CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9328 articles  ·  updated every 4 hours · grows forever

9328Total
4200Full Text
Jun 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3945 | tinyproxy up to 1.11.3 Chunk strtol integer overflow (EUVD-2026-17066)

A vulnerability was found in tinyproxy up to 1.11.3 . It has been classified as problematic . This issue affects the function strtol of the component Chunk Handler . The manipulation leads to integer …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-15379 | MLflow up to 3.8.1 Model _install_model_dependencies_to_env command injection (EUVD-2025-209121)

A vulnerability was found in MLflow up to 3.8.1 . It has been declared as critical . Impacted is the function _install_model_dependencies_to_env of the component Model Handler . The manipulation resul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5119 | GNOME libsoup HTTP Proxy cleartext transmission (EUVD-2026-17062)

A vulnerability was found in GNOME libsoup . It has been rated as problematic . The affected element is an unknown function of the component HTTP Proxy Handler . This manipulation causes cleartext tra…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-2328 | WAGO Device Sphere/Solution Builder up to 1.2.1 improper filtering of special elements (VDE-2026-010 / EUVD-2026-17064)

A vulnerability categorized as critical has been discovered in WAGO Device Sphere and Solution Builder up to 1.2.1 . The impacted element is an unknown function. Such manipulation leads to improper fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5122 | osrg GoBGP up to 4.3.0 BGP OPEN Message pkg/packet/bgp/bgp.go DecodeFromBytes domainNameLen access control (ID 3343)

A vulnerability identified as problematic has been detected in osrg GoBGP up to 4.3.0 . This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5123 | osrg GoBGP up to 4.3.0 pkg/packet/bgp/bgp.go DecodeFromBytes data[1] off-by-one (ID 3342)

A vulnerability labeled as problematic has been found in osrg GoBGP up to 4.3.0 . This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go . Executing a manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5124 | osrg GoBGP up to 4.3.0 BGP Header pkg/packet/bgp/bgp.go BGPHeader.DecodeFromBytes access control (ID 3340)

A vulnerability marked as problematic has been reported in osrg GoBGP up to 4.3.0 . Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5125 | raine consult-llm-mcp up to 2.5.3 src/server.ts child_process.execSync git_diff.base_ref/git_diff.files os command injection

A vulnerability described as critical has been identified in raine consult-llm-mcp up to 2.5.3 . Affected by this vulnerability is the function child_process.execSync of the file src/server.ts . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5126 | SourceCodester RSS Feed Parser 1.0 file_get_contents server-side request forgery

A vulnerability classified as critical has been found in SourceCodester RSS Feed Parser 1.0 . Affected by this issue is the function file_get_contents . This manipulation causes server-side request fo…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4415 | GIGABYTE Control Center up to 25.07.21.01 path traversal (EUVD-2026-17069)

A vulnerability classified as critical was found in GIGABYTE Control Center up to 25.07.21.01 . This affects an unknown part. Such manipulation leads to relative path traversal. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5121 | libarchive on 32-bit ISO9660 Image Parser heap-based overflow

A vulnerability, which was classified as critical , has been found in libarchive on 32-bit. This vulnerability affects unknown code of the component ISO9660 Image Parser . Performing a manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-25704 | pop-os cosmic-greeter privilege dropping (ID 426 / EUVD-2026-17067)

A vulnerability, which was classified as problematic , was found in pop-os cosmic-greeter . This issue affects some unknown processing. Executing a manipulation can lead to privilege dropping / loweri…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4416 | GIGABYTE Control Center prior 25.12.31.01 Performance Library deserialization

A vulnerability has been found in GIGABYTE Control Center and classified as critical . Impacted is an unknown function of the component Performance Library . The manipulation leads to deserialization.…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-3716 | ESET Protect prior 12.1.1.0 response discrepancy (EUVD-2025-209122)

A vulnerability was found in ESET Protect and classified as problematic . The affected element is an unknown function. The manipulation results in observable response discrepancy. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-5128 | ArthurFiorette steam-trader 2.1.1 API Endpoint /users information disclosure

A vulnerability was found in ArthurFiorette steam-trader 2.1.1 . It has been classified as problematic . The impacted element is an unknown function of the file /users of the component API Endpoint . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-7741 | Yokogawa Electric CENTUM VP up to R5.04.20/R6.12.00/R7.01.00 hard-coded password (EUVD-2025-209116)

A vulnerability, which was classified as problematic , was found in Yokogawa Electric CENTUM VP up to R5.04.20/R6.12.00/R7.01.00 . This impacts an unknown function. The manipulation results in use of …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-0558 | parisneo lollms up to 2.1.x Endpoint /api/files/extract-text get_current_active_user improper authentication

A vulnerability has been found in parisneo lollms up to 2.1.x and classified as critical . Affected is the function get_current_active_user of the file /api/files/extract-text of the component Endpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4176 | SHAY perl up to 5.43.8 Compress Compress::Raw vulnerable third-party component (EUVD-2026-17044)

A vulnerability was found in SHAY perl up to 5.43.8 and classified as problematic . Affected by this vulnerability is the function Compress::Raw in the library Compress . Such manipulation leads to de…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-0560 | parisneo lollms up to 2.1.x export-content _download_image_to_temp server-side request forgery

A vulnerability was found in parisneo lollms up to 2.1.x . It has been classified as critical . Affected by this issue is the function _download_image_to_temp of the file /api/files/export-content . P…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-0562 | parisneo lollms up to 2.1.x respond_request authorization

A vulnerability was found in parisneo lollms up to 2.1.x . It has been declared as critical . This affects the function respond_request . Executing a manipulation can lead to incorrect authorization. …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-4946 | NSA Ghidra up to 12.0.2 Binary os command injection (GHSA-mc3p-mq2p-xw6v / EUVD-2026-17042)

A vulnerability was found in NSA Ghidra up to 12.0.2 . It has been rated as critical . This vulnerability affects unknown code of the component Binary Handler . The manipulation leads to os command in…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-15036 | MLflow up to 3.8.x dbconnect_artifact_cache.py extract_archive_to_dir path traversal (EUVD-2025-209119)

A vulnerability categorized as critical has been discovered in MLflow up to 3.8.x . This issue affects the function extract_archive_to_dir of the file mlflow/pyfunc/dbconnect_artifact_cache.py . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3124 | wpchill Download Monitor Plugin up to 5.1.7 on WordPress executePayment authorization (EUVD-2026-17052)

A vulnerability identified as critical has been detected in wpchill Download Monitor Plugin up to 5.1.7 on WordPress. Impacted is the function executePayment . This manipulation causes authorization b…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-2370 | GitLab Community Edition/Enterprise Edition up to 18.8.6/18.9.2/18.10.0 parameters (EUVD-2026-17046)

A vulnerability labeled as critical has been found in GitLab Community Edition and Enterprise Edition up to 18.8.6/18.9.2/18.10.0 . The affected element is an unknown function. Such manipulation leads…

VulDB Read →
← Prev 317 / 389 Next →