CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9328 articles  ·  updated every 4 hours · grows forever

9328Total
4200Full Text
Jun 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33028 | 0xJacky nginx-ui up to 2.3.3 app.ini race condition (GHSA-m468-xcm6-fxg4)

A vulnerability categorized as problematic has been discovered in 0xJacky nginx-ui up to 2.3.3 . This vulnerability affects unknown code of the file app.ini . Such manipulation leads to race condition…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33029 | 0xJacky nginx-ui up to 2.3.3 Web Interface denial of service (GHSA-cp8r-8jvw-v3qg)

A vulnerability identified as problematic has been detected in 0xJacky nginx-ui up to 2.3.3 . This issue affects some unknown processing of the component Web Interface . Performing a manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-34714 | Vim up to 9.2.0271 File os command injection

A vulnerability labeled as critical has been found in Vim up to 9.2.0271 . Impacted is an unknown function of the component File Handler . Executing a manipulation can lead to os command injection. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3502 | TrueConf Client Application Update code download

A vulnerability marked as problematic has been reported in TrueConf Client . The affected element is an unknown function of the component Application Update Handler . The manipulation leads to downloa…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33032 | 0xJacky nginx-ui up to 2.3.5 Model Context Protocol /mcp AuthRequired missing authentication (GHSA-h6c2-x2m2-mwhf)

A vulnerability described as critical has been identified in 0xJacky nginx-ui up to 2.3.5 . The impacted element is the function AuthRequired of the file /mcp of the component Model Context Protocol .…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-29925 | Invoice Ninja 5.12.46/5.12.48 CheckDatabaseRequest.php server-side request forgery

A vulnerability classified as critical has been found in Invoice Ninja 5.12.46/5.12.48 . This affects an unknown function of the file CheckDatabaseRequest.php . This manipulation causes server-side re…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-29924 | Grav CMS up to 1.7.x SVG File xml external entity reference

A vulnerability classified as problematic was found in Grav CMS up to 1.7.x . This impacts an unknown function of the component SVG File Handler . Such manipulation leads to xml external entity refere…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5176 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setSyslogCfg provided command injection

A vulnerability, which was classified as critical , has been found in Totolink A3300R 17.0.0cu.557_b20221024 . Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5177 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setWiFiBasicCfg rxRate command injection

A vulnerability, which was classified as critical , was found in Totolink A3300R 17.0.0cu.557_b20221024 . Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cg…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5178 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setIptvCfg vlanPriLan3 command injection

A vulnerability has been found in Totolink A3300R 17.0.0cu.557_b20221024 and classified as critical . Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5179 | SourceCodester Simple Doctors Appointment System 1.0 /admin/login.php Username sql injection

A vulnerability was found in SourceCodester Simple Doctors Appointment System 1.0 and classified as critical . This affects an unknown part of the file /admin/login.php . The manipulation of the argum…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5180 | SourceCodester Simple Doctors Appointment System 1.0 ajax.php?action=login2 email sql injection

A vulnerability was found in SourceCodester Simple Doctors Appointment System 1.0 . It has been classified as critical . This vulnerability affects unknown code of the file /admin/ajax.php?action=logi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5181 | SourceCodester Simple Doctors Appointment System up to 1.0 ajax.php?action=save_category img unrestricted upload

A vulnerability was found in SourceCodester Simple Doctors Appointment System up to 1.0 . It has been declared as critical . This issue affects some unknown processing of the file /doctors_appointment…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5182 | SourceCodester Teacher Record System 1.0 Parameter searchteacher sql injection

A vulnerability was found in SourceCodester Teacher Record System 1.0 . It has been rated as critical . Impacted is an unknown function of the file Teacher Record System of the component Parameter Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5183 | TRENDnet TEW-713RE up to 1.02 /goform/addRouting sub_421494 dest command injection

A vulnerability categorized as critical has been discovered in TRENDnet TEW-713RE up to 1.02 . The affected element is the function sub_421494 of the file /goform/addRouting . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5184 | TRENDnet TEW-713RE up to 1.02 /goform/setSysAdm admuser command injection

A vulnerability identified as critical has been detected in TRENDnet TEW-713RE up to 1.02 . The impacted element is an unknown function of the file /goform/setSysAdm . The manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5185 | Nothings stb_image up to 2.30 Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflow

A vulnerability labeled as critical has been found in Nothings stb_image up to 2.30 . This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5186 | Nothings stb up to 2.30 Multi-frame GIF File stb_image.h stbi__load_gif_main double free

A vulnerability marked as critical has been reported in Nothings stb up to 2.30 . This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2018-25230 | Eusing Free IP Switcher 3.1 Computer Name out-of-bounds write (Exploit 46382 / EUVD-2018-21719)

A vulnerability classified as critical has been found in Eusing Free IP Switcher 3.1 . This issue affects some unknown processing. Performing a manipulation of the argument Computer Name results in ou…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2018-25231 | HeidiSQL 9.5.0.5196 file path filename control (Exploit 45806 / EUVD-2018-21720)

A vulnerability classified as problematic was found in HeidiSQL 9.5.0.5196 . Impacted is an unknown function. Executing a manipulation of the argument file path can lead to improper control of filenam…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2018-25232 | Softros LAN Messenger 9.2 Parameter Log Files Location Custom Path improper validation of specified index, position, or offset in input (Exploit 45781 / EUVD-2018-21722)

A vulnerability, which was classified as problematic , has been found in Softros LAN Messenger 9.2 . The affected element is an unknown function of the component Parameter Handler . The manipulation o…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2018-25234 | SmartFTP Client 9.0.2615.0 Parameter Host connection return of pointer value outside of expected range (Exploit 45759 / EUVD-2018-21726)

A vulnerability, which was classified as problematic , was found in SmartFTP Client 9.0.2615.0 . The impacted element is an unknown function of the component Parameter Handler . The manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2018-25233 | WebDrive 18.00.5057 Connection Test Username parameters (Exploit 45761 / EUVD-2018-21724)

A vulnerability has been found in WebDrive 18.00.5057 and classified as problematic . This affects an unknown function of the component Connection Test Handler . This manipulation of the argument User…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4266 | WatchGuard Fireware OS up to 12.11.8/2026.1.2 Access Portal deserialization (wgsa-2026-00007 / EUVD-2026-17079)

A vulnerability was found in WatchGuard Fireware OS up to 12.11.8/2026.1.2 and classified as critical . This impacts an unknown function of the component Access Portal . Such manipulation leads to des…

VulDB Read →
← Prev 315 / 389 Next →