CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10004 articles  ·  updated every 4 hours · grows forever

10004Total
4230Full Text
Jun 27, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32276 | opensource-workshop connect-cms up to 1.41.0/2.41.0 code injection (GHSA-hxqw-6qv7-cqfv)

A vulnerability, which was classified as critical , has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0 . The affected element is an unknown function. This manipulation causes code i…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32277 | opensource-workshop connect-cms up to 1.41.0/2.41.0 cross site scripting (GHSA-cmfh-mpmf-fmq4)

A vulnerability, which was classified as problematic , was found in opensource-workshop connect-cms up to 1.41.0/2.41.0 . The impacted element is an unknown function. Such manipulation leads to cross …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32278 | opensource-workshop connect-cms up to 1.41.0/2.41.0 Form Plugin File unrestricted upload (GHSA-mv3p-7p89-wq9p)

A vulnerability has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0 and classified as critical . This affects an unknown function of the component Form Plugin . Performing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33307 | airtower-luna mod_gnutls up to 0.12.2 on Apache gnutls_x509_crt_init x509[] stack-based overflow

A vulnerability was found in airtower-luna mod_gnutls up to 0.12.2 on Apache and classified as critical . This impacts the function gnutls_x509_crt_init . Executing a manipulation of the argument x509…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4001 | acowebs Woocommerce Custom Product Addons Pro Plugin up to 5.4.1 on WordPress price.php eval Field eval injection

A vulnerability was found in acowebs Woocommerce Custom Product Addons Pro Plugin up to 5.4.1 on WordPress. It has been classified as critical . Affected is the function eval of the file includes/proc…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4021 | contest-gallery Contest Gallery Plugin up to 28.1.5 on WordPress user_activation_key improper authentication

A vulnerability was found in contest-gallery Contest Gallery Plugin up to 28.1.5 on WordPress. It has been declared as critical . Affected by this vulnerability is the function user_activation_key of …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-3533 | artbees Jupiter X Core Plugin up to 4.14.1 on WordPress import_popup_templates unrestricted upload

A vulnerability was found in artbees Jupiter X Core Plugin up to 4.14.1 on WordPress. It has been rated as critical . Affected by this issue is the function import_popup_templates . This manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33176 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 resource consumption (GHSA-2j26-frm8-cmj9)

A vulnerability categorized as problematic has been discovered in rails activesupport . This affects an unknown part. Such manipulation leads to resource consumption. This vulnerability is referenced …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33169 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 Regular Expression resource consumption (GHSA-cg4j-q9v8-6v38)

A vulnerability identified as problematic has been detected in rails activesupport . This vulnerability affects unknown code of the component Regular Expression Handler . Performing a manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4681 | PTC Windchill PDMLink/FlexPLM up to 13.1.3.0 code injection

A vulnerability labeled as critical has been found in PTC Windchill PDMLink and FlexPLM up to 13.1.3.0 . This issue affects some unknown processing. Executing a manipulation can lead to code injection…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33634 | aquasecurity setup-trivy/trivy-action/trivy up to 0.2.5 malicious code (GHSA-69fq-xp46-6x23)

A vulnerability marked as critical has been reported in aquasecurity setup-trivy, trivy-action and trivy up to 0.2.5 . Impacted is an unknown function. The manipulation leads to embedded malicious cod…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-3079 | StellarWP LearnDash LMS Plugin up to 5.0.3 on WordPress AJAX Action filters[orderby_order] sql injection

A vulnerability described as critical has been identified in StellarWP LearnDash LMS Plugin up to 5.0.3 on WordPress. The affected element is an unknown function of the component AJAX Action Handler .…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4056 | wpeverest User Registration & Membership Plugin up to 5.1.4 on WordPress REST API Endpoint check_permissions authorization

A vulnerability classified as critical has been found in wpeverest User Registration & Membership Plugin up to 5.1.4 on WordPress. The impacted element is the function check_permissions of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33170 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 html_unsafe cross site scripting (GHSA-89vf-4333-qx8v)

A vulnerability classified as problematic was found in rails activesupport . This affects the function html_unsafe . Such manipulation leads to cross site scripting. This vulnerability is documented a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-27183 | OpenClaw up to 2026.3.6 authorization (GHSA-r6qf-8968-wj9q)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.3.6 . This impacts an unknown function. Performing a manipulation results in incorrect authorization. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33167 | rails actionpack up to 8.1/8.1.2.1 consider_all_requests_local cross site scripting (GHSA-pgm4-439c-5jp6)

A vulnerability, which was classified as problematic , was found in rails actionpack up to 8.1/8.1.2.1 . Affected is the function consider_all_requests_local . Executing a manipulation can lead to cro…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32913 | OpenClaw up to 2026.3.6 Header Validation insufficiently protected credentials (GHSA-6mgf-v5j7-45cr)

A vulnerability has been found in OpenClaw up to 2026.3.6 and classified as critical . Affected by this vulnerability is an unknown functionality of the component Header Validation Handler . The manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4066 | inc2734 Smart Custom Fields Plugin up to 5.0.6 on WordPress relational_posts_search authorization

A vulnerability was found in inc2734 Smart Custom Fields Plugin up to 5.0.6 on WordPress and classified as problematic . Affected by this issue is the function relational_posts_search . The manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-4306 | wpjobportal WP Job Portal Plugin up to 2.4.8 on WordPress Parameter radius sql injection

A vulnerability was found in wpjobportal WP Job Portal Plugin up to 2.4.8 on WordPress. It has been classified as critical . This affects an unknown part of the component Parameter Handler . This mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-3225 | thimpress LearnPress Plugin up to 4.3.2.8 on WordPress delete_question_answer authorization

A vulnerability was found in thimpress LearnPress Plugin up to 4.3.2.8 on WordPress. It has been declared as problematic . This vulnerability affects the function delete_question_answer . Such manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-2412 | expresstech Quiz and Survey Master Plugin up to 10.3.5 on WordPress Parameter sanitize_text_field wpdb sql injection

A vulnerability was found in expresstech Quiz and Survey Master Plugin up to 10.3.5 on WordPress. It has been rated as critical . This issue affects the function sanitize_text_field of the component P…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-27646 | OpenClaw up to 2026.3.6 /acp authorization (GHSA-9q36-67vc-rrwg)

A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.3.6 . Impacted is an unknown function of the file /acp . Executing a manipulation can lead to incorrect authorizat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33046 | Indico up to 3.3.11 LaTeX indico.conf os command injection (GHSA-rm2q-f7jv-3cfp)

A vulnerability identified as critical has been detected in Indico up to 3.3.11 . The affected element is an unknown function of the file indico.conf of the component LaTeX Handler . The manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-33168 | rails actionview prior 7.2.3.1/8.0.4.1/8.1.2.1 Attribute cross site scripting (GHSA-v55j-83pf-r9cq)

A vulnerability labeled as problematic has been found in rails actionview . The impacted element is an unknown function of the component Attribute Handler . The manipulation results in cross site scri…

VulDB Read →
← Prev 374 / 417 Next →