CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10108 articles  ·  updated every 4 hours · grows forever

10108Total
4231Full Text
Jun 28, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32318 | cryptomator up to 2.8.2 on iOS API Endpoint vault.cryptomator origin validation (GHSA-g7fr-c82r-hm6j)

A vulnerability categorized as critical has been discovered in cryptomator up to 2.8.2 on iOS. This issue affects some unknown processing of the file vault.cryptomator of the component API Endpoint . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33177 | Statamic CMS up to 5.73.13/6.6.x Field Action Handler Endpoint authorization (GHSA-wh3h-gvc4-cc2g)

A vulnerability identified as problematic has been detected in Statamic CMS up to 5.73.13/6.6.x . Impacted is an unknown function of the component Field Action Handler Endpoint . Performing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33140 | ParzivalHack PySpector up to 0.1.6 HTML Report eval HTML injection (GHSA-2gmv-2r3v-jxj2)

A vulnerability labeled as problematic has been found in ParzivalHack PySpector up to 0.1.6 . The affected element is the function eval of the component HTML Report Handler . Executing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-2378 | BrowserCompany of New York ArcSearch up to 1.12.6 on Android Web ui layer

A vulnerability marked as problematic has been reported in BrowserCompany of New York ArcSearch up to 1.12.6 on Android. The impacted element is an unknown function of the component Web Handler . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2025-63261 | AWStats 8.0 open command injection

A vulnerability described as critical has been identified in AWStats 8.0 . This affects the function Open . The manipulation results in command injection. This vulnerability is known as CVE-2025-63261…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33126 | blakeblackshear frigate up to 0.16.2 HTTP Request /ffprobe server-side request forgery (GHSA-j6g3-3j3q-c2xv)

A vulnerability classified as critical has been found in blakeblackshear frigate up to 0.16.2 . This impacts an unknown function of the file /ffprobe of the component HTTP Request Handler . This manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-32887 | Effect-TS effect up to 3.19.x API Call race condition (GHSA-38f7-945m-qr2g)

A vulnerability classified as problematic was found in Effect-TS effect up to 3.19.x . Affected is the function RpcServer.toWebHandler/HttpApp.toWebHandlerRuntime of the component API Call Handler . S…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33172 | Statamic CMS up to 5.73.13/6.6.x cross site scripting (GHSA-7rcv-55mj-chg7)

A vulnerability, which was classified as problematic , has been found in Statamic CMS up to 5.73.13/6.6.x . Affected by this vulnerability is an unknown functionality. Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-30579 | File Thingie 2.5.7 Upload File cross site scripting

A vulnerability, which was classified as problematic , was found in File Thingie 2.5.7 . Affected by this issue is some unknown functionality of the component Upload File Handler . Executing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33171 | Statamic CMS up to 5.73.13/6.6.x Configuration Parameter path traversal (GHSA-qm7r-wwq7-6f85)

A vulnerability has been found in Statamic CMS up to 5.73.13/6.6.x and classified as critical . This affects an unknown part of the component Configuration Parameter Handler . The manipulation leads t…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2025-63260 | SyncFusion 30.1.37 Document-Editor cross site scripting

A vulnerability was found in SyncFusion 30.1.37 and classified as problematic . This vulnerability affects unknown code of the component Document-Editor . The manipulation results in cross site script…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-30578 | File Thinghie 2.5.7 dir cross site scripting

A vulnerability was found in File Thinghie 2.5.7 . It has been classified as problematic . This issue affects some unknown processing. This manipulation of the argument dir causes cross site scripting…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33186 | grpc grpc-go up to 1.79.2 improper authorization

A vulnerability was found in grpc grpc-go up to 1.79.2 . It has been declared as critical . Impacted is an unknown function. Such manipulation leads to improper authorization. This vulnerability is li…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
CVE-2026-33180 | hapifhir org.hl7.fhir.core up to 6.8.x information disclosure

A vulnerability was found in hapifhir org.hl7.fhir.core up to 6.8.x . It has been rated as problematic . The affected element is an unknown function. Performing a manipulation results in information d…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
HPE Aruba Networking Vulnerability Allows Privilege Escalation and DoS Attacks - cyberpress.org

HPE Aruba Networking Vulnerability Allows Privilege Escalation and DoS Attacks cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
Hikvision Wireless Access Point Flaws Enable Remote Command Execution Attacks - cyberpress.org

Hikvision Wireless Access Point Flaws Enable Remote Command Execution Attacks cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
Apple Zero-Day Vulnerability Actively Exploited in Sophisticated Targeted Attacks - cyberpress.org

Apple Zero-Day Vulnerability Actively Exploited in Sophisticated Targeted Attacks cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Mar 21, 2026
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure - The Hacker News

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-22172 | OpenClaw up to 2026.3.11 WebSocket Connect Path authorization (GHSA-rqpp-rjj8-7wv8 / EUVD-2026-13704)

A vulnerability classified as critical was found in OpenClaw up to 2026.3.11 . This impacts an unknown function of the component WebSocket Connect Path Handler . The manipulation results in missing au…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-29794 | vikunja up to 2.1.x Header X-Forwarded-For reliance on untrusted inputs in a security decision (GHSA-m547-hp4w-j6jx / EUVD-2026-13706)

A vulnerability, which was classified as problematic , has been found in vikunja up to 2.1.x . Affected is an unknown function of the component Header Handler . This manipulation of the argument X-For…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33312 | vikunja up to 2.1.x background authorization (GHSA-564f-wx8x-878h / EUVD-2026-13708)

A vulnerability, which was classified as problematic , was found in vikunja up to 2.1.x . Affected by this vulnerability is an unknown functionality of the file /api/v1/projects/:project/background . …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4519 | Python CPython up to 3.14.x API webbrowser.open (ID 143930 / EUVD-2026-13712)

A vulnerability has been found in Python CPython up to 3.14.x and classified as problematic . Affected by this issue is the function webbrowser.open of the component API . Performing a manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2025-67260 | Terrapack TKServerCGI/TpkWebGIS Client unrestricted upload

A vulnerability was found in Terrapack TKServerCGI and TpkWebGIS Client and classified as critical . This affects an unknown part. Executing a manipulation can lead to unrestricted upload. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-32989 | Precurio Intranet Portal 4.4 cross-site request forgery

A vulnerability was found in Precurio Intranet Portal 4.4 . It has been classified as problematic . This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. This …

VulDB Read →
← Prev 392 / 422 Next →