CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9331 articles  ·  updated every 4 hours · grows forever

9331Total
4200Full Text
Jun 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2025-15036 | MLflow up to 3.8.x dbconnect_artifact_cache.py extract_archive_to_dir path traversal (EUVD-2025-209119)

A vulnerability categorized as critical has been discovered in MLflow up to 3.8.x . This issue affects the function extract_archive_to_dir of the file mlflow/pyfunc/dbconnect_artifact_cache.py . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-3124 | wpchill Download Monitor Plugin up to 5.1.7 on WordPress executePayment authorization (EUVD-2026-17052)

A vulnerability identified as critical has been detected in wpchill Download Monitor Plugin up to 5.1.7 on WordPress. Impacted is the function executePayment . This manipulation causes authorization b…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-2370 | GitLab Community Edition/Enterprise Edition up to 18.8.6/18.9.2/18.10.0 parameters (EUVD-2026-17046)

A vulnerability labeled as critical has been found in GitLab Community Edition and Enterprise Edition up to 18.8.6/18.9.2/18.10.0 . The affected element is an unknown function. Such manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-33691 | OWASP coreruleset up to 3.3.8/4.24.x Whitespace case sensitivity

A vulnerability marked as problematic has been reported in OWASP coreruleset up to 3.3.8/4.24.x . The impacted element is an unknown function of the component Whitespace Handler . Performing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21710 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 req.headersDistinct denial of service

A vulnerability described as problematic has been identified in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . This affects an unknown function. Executing a manipulation of the argument req.headersDis…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21711 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 UDS Server permission

A vulnerability classified as critical has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . This impacts an unknown function of the component UDS Server Handler . The manipulation leads to…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21712 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 URL node_url.cc url.format assertion

A vulnerability classified as problematic was found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . Affected is the function url.format of the file node_url.cc of the component URL Handler . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21713 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 HMAC Verification crypto_hmac.cc memcmp comparison

A vulnerability, which was classified as problematic , has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . Affected by this vulnerability is the function memcmp of the file crypto_hmac.cc…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21714 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 HTTP/2 Server resource consumption

A vulnerability, which was classified as problematic , was found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 . Affected by this issue is some unknown functionality of the component HTTP2 Server . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21717 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 V8 Handler JSON.parse denial of service

A vulnerability has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 and classified as problematic . This affects the function JSON.parse of the component V8 Handler . Performing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
CVE-2026-21715 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 File Existence fs.realpathSync.native information disclosure

A vulnerability was found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 and classified as problematic . This vulnerability affects the function fs.realpathSync.native of the component File Existence…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
Massive Spike in Attacks Exploiting Ivanti EPMM Systems 0-day Vulnerability - CyberSecurityNews

Massive Spike in Attacks Exploiting Ivanti EPMM Systems 0-day Vulnerability CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
Beyond CVE China’s Dual Vulnerability Databases Reveal a Different Disclosure Timeline - CyberSecurityNews

Beyond CVE China’s Dual Vulnerability Databases Reveal a Different Disclosure Timeline CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
Microsoft Desktop Window Manager Zero-Day Vulnerability Exploited in the Wild - cyberpress.org

Microsoft Desktop Window Manager Zero-Day Vulnerability Exploited in the Wild cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 30, 2026
Hackers Actively Exploit Microsoft Office Zero-Day to Deliver Malware - cyberpress.org

Hackers Actively Exploit Microsoft Office Zero-Day to Deliver Malware cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-33575 | OpenClaw up to 2026.3.11 /pair insufficiently protected credentials (GHSA-7h7g-x2px-94hj / EUVD-2026-17029)

A vulnerability was found in OpenClaw up to 2026.3.11 . It has been declared as critical . Affected is an unknown function of the file /pair . Such manipulation leads to insufficiently protected crede…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-33574 | OpenClaw up to 2026.3.7 toctou (GHSA-vhwf-4x96-vqx2 / EUVD-2026-17027)

A vulnerability was found in OpenClaw up to 2026.3.7 . It has been rated as problematic . Affected by this vulnerability is an unknown functionality. Performing a manipulation results in time-of-check…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-34005 | Xiongmai AHB7008T-MH-V2 /NBD7024H-P 4.03.R11 DVRIP Protocol system Hostname os command injection

A vulnerability categorized as critical has been discovered in Xiongmai AHB7008T-MH-V2 and NBD7024H-P 4.03.R11 . Affected by this issue is the function system of the component DVRIP Protocol Handler .…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-5101 | Totolink A3300R 17.0.0cu.557_b20221024 Parameter /cgi-bin/cstecgi.cgi setLanCfg lanIp command injection

A vulnerability identified as critical has been detected in Totolink A3300R 17.0.0cu.557_b20221024 . This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-5102 | Totolink A3300R 17.0.0cu.557_b20221024 Parameter /cgi-bin/cstecgi.cgi setSmartQosCfg qos_up_bw command injection

A vulnerability labeled as critical has been found in Totolink A3300R 17.0.0cu.557_b20221024 . This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-5103 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setUPnPCfg enable command injection

A vulnerability marked as critical has been reported in Totolink A3300R 17.0.0cu.557_b20221024 . This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi . This manipulation of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-5104 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setStaticRoute ip command injection

A vulnerability described as critical has been identified in Totolink A3300R 17.0.0cu.557_b20221024 . Impacted is the function setStaticRoute of the file /cgi-bin/cstecgi.cgi . Such manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-5105 | Totolink A3300R 17.0.0cu.557_b20221024 Parameter /cgi-bin/cstecgi.cgi setVpnPassCfg pptpPassThru command injection

A vulnerability classified as critical has been found in Totolink A3300R 17.0.0cu.557_b20221024 . The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component P…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 29, 2026
CVE-2026-5106 | code-projects Exam Form Submission 1.0 /admin/update_fst.php sname cross site scripting

A vulnerability classified as problematic was found in code-projects Exam Form Submission 1.0 . The impacted element is an unknown function of the file /admin/update_fst.php . Executing a manipulation…

VulDB Read →
← Prev 318 / 389 Next →