CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9985 articles  ·  updated every 4 hours · grows forever

9985Total
4229Full Text
Jun 27, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4754 | MolotovCherry Android-ImageMagick7 up to 7.1.2-10 cross site scripting

A vulnerability marked as problematic has been reported in MolotovCherry Android-ImageMagick7 up to 7.1.2-10 . The affected element is an unknown function. This manipulation causes cross site scriptin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4755 | MolotovCherry Android-ImageMagick7 up to 7.1.2-10 input validation

A vulnerability described as critical has been identified in MolotovCherry Android-ImageMagick7 up to 7.1.2-10 . The impacted element is an unknown function. Such manipulation leads to improper input …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4756 | MolotovCherry Android-ImageMagick7 up to 7.1.2-10 out-of-bounds write

A vulnerability classified as critical has been found in MolotovCherry Android-ImageMagick7 up to 7.1.2-10 . This affects an unknown function. Performing a manipulation results in out-of-bounds write.…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2025-52204 | Znuny::ITSM 6.5.x Parameter customer.pl OTRSCustomerInterface cross site scripting

A vulnerability classified as problematic has been found in Znuny::ITSM 6.5.x . This issue affects some unknown processing of the file customer.pl of the component Parameter Handler . The manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-3055 | Citrix NetScaler ADC/NetScaler Gateway SAML IdP out-of-bounds (CTX696300)

A vulnerability classified as critical was found in Citrix NetScaler ADC and NetScaler Gateway . Impacted is an unknown function of the component SAML IdP Handler . The manipulation results in out-of-…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32276 | opensource-workshop connect-cms up to 1.41.0/2.41.0 code injection (GHSA-hxqw-6qv7-cqfv)

A vulnerability, which was classified as critical , has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0 . The affected element is an unknown function. This manipulation causes code i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32277 | opensource-workshop connect-cms up to 1.41.0/2.41.0 cross site scripting (GHSA-cmfh-mpmf-fmq4)

A vulnerability, which was classified as problematic , was found in opensource-workshop connect-cms up to 1.41.0/2.41.0 . The impacted element is an unknown function. Such manipulation leads to cross …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32278 | opensource-workshop connect-cms up to 1.41.0/2.41.0 Form Plugin File unrestricted upload (GHSA-mv3p-7p89-wq9p)

A vulnerability has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0 and classified as critical . This affects an unknown function of the component Form Plugin . Performing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33307 | airtower-luna mod_gnutls up to 0.12.2 on Apache gnutls_x509_crt_init x509[] stack-based overflow

A vulnerability was found in airtower-luna mod_gnutls up to 0.12.2 on Apache and classified as critical . This impacts the function gnutls_x509_crt_init . Executing a manipulation of the argument x509…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4001 | acowebs Woocommerce Custom Product Addons Pro Plugin up to 5.4.1 on WordPress price.php eval Field eval injection

A vulnerability was found in acowebs Woocommerce Custom Product Addons Pro Plugin up to 5.4.1 on WordPress. It has been classified as critical . Affected is the function eval of the file includes/proc…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4021 | contest-gallery Contest Gallery Plugin up to 28.1.5 on WordPress user_activation_key improper authentication

A vulnerability was found in contest-gallery Contest Gallery Plugin up to 28.1.5 on WordPress. It has been declared as critical . Affected by this vulnerability is the function user_activation_key of …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-3533 | artbees Jupiter X Core Plugin up to 4.14.1 on WordPress import_popup_templates unrestricted upload

A vulnerability was found in artbees Jupiter X Core Plugin up to 4.14.1 on WordPress. It has been rated as critical . Affected by this issue is the function import_popup_templates . This manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33176 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 resource consumption (GHSA-2j26-frm8-cmj9)

A vulnerability categorized as problematic has been discovered in rails activesupport . This affects an unknown part. Such manipulation leads to resource consumption. This vulnerability is referenced …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33169 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 Regular Expression resource consumption (GHSA-cg4j-q9v8-6v38)

A vulnerability identified as problematic has been detected in rails activesupport . This vulnerability affects unknown code of the component Regular Expression Handler . Performing a manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4681 | PTC Windchill PDMLink/FlexPLM up to 13.1.3.0 code injection

A vulnerability labeled as critical has been found in PTC Windchill PDMLink and FlexPLM up to 13.1.3.0 . This issue affects some unknown processing. Executing a manipulation can lead to code injection…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33634 | aquasecurity setup-trivy/trivy-action/trivy up to 0.2.5 malicious code (GHSA-69fq-xp46-6x23)

A vulnerability marked as critical has been reported in aquasecurity setup-trivy, trivy-action and trivy up to 0.2.5 . Impacted is an unknown function. The manipulation leads to embedded malicious cod…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-3079 | StellarWP LearnDash LMS Plugin up to 5.0.3 on WordPress AJAX Action filters[orderby_order] sql injection

A vulnerability described as critical has been identified in StellarWP LearnDash LMS Plugin up to 5.0.3 on WordPress. The affected element is an unknown function of the component AJAX Action Handler .…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4056 | wpeverest User Registration & Membership Plugin up to 5.1.4 on WordPress REST API Endpoint check_permissions authorization

A vulnerability classified as critical has been found in wpeverest User Registration & Membership Plugin up to 5.1.4 on WordPress. The impacted element is the function check_permissions of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33170 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 html_unsafe cross site scripting (GHSA-89vf-4333-qx8v)

A vulnerability classified as problematic was found in rails activesupport . This affects the function html_unsafe . Such manipulation leads to cross site scripting. This vulnerability is documented a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-27183 | OpenClaw up to 2026.3.6 authorization (GHSA-r6qf-8968-wj9q)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.3.6 . This impacts an unknown function. Performing a manipulation results in incorrect authorization. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33167 | rails actionpack up to 8.1/8.1.2.1 consider_all_requests_local cross site scripting (GHSA-pgm4-439c-5jp6)

A vulnerability, which was classified as problematic , was found in rails actionpack up to 8.1/8.1.2.1 . Affected is the function consider_all_requests_local . Executing a manipulation can lead to cro…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32913 | OpenClaw up to 2026.3.6 Header Validation insufficiently protected credentials (GHSA-6mgf-v5j7-45cr)

A vulnerability has been found in OpenClaw up to 2026.3.6 and classified as critical . Affected by this vulnerability is an unknown functionality of the component Header Validation Handler . The manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4066 | inc2734 Smart Custom Fields Plugin up to 5.0.6 on WordPress relational_posts_search authorization

A vulnerability was found in inc2734 Smart Custom Fields Plugin up to 5.0.6 on WordPress and classified as problematic . Affected by this issue is the function relational_posts_search . The manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4306 | wpjobportal WP Job Portal Plugin up to 2.4.8 on WordPress Parameter radius sql injection

A vulnerability was found in wpjobportal WP Job Portal Plugin up to 2.4.8 on WordPress. It has been classified as critical . This affects an unknown part of the component Parameter Handler . This mani…

VulDB Read →
← Prev 373 / 417 Next →