found in oneuptime up to 10.0.41 and classified as critical . This affects an unknown part of the component Notification Handler . Such manipulation leads to missing authentication…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34759 | oneuptime up to 10.0.41 API Endpoint /notification/ authorization (GHSA-6wc5-rhvj-cx7f)

A vulnerability was found in oneuptime up to 10.0.41 . It has been classified as problematic . This vulnerability affects unknown code of the file /notification/ of the component API Endpoint . Perfor…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2025-15620 | Belden Hirschmann HiOS Switch Platform up to 09.4.05/10.3.01 Web Interface missing authentication

A vulnerability was found in Belden Hirschmann HiOS Switch Platform up to 09.4.05/10.3.01 . It has been declared as critical . This issue affects some unknown processing of the component Web Interface…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2024-14033 | Belden Hirschmann HiLCOS BAT-R up to 10.34.6313 HiLCOS Web Interface heap-based overflow (EUVD-2024-55531)

A vulnerability was found in Belden Hirschmann HiLCOS BAT-R, Hirschmann HiLCOS BAT-F, Hirschmann HiLCOS BAT450-F, Hirschmann HiLCOS BAT867-R, Hirschmann HiLCOS BAT867-F, Hirschmann HiLCOS WLC and Hirs…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34761 | ellanetworks core up to 1.7.x NGAP Handover Failure Message null pointer dereference (GHSA-6gm8-3g4h-w82m)

A vulnerability categorized as problematic has been discovered in ellanetworks core up to 1.7.x . The affected element is an unknown function of the component NGAP Handover Failure Message Handler . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34762 | ellanetworks core up to 1.7.x JSON Request Body /api/v1/subscriber/ improper authentication (GHSA-xw45-cc32-442f)

A vulnerability identified as critical has been detected in ellanetworks core up to 1.7.x . The impacted element is an unknown function of the file /api/v1/subscriber/ of the component JSON Request Bo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34834 | bulwarkmail webmail up to 1.4.9 Setting verifyIdentity improper authentication (GHSA-4356-876g-rfmh)

A vulnerability labeled as critical has been found in bulwarkmail webmail up to 1.4.9 . This affects the function verifyIdentity of the component Setting Handler . Such manipulation leads to improper …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34743 | tukaani-project xz up to 5.8.2 Compression lzma_index_decoder heap-based overflow (GHSA-x872-m794-cxhv)

A vulnerability marked as critical has been reported in tukaani-project xz up to 5.8.2 . This impacts the function lzma_index_decoder of the component Compression Handler . Performing a manipulation r…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34745 | ShaneIsrael fireshare up to 1.5.2 Endpoint /api/uploadChunked checkSum path traversal (GHSA-fvvp-rj8g-c7gc)

A vulnerability described as critical has been identified in ShaneIsrael fireshare up to 1.5.2 . Affected is an unknown function of the file /api/uploadChunked of the component Endpoint . Executing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34736 | openedx openedx-platform REST API /api/user/v1/accounts/ activation_key improper authentication (GHSA-m6rg-rp98-4crw)

A vulnerability classified as critical has been found in openedx openedx-platform . Affected by this vulnerability is an unknown functionality of the file /api/user/v1/accounts/ of the component REST …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34848 | hoppscotch 2023.4.5/2023.12.6/2026.2.0/2026.2.1 Display Name cross site scripting (GHSA-vw93-4m6p-ccm9)

A vulnerability classified as problematic was found in hoppscotch 2023.4.5/2023.12.6/2026.2.0/2026.2.1 . Affected by this issue is some unknown functionality of the component Display Name Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5429 | Amazon AWS Kiro IDE up to 0.8.139 Kiro Agent Webview cross site scripting

A vulnerability, which was classified as problematic , has been found in Amazon AWS Kiro IDE up to 0.8.139 . This affects an unknown part of the component Kiro Agent Webview . This manipulation causes…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34825 | nocobase NocoBase Plugin up to 2.0.29 Parameter getParsedValue sql injection (GHSA-vx58-fwwq-5g8j)

A vulnerability, which was classified as critical , was found in nocobase NocoBase Plugin up to 2.0.29 . This vulnerability affects the function getParsedValue of the component Parameter Handler . Suc…

VulDB Read →
← Prev 274 / 367 Next →