CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10004 articles  ·  updated every 4 hours · grows forever

10004Total
4230Full Text
Jun 27, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32279 | opensource-workshop connect-cms up to 1.41.0/2.41.0 server-side request forgery (GHSA-jh46-85jr-6ph9)

A vulnerability marked as critical has been reported in opensource-workshop connect-cms up to 1.41.0/2.41.0 . This affects an unknown function. This manipulation causes server-side request forgery. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32299 | opensource-workshop connect-cms up to 1.41.0/2.41.0 access control (GHSA-62ch-j6x7-722j)

A vulnerability described as critical has been identified in opensource-workshop connect-cms up to 1.41.0/2.41.0 . This impacts an unknown function. Such manipulation leads to improper access controls…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-32300 | opensource-workshop connect-cms up to 1.41.0/2.41.0 My Page improper authorization (GHSA-qr6x-wvxr-8hm9)

A vulnerability classified as critical has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0 . Affected is an unknown function of the component My Page . Performing a manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CVE-2026-1969 | WP-FeedStats trx_addons Plugin up to 2.38.4 on WordPress unrestricted upload

A vulnerability classified as critical was found in WP-FeedStats trx_addons Plugin up to 2.38.4 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
Ivanti Endpoint Manager Vulnerability Lets Remote Attacker Leak Arbitrary Data - CyberSecurityNews

Ivanti Endpoint Manager Vulnerability Lets Remote Attacker Leak Arbitrary Data CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths - The Hacker News

CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Mar 24, 2026
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks - The Hacker News

CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-26828 | owntone-server up to 3d1652d DAAP src/httpd_daap.c daap_reply_playlists null pointer dereference

A vulnerability described as problematic has been identified in owntone-server up to 3d1652d . The impacted element is the function daap_reply_playlists of the file src/httpd_daap.c of the component D…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33500 | WWBN AVideo up to 26.0 Markdown Link inlineLink cross site scripting

A vulnerability classified as problematic has been found in WWBN AVideo up to 26.0 . This affects the function inlineLink of the component Markdown Link Handler . The manipulation leads to cross site …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33507 | WWBN AVideo up to 26.0 ZIP File Parser pluginImport.json.php cross-site request forgery (GHSA-hv36-p4w4-6vmj)

A vulnerability classified as problematic was found in WWBN AVideo up to 26.0 . This impacts an unknown function of the file objects/pluginImport.json.php of the component ZIP File Parser . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-30006 | XnSoft NConvert 7.230 stack-based overflow

A vulnerability, which was classified as critical , has been found in XnSoft NConvert 7.230 . Affected is an unknown function. This manipulation causes stack-based buffer overflow. The identification …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33502 | WWBN AVideo up to 26.0 HTTP Request plugin/Live/test.php server-side request forgery (GHSA-3fpm-8rjr-v5mc)

A vulnerability, which was classified as critical , was found in WWBN AVideo up to 26.0 . Affected by this vulnerability is an unknown functionality of the file plugin/Live/test.php of the component H…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-30007 | XnSoft NConvert 7.230 use after free

A vulnerability has been found in XnSoft NConvert 7.230 and classified as critical . Affected by this issue is some unknown functionality. Performing a manipulation results in use after free. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33647 | WWBN AVideo up to 26.0 Filename Extension ImageGallery::saveFile unrestricted upload

A vulnerability was found in WWBN AVideo up to 26.0 and classified as critical . This affects the function ImageGallery::saveFile of the component Filename Extension Handler . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33513 | WWBN AVideo up to 26.0 API Endpoint view/about.php path traversal

A vulnerability was found in WWBN AVideo up to 26.0 . It has been classified as critical . This vulnerability affects unknown code of the file view/about.php of the component API Endpoint . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33649 | WWBN AVideo up to 26.0 Endpoint setPermission.json.php cross-site request forgery

A vulnerability was found in WWBN AVideo up to 26.0 . It has been declared as problematic . This issue affects some unknown processing of the file plugin/Permissions/setPermission.json.php of the comp…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33512 | WWBN AVideo up to 26.0 view/url2Embed.json.php improper authentication

A vulnerability was found in WWBN AVideo up to 26.0 . It has been rated as critical . Impacted is an unknown function of the file view/url2Embed.json.php . This manipulation causes improper authentica…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33650 | WWBN AVideo up to 26.0 videoAddNew.json.php canModerateVideos authorization

A vulnerability categorized as critical has been discovered in WWBN AVideo up to 26.0 . The affected element is the function Permissions::canModerateVideos of the file videoAddNew.json.php . Such mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33648 | WWBN AVideo up to 26.0 Restreamer Endpoint exec liveTransmitionHistory_id os command injection

A vulnerability identified as critical has been detected in WWBN AVideo up to 26.0 . The impacted element is the function exec of the component Restreamer Endpoint . Performing a manipulation of the a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2025-15517 | TP-Link Archer NX200 v1.0 CGI Endpoint missing authentication

A vulnerability labeled as critical has been found in TP-Link Archer NX600 v3.0, Archer NX600 v2.0, Archer NX600 v1.0, Archer NX500 v2.0, Archer NX500 v1.0, Archer NX210 v3.0, Archer NX210 v2.0 v2.20,…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2025-15519 | TP-Link Archer NX200 v1.0 CLI os command injection

A vulnerability marked as critical has been reported in TP-Link Archer NX600 v3.0, Archer NX600 v2.0, Archer NX600 v1.0, Archer NX500 v2.0, Archer NX500 v1.0, Archer NX210 v3.0, Archer NX210 v2.0 v2.2…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2025-15518 | TP-Link Archer NX200 v1.0 os command injection

A vulnerability described as critical has been identified in TP-Link Archer NX600 v3.0, Archer NX600 v2.0, Archer NX600 v1.0, Archer NX500 v2.0, Archer NX500 v1.0, Archer NX210 v3.0, Archer NX210 v2.0…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2025-15605 | TP-Link Archer NX200 v1.0 Device Configuration hard-coded key

A vulnerability classified as critical has been found in TP-Link Archer NX600 v3.0, Archer NX600 v2.0, Archer NX600 v1.0, Archer NX500 v2.0, Archer NX500 v1.0, Archer NX210 v3.0, Archer NX210 v2.0 v2.…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-0898 | Pegasystems Pega Robot Studio 22.1/R25 access control

A vulnerability classified as critical was found in Pegasystems Pega Robot Studio 22.1/R25 . Affected by this issue is some unknown functionality. Such manipulation leads to improper access controls. …

VulDB Read →
← Prev 375 / 417 Next →