CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9505 articles  ·  updated every 4 hours · grows forever

9505Total
4202Full Text
Jun 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4278 | specialk Simple Download Counter Plugin up to 2.3 on WordPress Shortcode text/cat cross site scripting

A vulnerability has been found in specialk Simple Download Counter Plugin up to 2.3 on WordPress and classified as problematic . Impacted is an unknown function of the component Shortcode Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4281 | trainingbusinesspros FormLift for Infusionsoft Web Forms Plugin up to 7.5.21 on WordPress connect/listen_for_tokens authorization

A vulnerability was found in trainingbusinesspros FormLift for Infusionsoft Web Forms Plugin up to 7.5.21 on WordPress and classified as critical . The affected element is the function connect/listen_…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4329 | specialk Blackhole for Bad Bots Plugin up to 3.8 on WordPress sanitize_text_field cross site scripting

A vulnerability was found in specialk Blackhole for Bad Bots Plugin up to 3.8 on WordPress. It has been classified as problematic . The impacted element is the function sanitize_text_field . Performin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4389 | hupe13 DSGVO Snippet for Leaflet Map and its Extensions Plugin Shortcode leafext-cookie-time/leafext-delete-cookie cross site scripting

A vulnerability was found in hupe13 DSGVO Snippet for Leaflet Map and its Extensions Plugin up to 3.1 on WordPress. It has been declared as problematic . This affects the function leafext-cookie-time/…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4075 | xenioushk BWL Advanced FAQ Manager Lite Plugin up to 1.1.1 on WordPress Shortcode esc_attr cross site scripting

A vulnerability was found in xenioushk BWL Advanced FAQ Manager Lite Plugin up to 1.1.1 on WordPress. It has been rated as problematic . This impacts the function esc_attr of the component Shortcode H…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33932 | OpenEMR up to 8.0.0.3 CCDA Document Preview cross site scripting (GHSA-g77x-9p3x-2j8f)

A vulnerability categorized as problematic has been discovered in OpenEMR up to 8.0.0.3 . Affected is an unknown function of the component CCDA Document Preview . The manipulation results in cross sit…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33348 | OpenEMR up to 8.0.0.3 Notes cross site scripting (GHSA-6ch2-p26g-x33h)

A vulnerability identified as problematic has been detected in OpenEMR up to 8.0.0.3 . Affected by this vulnerability is an unknown functionality of the component Notes Handler . This manipulation cau…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33933 | OpenEMR up to 8.0.0.2 cross site scripting (GHSA-9qh7-cfq4-j7c3)

A vulnerability labeled as problematic has been found in OpenEMR . Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. This vulnerability is uniquely…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2025-15101 | ASUS Router 3.0.0.6_102 Web Management Interface cross-site request forgery

A vulnerability marked as problematic has been reported in ASUS Router 3.0.0.6_102 . This affects an unknown part of the component Web Management Interface . Performing a manipulation results in cross…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-1206 | elemntor Elementor Website Builder Plugin up to 3.35.7 on WordPress Template is_allowed_to_read_template authorization

A vulnerability described as problematic has been identified in elemntor Elementor Website Builder Plugin up to 3.35.7 on WordPress. This vulnerability affects the function is_allowed_to_read_template…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33416 | pnggroup libpng up to 1.6.55 PNG File Parser png_set_tRNS/png_set_PLTE use after free

A vulnerability classified as critical has been found in pnggroup libpng up to 1.6.55 . This issue affects the function png_set_tRNS/png_set_PLTE of the component PNG File Parser . The manipulation le…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33636 | pnggroup libpng up to 1.6.36 out-of-bounds write

A vulnerability classified as critical was found in pnggroup libpng up to 1.6.36 . Impacted is an unknown function. The manipulation results in out-of-bounds write. This vulnerability is identified as…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4875 | itsourcecode Free Hotel Reservation System 1.0 index.php?view=add image unrestricted upload

A vulnerability, which was classified as critical , has been found in itsourcecode Free Hotel Reservation System 1.0 . The affected element is an unknown function of the file /admin/mod_amenities/inde…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4876 | itsourcecode Free Hotel Reservation System 1.0 index.php?view=editpic ID sql injection

A vulnerability, which was classified as critical , was found in itsourcecode Free Hotel Reservation System 1.0 . The impacted element is an unknown function of the file /admin/mod_amenities/index.php…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4877 | itsourcecode Payroll Management System up to 1.0 /index.php page cross site scripting

A vulnerability has been found in itsourcecode Payroll Management System up to 1.0 and classified as problematic . This affects an unknown function of the file /index.php . Performing a manipulation o…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2025-15433 | Shared Files Plugin up to 1.7.57 on WordPress path traversal

A vulnerability was found in Shared Files Plugin up to 1.7.57 on WordPress and classified as critical . This impacts an unknown function. Executing a manipulation can lead to path traversal. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2025-15488 | Responsive Plus Plugin up to 3.4.2 on WordPress Shortcode content_rech_data authorization

A vulnerability was found in Responsive Plus Plugin up to 3.4.2 on WordPress. It has been classified as critical . Affected is the function update_responsive_woo_free_shipping_left_shortcode of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4247 | FreeBSD ACK tcp_respond memory leak

A vulnerability was found in FreeBSD . It has been declared as problematic . Affected by this vulnerability is the function tcp_respond of the component ACK Handler . The manipulation results in memor…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-4652 | FreeBSD NVMe null pointer dereference

A vulnerability was found in FreeBSD . It has been rated as problematic . Affected by this issue is some unknown functionality of the component NVMe . This manipulation causes null pointer dereference…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-1430 | Syed Balkhi WP Lightbox 2 Plugin up to 3.0.6 on WordPress Setting cross site scripting

A vulnerability categorized as problematic has been discovered in Syed Balkhi WP Lightbox 2 Plugin up to 3.0.6 on WordPress. This affects an unknown part of the component Setting Handler . Such manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-1890 | LeadConnector Plugin up to 3.0.21 on WordPress authorization

A vulnerability identified as critical has been detected in LeadConnector Plugin up to 3.0.21 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in missing author…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
PoC Released for Critical Chrome 0-day Vulnerability Exploited in the Wild - CyberSecurityNews

PoC Released for Critical Chrome 0-day Vulnerability Exploited in the Wild CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities - The Hacker News

Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2025-14917 | IBM WebSphere Application Server up to 26.0.0.3 Setting default password

A vulnerability marked as critical has been reported in IBM WebSphere Application Server up to 26.0.0.3 . This impacts an unknown function of the component Setting Handler . The manipulation leads to …

VulDB Read →
← Prev 341 / 397 Next →