CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5668 articles  ·  updated every 4 hours · grows forever

5668Total
4035Full Text
May 17, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 07, 2026
CVE-2026-40076 | OpenMRS up to 2.7.8/2.8.5 REST Endpoint module WebModuleUtil.startModule path traversal

A vulnerability classified as critical was found in OpenMRS up to 2.7.8/2.8.5 . Impacted is the function WebModuleUtil.startModule of the file /openmrs/ws/rest/v1/module of the component REST Endpoint…

VulDB Read →
⬡ Vulnerabilities & CVEs May 07, 2026
CVE-2026-40171 | jupyter notebook up to 7.5.5 cross site scripting

A vulnerability, which was classified as problematic , has been found in jupyter notebook up to 7.5.5 . The affected element is an unknown function. Performing a manipulation results in cross site scr…

VulDB Read →
⬡ Vulnerabilities & CVEs May 07, 2026
CISA Unveils New Initiative to Fortify America’s Critical Infrastructure
CISA Read →
⬡ Vulnerabilities & CVEs May 06, 2026
Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks - CyberSecurityNews

Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs May 06, 2026
Apache HTTP Server Vulnerability Exposes Millions to Remote Code Execution Threats - gbhackers.com

Apache HTTP Server Vulnerability Exposes Millions to Remote Code Execution Threats gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs May 06, 2026
Firefox 150 Released With Fixes for Multiple Code Execution Vulnerabilities - cyberpress.org

Firefox 150 Released With Fixes for Multiple Code Execution Vulnerabilities cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-42311 | Pillow up to 12.1.1 PSD Tile Extents integer overflow

A vulnerability has been found in Pillow and classified as problematic . This affects an unknown function of the component PSD Tile Extents Handler . This manipulation causes integer overflow. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-42295 | argoproj argo-workflows up to 4.0.4 Artifact Repository Credential insufficiently protected credentials

A vulnerability was found in argoproj argo-workflows and classified as problematic . This impacts an unknown function of the component Artifact Repository Credential Handler . Such manipulation leads …

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-42297 | argoproj argo-workflows up to 4.0.4 Sync ConfigMap Provider authorization

A vulnerability was found in argoproj argo-workflows . It has been classified as critical . Affected is an unknown function of the component Sync ConfigMap Provider . Performing a manipulation results…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-39852 | io.quarkus:quarkus-vertx-http HTTP Request /api/admin authorization

A vulnerability was found in io.quarkus:quarkus-vertx-http . It has been declared as critical . Affected by this vulnerability is an unknown functionality of the file /api/admin of the component HTTP …

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-4362 | roxnor ElementsKit Elementor Addons Plugin up to 3.8.2 on WordPress Live_Action::reset authorization (EUVD-2026-27213)

A vulnerability was found in roxnor ElementsKit Elementor Addons Plugin up to 3.8.2 on WordPress. It has been rated as critical . Affected by this issue is the function Live_Action::reset . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7832 | IObit Advanced SystemCare 19 Service ASC.exe symlink

A vulnerability categorized as critical has been discovered in IObit Advanced SystemCare 19 . This affects an unknown part of the file ASC.exe of the component Service . The manipulation results in sy…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7833 | EFM ipTIME C200 up to 1.092 ApplyRestore Endpoint /cgi/iux_set.cgi sub_408F90 RestoreFile command injection

A vulnerability identified as critical has been detected in EFM ipTIME C200 up to 1.092 . This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the component ApplyRestore …

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7834 | EFM ipTIME NAS1dual 1.5.24 misc_main.cgi get_csrf_whites stack-based overflow

A vulnerability labeled as critical has been found in EFM ipTIME NAS1dual 1.5.24 . This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi . Such manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-2729 | wpmudev Forminator Forms Plugin up to 1.52.0 on WordPress authorization (EUVD-2026-27223)

A vulnerability marked as critical has been reported in wpmudev Forminator Forms Plugin up to 1.52.0 on WordPress. Impacted is an unknown function. Performing a manipulation results in authorization b…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-3454 | edge22 GenerateBlocks Plugin up to 2.2.0 on WordPress REST Endpoint dynamic-tag-replacements ID authorization (EUVD-2026-27225)

A vulnerability described as problematic has been identified in edge22 GenerateBlocks Plugin up to 2.2.0 on WordPress. The affected element is an unknown function of the file /wp-json/generateblocks/v…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-5192 | wpmudev Forminator Forms Plugin up to 1.52.1 on WordPress File Upload file_path path traversal (EUVD-2026-27229)

A vulnerability classified as critical has been found in wpmudev Forminator Forms Plugin up to 1.52.1 on WordPress. The impacted element is the function file_path of the component File Upload . The ma…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-6180 | PaperCut NG/MF up to 24.1.8/25.0.9 toctou

A vulnerability classified as critical was found in PaperCut NG and MF up to 24.1.8/25.0.9 . This affects an unknown function. The manipulation results in time-of-check time-of-use. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-40797 | Saleswonder WebinarIgnition Plugin up to 4.08.253 on WordPress sql injection (EUVD-2026-27227)

A vulnerability, which was classified as critical , has been found in Saleswonder WebinarIgnition Plugin up to 4.08.253 on WordPress. This impacts an unknown function. This manipulation causes sql inj…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-6418 | PaperCut NG/MF up to 25.0.10 Account Synchronization absolute path traversal

A vulnerability, which was classified as problematic , was found in PaperCut NG and MF up to 25.0.10 . Affected is an unknown function of the component Account Synchronization Component . Such manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7824 | PaperCut Hive up to 2.1.x log file

A vulnerability has been found in PaperCut Hive up to 2.1.x and classified as problematic . Affected by this vulnerability is an unknown functionality. Performing a manipulation results in sensitive i…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-3359 | 10web Form Maker Plugin up to 1.15.42 on WordPress inputs sql injection

A vulnerability was found in 10web Form Maker Plugin up to 1.15.42 on WordPress and classified as critical . Affected by this issue is some unknown functionality. Executing a manipulation of the argum…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-3601 | wpeverest User Registration & Membership Plugin up to 5.1.4 on WordPress Shortcode embed_form_action authorization

A vulnerability was found in wpeverest User Registration & Membership Plugin up to 5.1.4 on WordPress. It has been classified as critical . This affects the function embed_form_action of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs May 05, 2026
CVE-2026-7844 | chatchat-space Langchain-Chatchat up to 0.3.1.3 Compatible File Service openai_routes.py missing authentication (Issue 5465)

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3 . It has been declared as critical . This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_c…

VulDB Read →
← Prev 33 / 237 Next →