CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9442 articles  ·  updated every 4 hours · grows forever

9442Total
4202Full Text
Jun 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33433 | Traefik up to 2.11.41/3.6.10 authentication spoofing

A vulnerability was found in Traefik up to 2.11.41/3.6.10 . It has been rated as critical . This affects an unknown part. The manipulation leads to authentication bypass by spoofing. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33755 | Intermesh GroupOffice up to 6.8.157/25.0.91/26.0.16 Contact/query sql injection

A vulnerability categorized as critical has been discovered in Intermesh GroupOffice up to 6.8.157/25.0.91/26.0.16 . This vulnerability affects unknown code of the file Contact/query . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-5022 | langflow-ai langflow Image /api/v1/files/images/ flow_id/file_name authorization

A vulnerability identified as problematic has been detected in langflow-ai langflow . This issue affects some unknown processing of the file /api/v1/files/images/ of the component Image Handler . This…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-27876 | Grafana Enterprise up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 Expressions Feature privilege escalation

A vulnerability labeled as problematic has been found in Grafana Enterprise up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 . Impacted is an unknown function of the component Expressions Feature . Such mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33750 | juliangruber brace-expansion up to 1.1.12/2.0.2/3.0.1/5.0.4 expand step resource consumption

A vulnerability marked as problematic has been reported in juliangruber brace-expansion up to 1.1.12/2.0.2/3.0.1/5.0.4 . The affected element is the function expand . Performing a manipulation of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4984 | botpress MediaUrlN missing encryption

A vulnerability described as problematic has been identified in botpress . The impacted element is an unknown function. Executing a manipulation of the argument MediaUrlN can lead to missing encryptio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33758 | OpenBao up to 2.5.1 OIDC/JWT callback_mode error_description cross site scripting

A vulnerability classified as problematic has been found in OpenBao up to 2.5.1 . This affects the function callback_mode of the component OIDC/JWT . The manipulation of the argument error_description…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2025-69988 | BS Producten Petcam 33.1.0.0818 Network Interface access control

A vulnerability classified as critical was found in BS Producten Petcam 33.1.0.0818 . This impacts an unknown function of the component Network Interface Handler . The manipulation results in improper…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33206 | kovidgoyal calibre up to 9.5.x path traversal

A vulnerability, which was classified as problematic , has been found in kovidgoyal calibre up to 9.5.x . Affected is an unknown function. This manipulation causes relative path traversal. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2025-61190 | DSpace JSPUI 6.5 Parameter filter_type_1 cross site scripting

A vulnerability, which was classified as problematic , was found in DSpace JSPUI 6.5 . Affected by this vulnerability is an unknown functionality of the component Parameter Handler . Such manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-28375 | Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 testdata data-source denial of service

A vulnerability has been found in Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 and classified as problematic . Affected by this issue is some unknown functionality of the component testdata data-…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-27879 | Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 Resample Query denial of service

A vulnerability was found in Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 and classified as problematic . This affects an unknown part of the component Resample Query Handler . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
Fallout from latest Ivanti zero-days spreads to nearly 100 victims - CyberScoop

Fallout from latest Ivanti zero-days spreads to nearly 100 victims CyberScoop

CyberScoop Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4957 | OpenBMB XAgent 1.0.0 API Key function_handler.py FunctionHandler.handle_tool_call api_key log file

A vulnerability marked as problematic has been reported in OpenBMB XAgent 1.0.0 . The impacted element is the function FunctionHandler.handle_tool_call of the file XAgent/function_handler.py of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4958 | OpenBMB XAgent 1.0.0 WebSocket Endpoint replayer.py ReplayServer.on_connect/ReplayServer.send_data interaction_id authorization

A vulnerability described as problematic has been identified in OpenBMB XAgent 1.0.0 . This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentServer/application/web…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4959 | OpenBMB XAgent 1.0.0 ShareServer WebSocket Endpoint share.py check_user interaction_id missing authentication

A vulnerability classified as critical has been found in OpenBMB XAgent 1.0.0 . This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServ…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4960 | Tenda AC6 15.03.05.16 POST Request /goform/WizardHandle fromWizardHandle WANT/WANS stack-based overflow

A vulnerability classified as critical was found in Tenda AC6 15.03.05.16 . Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler . Executing…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4961 | Tenda AC6 15.03.05.16 POST Request /goform/QuickIndex formQuickIndex PPPOEPassword stack-based overflow

A vulnerability, which was classified as critical , has been found in Tenda AC6 15.03.05.16 . Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4962 | UltraVNC up to 1.6.4.0 Service version.dll uncontrolled search path

A vulnerability, which was classified as problematic , was found in UltraVNC up to 1.6.4.0 . Affected by this issue is some unknown functionality in the library version.dll of the component Service . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4963 | huggingface smolagents 1.25.0.dev0 Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_augassign/evaluate_call/evaluate_with code injection

A vulnerability has been found in huggingface smolagents 1.25.0.dev0 and classified as critical . This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/lo…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4964 | letta-ai letta 0.16.4 File URL message_helper.py _convert_message_create_to_message ImageContent server-side request forgery

A vulnerability was found in letta-ai letta 0.16.4 and classified as critical . This vulnerability affects the function _convert_message_create_to_message of the file letta/helpers/message_helper.py o…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4965 | letta-ai letta 0.16.4 Incomplete Fix CVE-2025-6101 ast_parsers.py resolve_type eval injection

A vulnerability was found in letta-ai letta 0.16.4 . It has been classified as critical . This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incom…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4966 | itsourcecode Free Hotel Reservation System 1.0 index.php?view=edit ID sql injection

A vulnerability was found in itsourcecode Free Hotel Reservation System 1.0 . It has been declared as critical . Impacted is an unknown function of the file /admin/mod_room/index.php?view=edit . Execu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-27856 | Open-Xchange OX Dovecot Pro up to 2.3.0 Doveadm Http Service improper authentication (adv-2026-0001)

A vulnerability was found in Open-Xchange OX Dovecot Pro up to 2.3.0 . It has been rated as critical . The affected element is an unknown function of the component Doveadm Http Service . The manipulat…

VulDB Read →
← Prev 331 / 394 Next →