CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9361 articles  ·  updated every 4 hours · grows forever

9361Total
4200Full Text
Jun 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33979 | AhmedAdelFahim express-xss-sanitizer up to 2.0.1 req.body/req.query/req.headers/req.params permissive list of allowed inputs (GHSA-3843-rr4g-m8jq)

A vulnerability was found in AhmedAdelFahim express-xss-sanitizer up to 2.0.1 . It has been rated as critical . The impacted element is an unknown function. The manipulation of the argument req.body/r…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33875 | Gematik app-Authenticator up to 4.15.x verification of source (GHSA-qg87-cf56-2rmr)

A vulnerability categorized as critical has been discovered in Gematik app-Authenticator up to 4.15.x . This affects an unknown function. The manipulation results in improper verification of source of…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-34205 | home-assistant up to 17.1 Internal Docker Bridge Interface communication channel to intended endpoints (GHSA-gh5m-4m97-c95h)

A vulnerability identified as critical has been detected in home-assistant up to 17.1 . This impacts an unknown function of the component Internal Docker Bridge Interface . This manipulation causes im…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33045 | home-assistant core prior 2026.01 cross site scripting (GHSA-46j8-vpx8-6p72)

A vulnerability labeled as problematic has been found in home-assistant core . Affected is an unknown function. Such manipulation leads to cross site scripting. This vulnerability is documented as CVE…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33993 | locutusjs locutus up to 3.0.24 unserialize prototype pollution

A vulnerability marked as problematic has been reported in locutusjs locutus up to 3.0.24 . Affected by this vulnerability is the function unserialize . Performing a manipulation results in improperly…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33992 | pyLoad up to 0.5.0b3.dev92 Network Configuration server-side request forgery

A vulnerability described as critical has been identified in pyLoad . Affected by this issue is some unknown functionality of the component Network Configuration Handler . Executing a manipulation can…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-4248 | ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress usermeta:password_reset_link improper authorization

A vulnerability classified as critical has been found in ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress. This affects an unknown part. The manipulation of the argument usermeta:passwo…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33936 | tlsfuzzer python-ecdsa up to 0.19.1 ECDSA.der.remove_octet_string denial of service (EUVD-2026-16856)

A vulnerability classified as problematic was found in tlsfuzzer python-ecdsa up to 0.19.1 . This vulnerability affects the function ECDSA.der.remove_octet_string . The manipulation results in denial …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33991 | LabRedesCefetRJ WeGIA up to 3.6.6 deletar_tag.php deletar_tag $_REQUEST sql injection (EUVD-2026-16884)

A vulnerability, which was classified as critical , has been found in LabRedesCefetRJ WeGIA up to 3.6.6 . This issue affects the function deletar_tag of the file html/socio/sistema/deletar_tag.php . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33996 | benmcollins libjwt up to 3.2.x JWK Parser null pointer dereference

A vulnerability, which was classified as problematic , was found in benmcollins libjwt up to 3.2.x . Impacted is an unknown function of the component JWK Parser . Such manipulation leads to null point…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33981 | dgtlmoon changedetection.io up to 0.54.6 Environment Variable SALTED_PASS/PLAYWRIGHT_DRIVER_URL/HTTP_PROXY information disclosure (GHSA-58r7-4wr5-hfx8)

A vulnerability has been found in dgtlmoon changedetection.io up to 0.54.6 and classified as problematic . The affected element is an unknown function of the component Environment Variable Handler . P…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33989 | mobile-next mobile-mcp up to 0.0.48 Fileystem Operation saveTo/output path traversal (GHSA-3p2m-h2v6-g9mx)

A vulnerability was found in mobile-next mobile-mcp up to 0.0.48 and classified as critical . The impacted element is the function mobile_save_screenshot/mobile_start_screen_recording of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
CVE-2026-33994 | locutusjs locutus up to 3.0.24 Query prototype pollution

A vulnerability was found in locutusjs locutus up to 3.0.24 . It has been classified as problematic . This affects an unknown function of the component Query Handler . The manipulation leads to improp…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 28, 2026
Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware - CyberSecurityNews

Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-29871 | awesome-llm-apps e46690f99c3f08be80a9877fab52acacf7ab8251 FastAPI Backend podcast_router.py stream_audio path path traversal

A vulnerability was found in awesome-llm-apps e46690f99c3f08be80a9877fab52acacf7ab8251 . It has been classified as critical . This vulnerability affects the function stream_audio of the file routers/p…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-30532 | SourceCodester Online Food Ordering System 1.0 Parameter admin/view_product.php ID sql injection

A vulnerability was found in SourceCodester Online Food Ordering System 1.0 . It has been declared as critical . This issue affects some unknown processing of the file admin/view_product.php of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-30533 | SourceCodester Online Food Ordering System 1.0 Parameter admin/manage_product.php ID sql injection

A vulnerability was found in SourceCodester Online Food Ordering System 1.0 . It has been rated as critical . Impacted is an unknown function of the file admin/manage_product.php of the component Para…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-30534 | SourceCodester Food Ordering System 1.0 Parameter manage_category.php ID sql injection

A vulnerability categorized as critical has been discovered in SourceCodester Food Ordering System 1.0 . The affected element is an unknown function of the file admin/manage_category.php of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-5025 | langflow-ai langflow Endpoint /logs get_current_active_user authorization

A vulnerability identified as problematic has been detected in langflow-ai langflow . The impacted element is the function get_current_active_user of the file /logs of the component Endpoint . Perform…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-5027 | langflow-ai langflow Multipart Form Data Parser /api/v2/files filename path traversal

A vulnerability labeled as critical has been found in langflow-ai langflow . This affects an unknown function of the file /api/v2/files of the component Multipart Form Data Parser . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-32984 | Wazuh 3.5.0/4.3.10 authd out-of-bounds

A vulnerability marked as problematic has been reported in Wazuh 3.5.0/4.3.10 . This impacts an unknown function of the component authd . The manipulation leads to out-of-bounds read. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4980 | Inkscape up to 1.2 XInclude xml external entity reference

A vulnerability described as problematic has been identified in Inkscape up to 1.2 . Affected is an unknown function of the component XInclude Handler . The manipulation results in xml external entity…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-5026 | langflow-ai langflow SVG File /api/v1/files/images/ flow_id cross site scripting

A vulnerability classified as problematic has been found in langflow-ai langflow . Affected by this vulnerability is an unknown functionality of the file /api/v1/files/images/ of the component SVG Fil…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-30531 | SourceCodester Online Food Ordering System 1.0 Parameter Actions.php save_category Name sql injection

A vulnerability classified as critical was found in SourceCodester Online Food Ordering System 1.0 . Affected by this issue is the function save_category of the file Actions.php of the component Param…

VulDB Read →
← Prev 325 / 391 Next →