CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9475 articles  ·  updated every 4 hours · grows forever

9475Total
4202Full Text
Jun 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33009 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 switch_three_phases_while_charging race condition (GHSA-33qh-fg6f-jjx5 / EUVD-2026-16250)

A vulnerability labeled as critical has been found in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . The affected element is an unknown function of the file /everest_external/nodered/{connector}/…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3108 | Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0 Messages control sequence

A vulnerability marked as problematic has been reported in Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0 . The impacted element is an unknown function of the component Messages Handler . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3112 | Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0/11.4.x AdvancedLoggingJSON path traversal (EUVD-2026-16238)

A vulnerability described as critical has been identified in Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0/11.4.x . This affects an unknown function of the component AdvancedLoggingJSON Handler . Exe…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3114 | Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0 Zip data amplification

A vulnerability classified as problematic has been found in Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0 . This impacts an unknown function of the component Zip Handler . The manipulation leads to h…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3115 | Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0 Group Retrieval Endpoint authorization

A vulnerability classified as problematic was found in Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0 . Affected is an unknown function of the component Group Retrieval Endpoint . The manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33442 | kysely up to 0.28.13 sanitizeStringLiteral sql injection (GHSA-fr9j-6mvq-frcv)

A vulnerability, which was classified as critical , has been found in kysely up to 0.28.13 . Affected by this vulnerability is the function sanitizeStringLiteral . This manipulation causes sql injecti…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33487 | russellhaering goxmldsig up to 1.5.x XML Digital Signature validateSignature signature verification

A vulnerability, which was classified as problematic , was found in russellhaering goxmldsig up to 1.5.x . Affected by this issue is the function validateSignature of the component XML Digital Signatu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33490 | h3js h3 up to 2.0.0-0/2.0.1-rc.16/2.0.2-rc.17 mount name resolution

A vulnerability has been found in h3js h3 up to 2.0.0-0/2.0.1-rc.16/2.0.2-rc.17 and classified as problematic . This affects the function mount . Performing a manipulation results in incorrectly-resol…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33468 | kysely-org kysely up to 0.28.13 CreateViewBuilder.as sanitizeStringLiteral sql injection (GHSA-8cpq-38p9-67gx)

A vulnerability was found in kysely-org kysely up to 0.28.13 and classified as critical . This vulnerability affects the function sanitizeStringLiteral of the file CreateViewBuilder.as . Executing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33496 | ory oathkeeper up to 26.1.x oauth2_introspection improper validation of unsafe equivalence in input

A vulnerability was found in ory oathkeeper up to 26.1.x . It has been classified as critical . This issue affects the function oauth2_introspection . The manipulation leads to improper validation of …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33494 | ory oathkeeper up to 26.1.x Path Normalization path traversal

A vulnerability was found in ory oathkeeper up to 26.1.x . It has been declared as critical . Impacted is an unknown function of the component Path Normalization Handler . The manipulation results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-32846 | OpenClaw up to 2026.3.23 Path Validation isLikelyLocalPath path traversal (GHSA-f6pf-4gjx-c94r / EUVD-2026-16248)

A vulnerability was found in OpenClaw up to 2026.3.23 . It has been rated as critical . The affected element is the function isLikelyLocalPath of the component Path Validation Handler . This manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-27828 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 handle_session_setup use after free (GHSA-5g3v-qc79-qqwr / EUVD-2026-16228)

A vulnerability categorized as critical has been discovered in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . The impacted element is the function ISO15118_chargerImpl::handle_session_setup . Suc…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33503 | ory kratos up to 26.1.x ListCourierMessages Admin API sql injection

A vulnerability identified as critical has been detected in ory kratos up to 26.1.x . This affects an unknown function of the component ListCourierMessages Admin API . Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-32857 | Firecrawl up to 2.8.0 Playwright Scraping Service server-side request forgery

A vulnerability labeled as critical has been found in Firecrawl up to 2.8.0 . This impacts an unknown function of the component Playwright Scraping Service . Executing a manipulation can lead to serve…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-26074 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 std::map race condition (GHSA-p3hg-vqgv-h524)

A vulnerability marked as problematic has been reported in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . Affected is the function std::map . The manipulation leads to race condition. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3116 | Mattermost Plugins up to 11.4.x Webhook Endpoint resource consumption

A vulnerability described as problematic has been identified in Mattermost Plugins up to 11.4.x . Affected by this vulnerability is an unknown functionality of the component Webhook Endpoint . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3109 | Mattermost Plugins up to 10.11.11/11.4.x Webhook Request unusual condition

A vulnerability classified as problematic has been found in Mattermost Plugins up to 10.11.11/11.4.x . Affected by this issue is some unknown functionality of the component Webhook Request Handler . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33470 | blakeblackshear frigate 0.17.0 /api/timeline authorization (GHSA-m2mg-pj9p-2r7g / EUVD-2026-16267)

A vulnerability classified as problematic was found in blakeblackshear frigate 0.17.0 . This affects an unknown part of the file /api/timeline . Such manipulation leads to missing authorization. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3113 | Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0 permission assignment

A vulnerability, which was classified as problematic , has been found in Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0 . This vulnerability affects unknown code. Performing a manipulation results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33402 | sakaiproject sakai up to 23.4/25.1 Description cross site scripting (GHSA-6g62-3898-hpvm / EUVD-2026-16256)

A vulnerability, which was classified as problematic , was found in sakaiproject sakai up to 23.4/25.1 . This issue affects some unknown processing of the component Description Handler . Executing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33469 | blakeblackshear frigate 0.17.0 Configuration /api/config/raw authorization (GHSA-26g3-f8g8-9ffh / EUVD-2026-16266)

A vulnerability has been found in blakeblackshear frigate 0.17.0 and classified as problematic . Impacted is an unknown function of the file /api/config/raw of the component Configuration Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33486 | roadiz core-bundle-dev-app up to 2.3.41/2.5.43/2.6.27/2.7.8 Environment Variable server-side request forgery

A vulnerability was found in roadiz core-bundle-dev-app up to 2.3.41/2.5.43/2.6.27/2.7.8 and classified as critical . The affected element is an unknown function of the component Environment Variable …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33504 | ory hydra up to 26.1.x Admin API sql injection

A vulnerability was found in ory hydra up to 26.1.x . It has been classified as critical . The impacted element is an unknown function of the component Admin API . This manipulation causes sql injecti…

VulDB Read →
← Prev 337 / 395 Next →