CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10085 articles  ·  updated every 4 hours · grows forever

10085Total
4231Full Text
Jun 28, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4067 | nocaredev Ad Short Plugin up to 2.0.1 on WordPress Shortcode ad_func cross site scripting

A vulnerability has been found in nocaredev Ad Short Plugin up to 2.0.1 on WordPress and classified as problematic . Affected is the function ad_func of the component Shortcode Handler . This manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4143 | neo2oo5 Neos Connector for Fakturama Plugin up to 0.0.14 on WordPress Setting ncff_add_plugin_page cross-site request forgery

A vulnerability was found in neo2oo5 Neos Connector for Fakturama Plugin up to 0.0.14 on WordPress and classified as problematic . Affected by this vulnerability is the function ncff_add_plugin_page o…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4161 | revukangaroo Review Map by RevuKangaroo Plugin up to 1.7 on WordPress Setting cross site scripting

A vulnerability was found in revukangaroo Review Map by RevuKangaroo Plugin up to 1.7 on WordPress. It has been classified as problematic . Affected by this issue is some unknown functionality of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4086 | newbiesup WP Random Button Plugin up to 1.0 on WordPress Shortcode random_button_html nocat cross site scripting

A vulnerability was found in newbiesup WP Random Button Plugin up to 1.0 on WordPress. It has been declared as problematic . This affects the function random_button_html of the component Shortcode Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4072 | tstachl WordPress PayPal Donation Plugin up to 1.01 on WordPress Shortcode wordpress_paypal_donation_create cross site scripting

A vulnerability was found in tstachl WordPress PayPal Donation Plugin up to 1.01 on WordPress. It has been rated as problematic . This vulnerability affects the function wordpress_paypal_donation_crea…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32897 | OpenClaw up to 2026.2.21 gateway.auth.token key management (GHSA-v6x2-2qvm-6gv8)

A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.2.21 . This issue affects some unknown processing. The manipulation of the argument gateway.auth.token results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32899 | OpenClaw up to 2026.2.24 authorization (GHSA-rm2p-j3r7-4x4j)

A vulnerability identified as problematic has been detected in OpenClaw up to 2026.2.24 . Impacted is an unknown function. This manipulation causes incorrect authorization. This vulnerability is handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-3350 | wpsaad Image Alt Text Manager Plugin up to 1.8.2 on WordPress DOM Parser cross site scripting

A vulnerability labeled as problematic has been found in wpsaad Image Alt Text Manager Plugin up to 1.8.2 on WordPress. The affected element is an unknown function of the component DOM Parser . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-3577 | fahadmahmood Keep Backup Daily Plugin up to 2.1.2 on WordPress HTML Attribute sanitize_text_field val HTML injection

A vulnerability marked as problematic has been reported in fahadmahmood Keep Backup Daily Plugin up to 2.1.2 on WordPress. The impacted element is the function sanitize_text_field of the component HTM…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-4083 | demonisblack Scoreboard for HTML5 Games Lite Plugin up to 1.2 on WordPress Shortcode sfhg_shortcode cross site scripting

A vulnerability described as problematic has been identified in demonisblack Scoreboard for HTML5 Games Lite Plugin up to 1.2 on WordPress. This affects the function sfhg_shortcode of the component Sh…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32666 | Automated Logic WebCTRL Premium Server up to 8.4 authentication spoofing

A vulnerability classified as critical has been found in Automated Logic WebCTRL Premium Server up to 8.4 . This impacts an unknown function. The manipulation leads to authentication bypass by spoofin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33228 | WebReflection flatted up to 3.4.1 JSON Parser parse prototype pollution (GHSA-rf6f-7fwh-wjgh)

A vulnerability classified as critical was found in WebReflection flatted up to 3.4.1 . Affected is the function parse of the component JSON Parser . The manipulation results in improperly controlled …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32663 | IGL-Technologies eParking.fi session expiration (icsa-26-078-08)

A vulnerability, which was classified as critical , has been found in IGL-Technologies eParking.fi . Affected by this vulnerability is an unknown functionality. This manipulation causes session expira…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-21732 | Imagination Graphics DDK up to 23.2 RTM/25.1 RTM Switch Statements out-of-range pointer offset

A vulnerability, which was classified as problematic , was found in Imagination Graphics DDK up to 23.2 RTM/25.1 RTM . Affected by this issue is some unknown functionality of the component Switch Stat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-25086 | Automated Logic WebCTRL Premium Server up to 8.4 multiple binds to the same port

A vulnerability has been found in Automated Logic WebCTRL Premium Server up to 8.4 and classified as problematic . This affects an unknown part. Performing a manipulation results in multiple binds to …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-27649 | CTEK Chargeportal session expiration (icsa-26-078-06)

A vulnerability was found in CTEK Chargeportal and classified as critical . This vulnerability affects unknown code. Executing a manipulation can lead to session expiration. This vulnerability is regi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33209 | avo-hq avo up to 3.30.2 return_to cross site scripting (GHSA-762r-27w2-q22j)

A vulnerability was found in avo-hq avo up to 3.30.2 . It has been classified as problematic . This issue affects some unknown processing. The manipulation of the argument return_to leads to cross sit…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33243 | barebox up to 2025.09.2/2026.03.0 data authenticity (GHSA-3fvj-q26p-j6h4)

A vulnerability was found in barebox up to 2025.09.2/2026.03.0 . It has been declared as critical . Impacted is an unknown function. The manipulation results in insufficient verification of data authe…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33411 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest Content Security Policy cross site scripting (GHSA-j3mm-ghh2-83x2)

A vulnerability was found in Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest . It has been rated as problematic . The affected element is an unknown function of the component Content Security Policy…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33291 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest Zendesk Plugin authorization (GHSA-p26h-jqr4-r6j7)

A vulnerability categorized as critical has been discovered in Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest . The impacted element is an unknown function of the component Zendesk Plugin . Such ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32810 | squidowl halloy up to 2026.4 permission assignment (GHSA-x5j2-fr4h-9p7g)

A vulnerability identified as problematic has been detected in squidowl halloy up to 2026.4 . This affects an unknown function. Performing a manipulation results in incorrect permission assignment. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-3572 | iTracker360 Plugin up to 2.2.0 on WordPress Setting cross site scripting

A vulnerability labeled as problematic has been found in iTracker360 Plugin up to 2.2.0 on WordPress. This impacts an unknown function of the component Setting Handler . Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-3332 | xhanch_studio Xhanch Plugin up to 1.1.2 on WordPress Setting xms_setting favicon_url/ga_acc_id cross-site request forgery

A vulnerability marked as problematic has been reported in xhanch_studio Xhanch Plugin up to 1.1.2 on WordPress. Affected is the function xms_setting of the component Setting Handler . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32896 | OpenClaw up to 2026.2.20 BlueBubbles Plugin missing authentication (GHSA-5mx2-2mgw-x8rm)

A vulnerability described as critical has been identified in OpenClaw up to 2026.2.20 . Affected by this vulnerability is an unknown functionality of the component BlueBubbles Plugin . The manipulatio…

VulDB Read →
← Prev 389 / 421 Next →