CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9297 articles  ·  updated every 4 hours · grows forever

9297Total
4200Full Text
Jun 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5115 | PaperCut NG/MF up to 25.0.4 Communication Channel cleartext transmission

A vulnerability marked as problematic has been reported in PaperCut NG and MF up to 25.0.4 . Affected is an unknown function of the component Communication Channel Handler . Performing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34043 | yahoo serialize-javascript up to 7.0.4 Regular Expression resource consumption (GHSA-qj8w-gfj5-8c6v)

A vulnerability described as problematic has been identified in yahoo serialize-javascript up to 7.0.4 . Affected by this vulnerability is an unknown functionality of the component Regular Expression …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34070 | langchain-ai langchain up to 1.2.21 load_prompt/load_prompt_from_config path traversal (GHSA-qh6h-p6c9-ff54)

A vulnerability classified as critical has been found in langchain-ai langchain up to 1.2.21 . Affected by this issue is the function load_prompt/load_prompt_from_config . The manipulation leads to pa…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-4146 | timwhitlock Loco Translate Plugin up to 2.8.2 on WordPress Parameter update_href cross site scripting

A vulnerability classified as problematic was found in timwhitlock Loco Translate Plugin up to 2.8.2 on WordPress. This affects an unknown part of the component Parameter Handler . The manipulation of…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34042 | nektos act up to 0.2.85 Docker Container authorization (ID 294)

A vulnerability, which was classified as critical , has been found in nektos act up to 0.2.85 . This vulnerability affects unknown code of the component Docker Container Handler . This manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-33997 | Moby up to 29.3.0 off-by-one (GHSA-pxq6-2prw-chj9)

A vulnerability, which was classified as problematic , was found in Moby up to 29.3.0 . This issue affects some unknown processing. Such manipulation leads to off-by-one. This vulnerability is traded …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-1834 | vowelweb Ibtana Plugin up to 1.2.5.7 on WordPress Shortcode ive cross site scripting

A vulnerability has been found in vowelweb Ibtana Plugin up to 1.2.5.7 on WordPress and classified as problematic . Impacted is the function ive of the component Shortcode Handler . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30877 | baserproject basercms up to 5.2.2 User Account update os command injection (GHSA-m9g7-rgfc-jcm7)

A vulnerability was found in baserproject basercms up to 5.2.2 and classified as critical . The affected element is the function update of the component User Account Handler . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30878 | baserproject basercms up to 5.2.2 Submission API improper authorization (GHSA-8cr7-r8qw-gp3c)

A vulnerability was found in baserproject basercms up to 5.2.2 . It has been classified as critical . The impacted element is an unknown function of the component Submission API . The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-21861 | baserproject basercms up to 5.2.2 exec os command injection (GHSA-qxmc-6f24-g86g)

A vulnerability was found in baserproject basercms up to 5.2.2 . It has been declared as critical . This affects the function exec . The manipulation results in os command injection. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-1877 | johnh10 Auto Post Scheduler Plugin up to 1.84 on WordPress Setting aps_options_page cross site scripting

A vulnerability was found in johnh10 Auto Post Scheduler Plugin up to 1.84 on WordPress. It has been rated as problematic . This impacts the function aps_options_page of the component Setting Handler …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-4794 | PaperCut NG/MF up to 25.0.9 cross site scripting

A vulnerability categorized as problematic has been discovered in PaperCut NG and MF up to 25.0.9 . Affected is an unknown function. Such manipulation leads to cross site scripting. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34881 | OpenStack Glance up to 29.1.0/30.1.0/31.0.0 ovf_process Image Import Plugin server-side request forgery

A vulnerability identified as critical has been detected in OpenStack Glance up to 29.1.0/30.1.0/31.0.0 . Affected by this vulnerability is an unknown functionality of the component ovf_process Image …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-27697 | baserproject basercms up to 5.2.2 Blog Post sql injection (GHSA-vh89-rjph-2g7p)

A vulnerability labeled as critical has been found in baserproject basercms up to 5.2.2 . Affected by this issue is some unknown functionality of the component Blog Post Handler . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30880 | baserproject basercms up to 5.2.2 Installer os command injection (GHSA-6hpg-8rx3-cwgv)

A vulnerability marked as critical has been reported in baserproject basercms up to 5.2.2 . This affects an unknown part of the component Installer . The manipulation leads to os command injection. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30879 | baserproject basercms up to 5.2.2 Blog Post cross site scripting (GHSA-jmq3-x8q7-j9qm)

A vulnerability described as problematic has been identified in baserproject basercms up to 5.2.2 . This vulnerability affects unknown code of the component Blog Post Handler . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-32734 | baserproject basercms up to 5.2.2 cross site scripting (GHSA-677c-xv24-crgx)

A vulnerability classified as problematic has been found in baserproject basercms up to 5.2.2 . This issue affects some unknown processing. This manipulation causes cross site scripting. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5053 | NoMachine denial of service

A vulnerability classified as critical was found in NoMachine . Impacted is an unknown function. Such manipulation leads to denial of service. This vulnerability is documented as CVE-2026-5053 . The a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5054 | NoMachine Local Privilege Escalation

A vulnerability, which was classified as problematic , has been found in NoMachine . The affected element is an unknown function. Performing a manipulation results in Local Privilege Escalation. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5055 | NoMachine uncontrolled search path

A vulnerability, which was classified as problematic , was found in NoMachine . The impacted element is an unknown function. Executing a manipulation can lead to uncontrolled search path. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-3881 | Performance Monitor Plugin up to 1.0.6 on WordPress server-side request forgery

A vulnerability has been found in Performance Monitor Plugin up to 1.0.6 on WordPress and classified as critical . This affects an unknown function. The manipulation leads to server-side request forge…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
Cisco SD-WAN Zero-Day Under Active Exploitation Grants Attackers Root-Level Control - cyberpress.org

Cisco SD-WAN Zero-Day Under Active Exploitation Grants Attackers Root-Level Control cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
Windows Shell Zero-Day Vulnerability Allows Attackers to Bypass Authentication - cyberpress.org

Windows Shell Zero-Day Vulnerability Allows Attackers to Bypass Authentication cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-31946 | OpenOlat up to 20.2.4 JWKS Endpoint JSONWebToken.parse improper authentication (GHSA-v8vp-x4q4-2vch)

A vulnerability labeled as critical has been found in OpenOlat up to 20.2.4 . Affected by this vulnerability is the function JSONWebToken.parse of the component JWKS Endpoint . Such manipulation leads…

VulDB Read →
← Prev 311 / 388 Next →