CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9472 articles  ·  updated every 4 hours · grows forever

9472Total
4202Full Text
Jun 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3525 | File Access Fix up to 1.1.x on Drupal authorization (sa-contrib-2026-020)

A vulnerability, which was classified as critical , has been found in File Access Fix up to 1.1.x on Drupal. The impacted element is an unknown function. This manipulation causes incorrect authorizati…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3526 | File Access Fix up to 1.1.x on Drupal authorization (sa-contrib-2026-021)

A vulnerability, which was classified as critical , was found in File Access Fix up to 1.1.x on Drupal. This affects an unknown function. Such manipulation leads to incorrect authorization. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-28377 | Grafana Tempo 2.10.3 /status/config missing encryption

A vulnerability has been found in Grafana Tempo 2.10.3 and classified as problematic . This impacts an unknown function of the file /status/config . Performing a manipulation results in missing encryp…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4933 | Unpublished Node Permissions up to 1.6.x on Drupal authorization (sa-contrib-2026-029)

A vulnerability was found in Unpublished Node Permissions up to 1.6.x on Drupal and classified as critical . Affected is an unknown function. Executing a manipulation can lead to incorrect authorizati…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3622 | TP-Link TL-WR841N -/0.9.1 UPnP out-of-bounds

A vulnerability was found in TP-Link TL-WR841N -/0.9.1 . It has been classified as problematic . Affected by this vulnerability is an unknown functionality of the component UPnP . The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-3528 | Calculation Fields up to 1.0.3 on Drupal cross site scripting (sa-contrib-2026-023)

A vulnerability was found in Calculation Fields up to 1.0.3 on Drupal. It has been declared as problematic . Affected by this issue is some unknown functionality. The manipulation results in cross sit…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-4393 | Automated Logout up to 1.6.x/2.0.1 on Drupal cross-site request forgery (sa-contrib-2026-030)

A vulnerability was found in Automated Logout up to 1.6.x/2.0.1 on Drupal. It has been rated as problematic . This affects an unknown part. This manipulation causes cross-site request forgery. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33375 | Grafana OSS up to 11.6.14/12.1.10/12.2.8/12.3.6/12.4.1 memory allocation

A vulnerability categorized as problematic has been discovered in Grafana OSS up to 11.6.14/12.1.10/12.2.8/12.3.6/12.4.1 . This vulnerability affects unknown code. Such manipulation leads to uncontrol…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33537 | Lychee up to 7.5.0 Photo::fromUrl server-side request forgery (GHSA-vq6w-prpf-h287)

A vulnerability identified as critical has been detected in Lychee up to 7.5.0 . This issue affects the function Photo::fromUrl . Performing a manipulation results in server-side request forgery. This…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33673 | PrestaShop up to 8.2.4/9.0.x cross site scripting

A vulnerability labeled as problematic has been found in PrestaShop up to 8.2.4/9.0.x . Impacted is an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33619 | PinchTab up to 0.8.3 /tasks server-side request forgery (GHSA-xqq2-4j46-vwp7)

A vulnerability marked as critical has been reported in PinchTab up to 0.8.3 . The affected element is an unknown function of the file /tasks . The manipulation leads to server-side request forgery. T…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-29969 | staffwiki 7.0.1.19219 wff_cols_pref.css.aspx cross site scripting

A vulnerability described as problematic has been identified in staffwiki 7.0.1.19219 . The impacted element is an unknown function of the file wff_cols_pref.css.aspx . The manipulation results in cro…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33506 | ory polis up to 26.1.x cross site scripting (GHSA-3wjr-6gw8-9j22)

A vulnerability classified as problematic has been found in ory polis up to 26.1.x . This affects an unknown function. This manipulation causes improper neutralization of alternate xss syntax. The ide…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-33653 | farisc0de Uploady up to 3.1.1 Filename cross site scripting

A vulnerability classified as problematic was found in farisc0de Uploady up to 3.1.1 . This impacts an unknown function of the component Filename Handler . Such manipulation leads to cross site script…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 27, 2026
CVE-2026-30458 | Daylight Studio FuelCMS 1.5.2 Password Reset password recovery

A vulnerability, which was classified as critical , has been found in Daylight Studio FuelCMS 1.5.2 . Affected is an unknown function of the component Password Reset Handler . Performing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33732 | h3js srvx up to 0.11.12 HTTP Request name resolution

A vulnerability was found in h3js srvx up to 0.11.12 and classified as problematic . Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler . Such manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-26073 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 std::queue/std::queue heap-based overflow (GHSA-jf36-f4f9-7qc2)

A vulnerability was found in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . It has been classified as critical . Affected by this issue is the function std::queue/std::queue . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-27814 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 ac_switch_three_phases_while_charging race condition (GHSA-5528-wc53-v557)

A vulnerability was found in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . It has been declared as problematic . This affects the function ac_switch_three_phases_while_charging . Executing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-27815 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 handle_session_setup out-of-bounds write (GHSA-7wmg-crc8-6xxf)

A vulnerability was found in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . It has been rated as critical . This vulnerability affects the function ISO15118_chargerImpl::handle_session_setup . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-27816 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 handle_update_energy_transfer_modes out-of-bounds write (GHSA-gq54-j8f4-xj8c / EUVD-2026-16226)

A vulnerability categorized as critical has been discovered in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . This issue affects the function ISO15118_chargerImpl::handle_update_energy_transfer_m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-29044 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 Charger::deauthorize authorization (GHSA-gx37-p775-qf5v / EUVD-2026-16230)

A vulnerability identified as problematic has been detected in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . Impacted is the function Charger::deauthorize . This manipulation causes incorrect au…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33009 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 switch_three_phases_while_charging race condition (GHSA-33qh-fg6f-jjx5 / EUVD-2026-16250)

A vulnerability labeled as critical has been found in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . The affected element is an unknown function of the file /everest_external/nodered/{connector}/…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3108 | Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0 Messages control sequence

A vulnerability marked as problematic has been reported in Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0 . The impacted element is an unknown function of the component Messages Handler . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3112 | Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0/11.4.x AdvancedLoggingJSON path traversal (EUVD-2026-16238)

A vulnerability described as critical has been identified in Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0/11.4.x . This affects an unknown function of the component AdvancedLoggingJSON Handler . Exe…

VulDB Read →
← Prev 336 / 395 Next →