CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9442 articles  ·  updated every 4 hours · grows forever

9442Total
4202Full Text
Jun 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33943 | happy-dom 15.10.2/20.0.0/20.0.2 ECMAScriptModuleCompiler code injection

A vulnerability was found in happy-dom 15.10.2/20.0.0/20.0.2 . It has been declared as critical . This affects an unknown part of the component ECMAScriptModuleCompiler . Such manipulation leads to co…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4851 | GRID::Machine 0.127 code injection

A vulnerability was found in GRID::Machine 0.127 . It has been rated as critical . This vulnerability affects unknown code. Performing a manipulation results in code injection. This vulnerability is c…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CISA Alerts on Actively Exploited Google Chromium Zero-Day - cyberpress.org

CISA Alerts on Actively Exploited Google Chromium Zero-Day cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33644 | Lychee up to 7.5.1 Domain Name PhotoUrlRule.php filter_var host server-side request forgery (GHSA-5245-4p8c-jwff)

A vulnerability classified as critical was found in Lychee up to 7.5.1 . This vulnerability affects the function filter_var of the file PhotoUrlRule.php of the component Domain Name Handler . Executin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33686 | code16 sharp up to 9.19.x Management Frame src/Utils/FileUtil.php explodeExtension path traversal (ffq-6457-8958)

A vulnerability, which was classified as critical , has been found in code16 sharp up to 9.19.x . This issue affects the function FileUtil::explodeExtension of the file src/Utils/FileUtil.php of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33635 | iCalendar up to 2.12.1 Icalendar::Values crlf injection (GHSA-pv9c-9mfh-hvxq)

A vulnerability, which was classified as problematic , was found in iCalendar up to 2.12.1 . Impacted is the function Icalendar::Values . The manipulation results in crlf injection. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3573 | Drupal AI up to 1.1.10/1.2.11 authorization (sa-contrib-2026-028)

A vulnerability has been found in Drupal AI up to 1.1.10/1.2.11 and classified as problematic . The affected element is an unknown function. This manipulation causes incorrect authorization. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33682 | Streamlit up to 1.53.x on Windows UNC realpath server-side request forgery

A vulnerability was found in Streamlit up to 1.53.x on Windows and classified as critical . The impacted element is the function realpath of the component UNC Handler . Such manipulation leads to serv…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3527 | AJAX Dashboard up to 3.0.x on Drupal missing authentication (sa-contrib-2026-022)

A vulnerability was found in AJAX Dashboard up to 3.0.x on Drupal. It has been classified as critical . This affects an unknown function. Performing a manipulation results in missing authentication. T…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3531 | OpenID Connect OAuth client up to 1.4.x on Drupal authentication bypass (sa-contrib-2026-026)

A vulnerability was found in OpenID Connect OAuth client up to 1.4.x on Drupal. It has been declared as critical . This impacts an unknown function. Executing a manipulation can lead to authentication…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3532 | OpenID Connect OAuth client up to 1.4.x on Drupal case sensitivity (sa-contrib-2026-027)

A vulnerability was found in OpenID Connect OAuth client up to 1.4.x on Drupal. It has been rated as critical . Affected is an unknown function. The manipulation leads to improper handling of case sen…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33672 | micromatch picomatch up to 2.3.1/3.0.1/4.0.3 POSIX character prototype pollution

A vulnerability categorized as critical has been discovered in micromatch picomatch up to 2.3.1/3.0.1/4.0.3 . Affected by this vulnerability is the function character of the component POSIX Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3650 | Grassroots DICOM 3.2.2 DICOM File Parser memory leak

A vulnerability identified as problematic has been detected in Grassroots DICOM 3.2.2 . Affected by this issue is some unknown functionality of the component DICOM File Parser . This manipulation caus…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2025-12805 | Red Hat OpenShift AI Llama Stack Service improper isolation or compartmentalization (RHSA-2026:2106)

A vulnerability labeled as critical has been found in Red Hat OpenShift AI . This affects an unknown part of the component Llama Stack Service . Such manipulation leads to improper isolation or compar…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3530 | OpenID Connect OAuth client up to 1.4.x on Drupal server-side request forgery (sa-contrib-2026-025)

A vulnerability marked as critical has been reported in OpenID Connect OAuth client up to 1.4.x on Drupal. This vulnerability affects unknown code. Performing a manipulation results in server-side req…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33622 | PinchTab up to 0.8.5 /wait code injection (GHSA-w5pc-m664-r62v)

A vulnerability described as critical has been identified in PinchTab up to 0.8.5 . This issue affects some unknown processing of the file /wait . Executing a manipulation can lead to code injection. …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3529 | Google Analytics GA4 up to 1.1.13 on Drupal cross site scripting (sa-contrib-2026-024)

A vulnerability classified as problematic has been found in Google Analytics GA4 up to 1.1.13 on Drupal. Impacted is an unknown function. The manipulation leads to cross site scripting. This vulnerabi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33674 | PrestaShop up to 8.2.4/9.0.x improper validation framework

A vulnerability classified as problematic was found in PrestaShop up to 8.2.4/9.0.x . The affected element is an unknown function. The manipulation results in improper use of validation framework. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3525 | File Access Fix up to 1.1.x on Drupal authorization (sa-contrib-2026-020)

A vulnerability, which was classified as critical , has been found in File Access Fix up to 1.1.x on Drupal. The impacted element is an unknown function. This manipulation causes incorrect authorizati…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3526 | File Access Fix up to 1.1.x on Drupal authorization (sa-contrib-2026-021)

A vulnerability, which was classified as critical , was found in File Access Fix up to 1.1.x on Drupal. This affects an unknown function. Such manipulation leads to incorrect authorization. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-28377 | Grafana Tempo 2.10.3 /status/config missing encryption

A vulnerability has been found in Grafana Tempo 2.10.3 and classified as problematic . This impacts an unknown function of the file /status/config . Performing a manipulation results in missing encryp…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4933 | Unpublished Node Permissions up to 1.6.x on Drupal authorization (sa-contrib-2026-029)

A vulnerability was found in Unpublished Node Permissions up to 1.6.x on Drupal and classified as critical . Affected is an unknown function. Executing a manipulation can lead to incorrect authorizati…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3622 | TP-Link TL-WR841N -/0.9.1 UPnP out-of-bounds

A vulnerability was found in TP-Link TL-WR841N -/0.9.1 . It has been classified as problematic . Affected by this vulnerability is an unknown functionality of the component UPnP . The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3528 | Calculation Fields up to 1.0.3 on Drupal cross site scripting (sa-contrib-2026-023)

A vulnerability was found in Calculation Fields up to 1.0.3 on Drupal. It has been declared as problematic . Affected by this issue is some unknown functionality. The manipulation results in cross sit…

VulDB Read →
← Prev 334 / 394 Next →