CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10056 articles  ·  updated every 4 hours · grows forever

10056Total
4231Full Text
Jun 28, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32897 | OpenClaw up to 2026.2.21 gateway.auth.token key management (GHSA-v6x2-2qvm-6gv8)

A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.2.21 . This issue affects some unknown processing. The manipulation of the argument gateway.auth.token results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32899 | OpenClaw up to 2026.2.24 authorization (GHSA-rm2p-j3r7-4x4j)

A vulnerability identified as problematic has been detected in OpenClaw up to 2026.2.24 . Impacted is an unknown function. This manipulation causes incorrect authorization. This vulnerability is handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-3350 | wpsaad Image Alt Text Manager Plugin up to 1.8.2 on WordPress DOM Parser cross site scripting

A vulnerability labeled as problematic has been found in wpsaad Image Alt Text Manager Plugin up to 1.8.2 on WordPress. The affected element is an unknown function of the component DOM Parser . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-3577 | fahadmahmood Keep Backup Daily Plugin up to 2.1.2 on WordPress HTML Attribute sanitize_text_field val HTML injection

A vulnerability marked as problematic has been reported in fahadmahmood Keep Backup Daily Plugin up to 2.1.2 on WordPress. The impacted element is the function sanitize_text_field of the component HTM…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4083 | demonisblack Scoreboard for HTML5 Games Lite Plugin up to 1.2 on WordPress Shortcode sfhg_shortcode cross site scripting

A vulnerability described as problematic has been identified in demonisblack Scoreboard for HTML5 Games Lite Plugin up to 1.2 on WordPress. This affects the function sfhg_shortcode of the component Sh…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32666 | Automated Logic WebCTRL Premium Server up to 8.4 authentication spoofing

A vulnerability classified as critical has been found in Automated Logic WebCTRL Premium Server up to 8.4 . This impacts an unknown function. The manipulation leads to authentication bypass by spoofin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33228 | WebReflection flatted up to 3.4.1 JSON Parser parse prototype pollution (GHSA-rf6f-7fwh-wjgh)

A vulnerability classified as critical was found in WebReflection flatted up to 3.4.1 . Affected is the function parse of the component JSON Parser . The manipulation results in improperly controlled …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32663 | IGL-Technologies eParking.fi session expiration (icsa-26-078-08)

A vulnerability, which was classified as critical , has been found in IGL-Technologies eParking.fi . Affected by this vulnerability is an unknown functionality. This manipulation causes session expira…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-21732 | Imagination Graphics DDK up to 23.2 RTM/25.1 RTM Switch Statements out-of-range pointer offset

A vulnerability, which was classified as problematic , was found in Imagination Graphics DDK up to 23.2 RTM/25.1 RTM . Affected by this issue is some unknown functionality of the component Switch Stat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-25086 | Automated Logic WebCTRL Premium Server up to 8.4 multiple binds to the same port

A vulnerability has been found in Automated Logic WebCTRL Premium Server up to 8.4 and classified as problematic . This affects an unknown part. Performing a manipulation results in multiple binds to …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-27649 | CTEK Chargeportal session expiration (icsa-26-078-06)

A vulnerability was found in CTEK Chargeportal and classified as critical . This vulnerability affects unknown code. Executing a manipulation can lead to session expiration. This vulnerability is regi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33209 | avo-hq avo up to 3.30.2 return_to cross site scripting (GHSA-762r-27w2-q22j)

A vulnerability was found in avo-hq avo up to 3.30.2 . It has been classified as problematic . This issue affects some unknown processing. The manipulation of the argument return_to leads to cross sit…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33243 | barebox up to 2025.09.2/2026.03.0 data authenticity (GHSA-3fvj-q26p-j6h4)

A vulnerability was found in barebox up to 2025.09.2/2026.03.0 . It has been declared as critical . Impacted is an unknown function. The manipulation results in insufficient verification of data authe…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33411 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest Content Security Policy cross site scripting (GHSA-j3mm-ghh2-83x2)

A vulnerability was found in Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest . It has been rated as problematic . The affected element is an unknown function of the component Content Security Policy…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33291 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest Zendesk Plugin authorization (GHSA-p26h-jqr4-r6j7)

A vulnerability categorized as critical has been discovered in Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest . The impacted element is an unknown function of the component Zendesk Plugin . Such ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32810 | squidowl halloy up to 2026.4 permission assignment (GHSA-x5j2-fr4h-9p7g)

A vulnerability identified as problematic has been detected in squidowl halloy up to 2026.4 . This affects an unknown function. Performing a manipulation results in incorrect permission assignment. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-3572 | iTracker360 Plugin up to 2.2.0 on WordPress Setting cross site scripting

A vulnerability labeled as problematic has been found in iTracker360 Plugin up to 2.2.0 on WordPress. This impacts an unknown function of the component Setting Handler . Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-3332 | xhanch_studio Xhanch Plugin up to 1.1.2 on WordPress Setting xms_setting favicon_url/ga_acc_id cross-site request forgery

A vulnerability marked as problematic has been reported in xhanch_studio Xhanch Plugin up to 1.1.2 on WordPress. Affected is the function xms_setting of the component Setting Handler . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32896 | OpenClaw up to 2026.2.20 BlueBubbles Plugin missing authentication (GHSA-5mx2-2mgw-x8rm)

A vulnerability described as critical has been identified in OpenClaw up to 2026.2.20 . Affected by this vulnerability is an unknown functionality of the component BlueBubbles Plugin . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-31926 | IGL-Technologies eParking.fi insufficiently protected credentials (icsa-26-078-08)

A vulnerability classified as critical has been found in IGL-Technologies eParking.fi . Affected by this issue is some unknown functionality. This manipulation causes insufficiently protected credenti…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-28204 | CTEK Chargeportal insufficiently protected credentials (icsa-26-078-06)

A vulnerability classified as critical was found in CTEK Chargeportal . This affects an unknown part. Such manipulation leads to insufficiently protected credentials. This vulnerability is referenced …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4373 | jetmonsters JetFormBuilder Plugin up to 3.5.6.2 on WordPress set_from_array absolute path traversal

A vulnerability, which was classified as problematic , has been found in jetmonsters JetFormBuilder Plugin up to 3.5.6.2 on WordPress. This vulnerability affects the function Uploaded_File::set_from_a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32642 | Apache Artemis/ActiveMQ Artemis on OpenWire OpenWire Consumer permission

A vulnerability, which was classified as critical , was found in Apache Artemis and ActiveMQ Artemis on OpenWire. This issue affects some unknown processing of the component OpenWire Consumer Handler …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-23537 | feast-dev feast /save-document path traversal

A vulnerability has been found in feast-dev feast and classified as critical . Impacted is an unknown function of the file /save-document . The manipulation leads to path traversal. This vulnerability…

VulDB Read →
← Prev 388 / 419 Next →