CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9327 articles  ·  updated every 4 hours · grows forever

9327Total
4200Full Text
Jun 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34060 | Shopify ruby-lsp up to 0.26.8 vscode/settings.json code injection (GHSA-c4r5-fxqw-vh93)

A vulnerability was found in Shopify ruby-lsp up to 0.26.8 . It has been classified as critical . This issue affects some unknown processing of the file vscode/settings.json . Performing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-1710 | woocommerce WooPayments Plugin up to 10.5.1 on WordPress Setting save_upe_appearance_ajax improper authorization

A vulnerability was found in woocommerce WooPayments Plugin up to 10.5.1 on WordPress. It has been declared as critical . Impacted is the function save_upe_appearance_ajax of the component Setting Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5130 | jhimross Debugger & Troubleshooter Plugin up to 1.3.2 on WordPress wp_debug_troubleshoot_simulate_user cookie cookie validation

A vulnerability was found in jhimross Debugger & Troubleshooter Plugin up to 1.3.2 on WordPress. It has been rated as critical . The affected element is the function wp_debug_troubleshoot_simulate_use…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-32714 | SciTokens up to 1.9.5 str.format sql injection (GHSA-rh5m-2482-966c)

A vulnerability categorized as critical has been discovered in SciTokens up to 1.9.5 . The impacted element is the function str.format . The manipulation results in sql injection. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-32716 | SciTokens up to 1.9.5 improper authorization (GHSA-w8fp-g9rh-34jh)

A vulnerability identified as critical has been detected in SciTokens up to 1.9.5 . This affects an unknown function. This manipulation causes improper authorization. This vulnerability is tracked as …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-32727 | SciTokens up to 1.9.6 path traversal (GHSA-3x2w-63fp-3qvw)

A vulnerability labeled as critical has been found in SciTokens up to 1.9.6 . This impacts an unknown function. Such manipulation leads to path traversal. This vulnerability is listed as CVE-2026-3272…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5115 | PaperCut NG/MF up to 25.0.4 Communication Channel cleartext transmission

A vulnerability marked as problematic has been reported in PaperCut NG and MF up to 25.0.4 . Affected is an unknown function of the component Communication Channel Handler . Performing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34043 | yahoo serialize-javascript up to 7.0.4 Regular Expression resource consumption (GHSA-qj8w-gfj5-8c6v)

A vulnerability described as problematic has been identified in yahoo serialize-javascript up to 7.0.4 . Affected by this vulnerability is an unknown functionality of the component Regular Expression …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34070 | langchain-ai langchain up to 1.2.21 load_prompt/load_prompt_from_config path traversal (GHSA-qh6h-p6c9-ff54)

A vulnerability classified as critical has been found in langchain-ai langchain up to 1.2.21 . Affected by this issue is the function load_prompt/load_prompt_from_config . The manipulation leads to pa…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-4146 | timwhitlock Loco Translate Plugin up to 2.8.2 on WordPress Parameter update_href cross site scripting

A vulnerability classified as problematic was found in timwhitlock Loco Translate Plugin up to 2.8.2 on WordPress. This affects an unknown part of the component Parameter Handler . The manipulation of…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34042 | nektos act up to 0.2.85 Docker Container authorization (ID 294)

A vulnerability, which was classified as critical , has been found in nektos act up to 0.2.85 . This vulnerability affects unknown code of the component Docker Container Handler . This manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-33997 | Moby up to 29.3.0 off-by-one (GHSA-pxq6-2prw-chj9)

A vulnerability, which was classified as problematic , was found in Moby up to 29.3.0 . This issue affects some unknown processing. Such manipulation leads to off-by-one. This vulnerability is traded …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-1834 | vowelweb Ibtana Plugin up to 1.2.5.7 on WordPress Shortcode ive cross site scripting

A vulnerability has been found in vowelweb Ibtana Plugin up to 1.2.5.7 on WordPress and classified as problematic . Impacted is the function ive of the component Shortcode Handler . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30877 | baserproject basercms up to 5.2.2 User Account update os command injection (GHSA-m9g7-rgfc-jcm7)

A vulnerability was found in baserproject basercms up to 5.2.2 and classified as critical . The affected element is the function update of the component User Account Handler . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30878 | baserproject basercms up to 5.2.2 Submission API improper authorization (GHSA-8cr7-r8qw-gp3c)

A vulnerability was found in baserproject basercms up to 5.2.2 . It has been classified as critical . The impacted element is an unknown function of the component Submission API . The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-21861 | baserproject basercms up to 5.2.2 exec os command injection (GHSA-qxmc-6f24-g86g)

A vulnerability was found in baserproject basercms up to 5.2.2 . It has been declared as critical . This affects the function exec . The manipulation results in os command injection. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-1877 | johnh10 Auto Post Scheduler Plugin up to 1.84 on WordPress Setting aps_options_page cross site scripting

A vulnerability was found in johnh10 Auto Post Scheduler Plugin up to 1.84 on WordPress. It has been rated as problematic . This impacts the function aps_options_page of the component Setting Handler …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-4794 | PaperCut NG/MF up to 25.0.9 cross site scripting

A vulnerability categorized as problematic has been discovered in PaperCut NG and MF up to 25.0.9 . Affected is an unknown function. Such manipulation leads to cross site scripting. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34881 | OpenStack Glance up to 29.1.0/30.1.0/31.0.0 ovf_process Image Import Plugin server-side request forgery

A vulnerability identified as critical has been detected in OpenStack Glance up to 29.1.0/30.1.0/31.0.0 . Affected by this vulnerability is an unknown functionality of the component ovf_process Image …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-27697 | baserproject basercms up to 5.2.2 Blog Post sql injection (GHSA-vh89-rjph-2g7p)

A vulnerability labeled as critical has been found in baserproject basercms up to 5.2.2 . Affected by this issue is some unknown functionality of the component Blog Post Handler . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30880 | baserproject basercms up to 5.2.2 Installer os command injection (GHSA-6hpg-8rx3-cwgv)

A vulnerability marked as critical has been reported in baserproject basercms up to 5.2.2 . This affects an unknown part of the component Installer . The manipulation leads to os command injection. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30879 | baserproject basercms up to 5.2.2 Blog Post cross site scripting (GHSA-jmq3-x8q7-j9qm)

A vulnerability described as problematic has been identified in baserproject basercms up to 5.2.2 . This vulnerability affects unknown code of the component Blog Post Handler . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-32734 | baserproject basercms up to 5.2.2 cross site scripting (GHSA-677c-xv24-crgx)

A vulnerability classified as problematic has been found in baserproject basercms up to 5.2.2 . This issue affects some unknown processing. This manipulation causes cross site scripting. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5053 | NoMachine denial of service

A vulnerability classified as critical was found in NoMachine . Impacted is an unknown function. Such manipulation leads to denial of service. This vulnerability is documented as CVE-2026-5053 . The a…

VulDB Read →
← Prev 312 / 389 Next →