CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9828 articles  ·  updated every 4 hours · grows forever

9828Total
4226Full Text
Jun 26, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-23920 | Zabbix up to 7.0.21/7.2.14/7.4.5 Shell Command os command injection (EUVD-2026-14952)

A vulnerability classified as critical was found in Zabbix up to 7.0.21/7.2.14/7.4.5 . This impacts an unknown function of the component Shell Command Handler . Such manipulation leads to os command i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-32948 | sbt up to 1.12.6 os command injection

A vulnerability, which was classified as critical , has been found in sbt up to 1.12.6 . Affected is an unknown function. Performing a manipulation results in os command injection. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33326 | keystone up to 6.5.1 update/delete where authorization

A vulnerability, which was classified as problematic , was found in keystone up to 6.5.1 . Affected by this vulnerability is the function update/delete . Executing a manipulation of the argument where…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33329 | error311 FileRise up to 3.9.x Parameter handleUpload resumableIdentifier path traversal

A vulnerability has been found in error311 FileRise up to 3.9.x and classified as critical . Affected by this issue is the function UploadModel::handleUpload of the component Parameter Handler . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33330 | error311 FileRise up to 3.9.x Save Call authorization

A vulnerability was found in error311 FileRise up to 3.9.x and classified as critical . This affects an unknown part of the component Save Call Handler . The manipulation results in incorrect authoriz…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-29772 | withastro up to 9.x POST /_server-islands/ JSON.parse allocation of resources (GHSA-3rmj-9m5h-8fpv / EUVD-2026-14962)

A vulnerability was found in withastro astro up to 9.x . It has been classified as problematic . This vulnerability affects the function JSON.parse of the file /_server-islands/ of the component POST …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-23924 | Zabbix Agent 2 Docker Plugin up to 6.0.43/7.0.22/7.4.6 Docker Archive API docker.container_info argument injection (EUVD-2026-14958)

A vulnerability was found in Zabbix Agent 2 Docker Plugin up to 6.0.43/7.0.22/7.4.6 . It has been declared as critical . This issue affects some unknown processing of the component Docker Archive API …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33349 | NaturalIntelligence fast-xml-parser up to 5.5.6 improper validation of specified quantity in input

A vulnerability was found in NaturalIntelligence fast-xml-parser up to 5.5.6 . It has been rated as problematic . Impacted is an unknown function. Performing a manipulation results in improper validat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33347 | thephpleague commonmark up to 2.8.1 PHP Markdown Parser cross site scripting (Nessus ID 303380)

A vulnerability categorized as problematic has been discovered in thephpleague commonmark up to 2.8.1 . The affected element is an unknown function of the component PHP Markdown Parser . Executing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33331 | middleapi orpc up to 1.13.8 Generated API Documentation cross site scripting

A vulnerability identified as problematic has been detected in middleapi orpc up to 1.13.8 . The impacted element is an unknown function of the component Generated API Documentation . The manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33332 | zauberzeug nicegui up to 3.8.x Query Parameter app.add_media_file/app.add_media_files denial of service

A vulnerability labeled as problematic has been found in zauberzeug nicegui up to 3.8.x . This affects the function app.add_media_file/app.add_media_files of the component Query Parameter Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33345 | solidtime-io solidtime up to 0.11.5 Project Detail Endpoint projects index authorization

A vulnerability marked as problematic has been reported in solidtime-io solidtime up to 0.11.5 . This impacts the function index of the file /api/v1/organizations/{org}/projects/ of the component Proj…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33344 | dagu-org dagu up to 2.3.0 API Endpoint generateFilepath path traversal

A vulnerability described as critical has been identified in dagu-org dagu up to 2.3.0 . Affected is the function generateFilepath of the component API Endpoint . Such manipulation leads to path trave…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-21790 | HCL Traveler 3.0.11/3.0.12/3.0.14 HTTP Header Validation origin validation (KB0129139)

A vulnerability classified as critical has been found in HCL Traveler 3.0.11/3.0.12/3.0.14 . Affected by this vulnerability is an unknown functionality of the component HTTP Header Validation Handler …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-21783 | HCL Traveler 3.0.11/3.0.12/3.0.14 information exposure (KB0129139)

A vulnerability classified as problematic was found in HCL Traveler 3.0.11/3.0.12/3.0.14 . Affected by this issue is some unknown functionality. Executing a manipulation can lead to information exposu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 25, 2026
CVE-2026-33353 | charmbracelet soft-serve up to 0.11.5 information disclosure (GHSA-xgxp-f695-6vrp)

A vulnerability, which was classified as problematic , has been found in charmbracelet soft-serve up to 0.11.5 . This affects an unknown part. The manipulation leads to information disclosure. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33160 | Craft CMS up to 4.17.7/5.9.13 Endpoint authorization

A vulnerability identified as problematic has been detected in Craft CMS up to 4.17.7/5.9.13 . This impacts an unknown function of the component Endpoint . The manipulation leads to authorization bypa…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33162 | Craft CMS up to 5.9.13 move-to-section improper authorization

A vulnerability labeled as critical has been found in Craft CMS up to 5.9.13 . Affected is an unknown function of the file /actions/entries/move-to-section . The manipulation results in improper autho…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33159 | Craft CMS up to 4.17.7/5.9.13 missing authentication

A vulnerability marked as critical has been reported in Craft CMS up to 4.17.7/5.9.13 . Affected by this vulnerability is an unknown functionality. This manipulation causes missing authentication. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33340 | ParisNeo lollms-webui up to 8c5dcef63d847bb3d027ec74915d8fe4afd3014e Web User Interface missing authentication (GHSA-mcwr-5469-pxj4)

A vulnerability described as critical has been identified in ParisNeo lollms-webui up to 8c5dcef63d847bb3d027ec74915d8fe4afd3014e . Affected by this issue is some unknown functionality of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33161 | Craft CMS up to 4.17.7/5.9.13 Endpoint information disclosure

A vulnerability classified as problematic has been found in Craft CMS up to 4.17.7/5.9.13 . This affects an unknown part of the component Endpoint . Performing a manipulation results in information di…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33399 | ellite Wallos up to 4.6.x Notifications validate_webhook_url_for_ssrf server-side request forgery

A vulnerability classified as critical was found in ellite Wallos up to 4.6.x . This vulnerability affects the function validate_webhook_url_for_ssrf of the component Notifications Handler . Executing…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33407 | ellite Wallos up to 4.6.x Endpoint search.php HTTP_PROXY/HTTPS_PROXY server-side request forgery

A vulnerability, which was classified as critical , has been found in ellite Wallos up to 4.6.x . This issue affects some unknown processing of the file endpoints/logos/search.php of the component End…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33401 | ellite Wallos up to 4.6.x AI Recommendations Endpoint AI Ollama host server-side request forgery

A vulnerability, which was classified as critical , was found in ellite Wallos up to 4.6.x . Impacted is an unknown function of the component AI Recommendations Endpoint . The manipulation of the argu…

VulDB Read →
← Prev 362 / 410 Next →