CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9860 articles  ·  updated every 4 hours · grows forever

9860Total
4228Full Text
Jun 26, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33160 | Craft CMS up to 4.17.7/5.9.13 Endpoint authorization

A vulnerability identified as problematic has been detected in Craft CMS up to 4.17.7/5.9.13 . This impacts an unknown function of the component Endpoint . The manipulation leads to authorization bypa…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33162 | Craft CMS up to 5.9.13 move-to-section improper authorization

A vulnerability labeled as critical has been found in Craft CMS up to 5.9.13 . Affected is an unknown function of the file /actions/entries/move-to-section . The manipulation results in improper autho…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33159 | Craft CMS up to 4.17.7/5.9.13 missing authentication

A vulnerability marked as critical has been reported in Craft CMS up to 4.17.7/5.9.13 . Affected by this vulnerability is an unknown functionality. This manipulation causes missing authentication. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33340 | ParisNeo lollms-webui up to 8c5dcef63d847bb3d027ec74915d8fe4afd3014e Web User Interface missing authentication (GHSA-mcwr-5469-pxj4)

A vulnerability described as critical has been identified in ParisNeo lollms-webui up to 8c5dcef63d847bb3d027ec74915d8fe4afd3014e . Affected by this issue is some unknown functionality of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33161 | Craft CMS up to 4.17.7/5.9.13 Endpoint information disclosure

A vulnerability classified as problematic has been found in Craft CMS up to 4.17.7/5.9.13 . This affects an unknown part of the component Endpoint . Performing a manipulation results in information di…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33399 | ellite Wallos up to 4.6.x Notifications validate_webhook_url_for_ssrf server-side request forgery

A vulnerability classified as critical was found in ellite Wallos up to 4.6.x . This vulnerability affects the function validate_webhook_url_for_ssrf of the component Notifications Handler . Executing…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33407 | ellite Wallos up to 4.6.x Endpoint search.php HTTP_PROXY/HTTPS_PROXY server-side request forgery

A vulnerability, which was classified as critical , has been found in ellite Wallos up to 4.6.x . This issue affects some unknown processing of the file endpoints/logos/search.php of the component End…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33401 | ellite Wallos up to 4.6.x AI Recommendations Endpoint AI Ollama host server-side request forgery

A vulnerability, which was classified as critical , was found in ellite Wallos up to 4.6.x . Impacted is an unknown function of the component AI Recommendations Endpoint . The manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33400 | ellite Wallos up to 4.6.x Statistics Page payment cross site scripting

A vulnerability has been found in ellite Wallos up to 4.6.x and classified as problematic . The affected element is the function payment of the component Statistics Page . This manipulation causes cro…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33429 | parse-community parse-server up to 8.6.53/9.6.0-alpha.42 information exposure (GHSA-qpc3-fg4j-8hgm)

A vulnerability was found in parse-community parse-server up to 8.6.53/9.6.0-alpha.42 and classified as problematic . The impacted element is an unknown function. Such manipulation leads to informatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-23921 | Zabbix up to 7.0.21/7.2.14/7.4.5 CApiService.php sortfield sql injection

A vulnerability was found in Zabbix up to 7.0.21/7.2.14/7.4.5 . It has been classified as critical . This affects an unknown function of the file include/classes/api/CApiService.php . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-23923 | Zabbix up to 7.4.6 Frontend validate externally-controlled input to select classes or code

A vulnerability was found in Zabbix up to 7.4.6 . It has been declared as problematic . This impacts the function validate of the component Frontend . Executing a manipulation can lead to use of exter…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33509 | pyLoad up to 0.5.0b3.dev96 API Endpoint set_config_value privileges management

A vulnerability was found in pyLoad up to 0.5.0b3.dev96 . It has been rated as critical . Affected is the function set_config_value of the component API Endpoint . The manipulation leads to improper p…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33508 | parse-community parse-server up to 8.6.55/9.6.0-alpha.44 LiveQuery recursion (GHSA-6qh5-m6g3-xhq6)

A vulnerability categorized as problematic has been discovered in parse-community parse-server up to 8.6.55/9.6.0-alpha.44 . Affected by this vulnerability is an unknown functionality of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33539 | parse-community parse-server up to 8.6.58/9.6.0-alpha.52 PostgreSQL Database group sql injection (GHSA-p2w6-rmh7-w8q3)

A vulnerability identified as critical has been detected in parse-community parse-server up to 8.6.58/9.6.0-alpha.52 . Affected by this issue is some unknown functionality of the component PostgreSQL …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33511 | pyLoad up to 0.4.20/0.5.0b3.dev97 ClickNLoad Feature local_check authorization

A vulnerability labeled as critical has been found in pyLoad up to 0.4.20/0.5.0b3.dev97 . This affects the function local_check of the component ClickNLoad Feature . Such manipulation leads to authori…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33769 | withastro up to 5.18.0 Image Optimization Endpoint information disclosure (GHSA-g735-7g2w-hh3f)

A vulnerability marked as problematic has been reported in withastro astro up to 5.18.0 . This vulnerability affects unknown code of the component Image Optimization Endpoint . Performing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33498 | parse-community parse-server up to 8.6.54/9.6.0-alpha.43 HTTP Request recursion (GHSA-9fjp-q3c4-6w3j)

A vulnerability described as problematic has been identified in parse-community parse-server up to 8.6.54/9.6.0-alpha.43 . This issue affects some unknown processing of the component HTTP Request Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33624 | parse-community parse-server up to 8.6.59/9.6.0-alpha.53 toctou (GHSA-2299-ghjr-6vjp)

A vulnerability classified as problematic has been found in parse-community parse-server up to 8.6.59/9.6.0-alpha.53 . Impacted is an unknown function. The manipulation leads to time-of-check time-of-…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33768 | withastro up to 10.0.1 Query Parameter x_astro_path confused deputy (GHSA-mr6q-rp88-fx84)

A vulnerability classified as critical was found in withastro astro up to 10.0.1 . The affected element is an unknown function of the component Query Parameter Handler . The manipulation of the argume…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33314 | pyLoad up to 0.5.0b3.dev92 Click'N'Load API Endpoint local_check improper authentication

A vulnerability, which was classified as critical , has been found in pyLoad . The impacted element is the function local_check of the component Click'N'Load API Endpoint . This manipulation causes im…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-2417 | Pharos Controls Mosaic Show Controller 2.15.3 missing authentication (icsa-26-083-01)

A vulnerability, which was classified as critical , was found in Pharos Controls Mosaic Show Controller 2.15.3 . This affects an unknown function. Such manipulation leads to missing authentication. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33323 | parse-community parse-server up to 8.6.50/9.6.0-alpha.39 Configuration Options response discrepancy (GHSA-h29g-q5c2-9h4f)

A vulnerability has been found in parse-community parse-server up to 8.6.50/9.6.0-alpha.39 and classified as problematic . This impacts an unknown function of the component Configuration Options Handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33409 | parse-community parse-server up to 8.6.51/9.6.0-alpha.40 improper authentication (GHSA-pfj7-wv7c-22pr)

A vulnerability was found in parse-community parse-server up to 8.6.51/9.6.0-alpha.40 and classified as critical . Affected is an unknown function. Executing a manipulation can lead to improper authen…

VulDB Read →
← Prev 364 / 411 Next →