CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10115 articles  ·  updated every 4 hours · grows forever

10115Total
4231Full Text
Jun 29, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 20, 2026
Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks - CyberSecurityNews

Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-3102: macOS ExifTool image-processing vulnerability - Kaspersky

CVE-2026-3102: macOS ExifTool image-processing vulnerability Kaspersky

Kaspersky Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-32305 | Traefik up to 2.11.40/3.6.10 TLS Configuration improper authentication (GHSA-wvvq-wgcr-9q48)

A vulnerability described as critical has been identified in Traefik up to 2.11.40/3.6.10 . Affected by this issue is some unknown functionality of the component TLS Configuration Handler . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-25792 | Greenshot up to 1.3.312 untrusted search path (GHSA-f8v9-7fph-fr2j)

A vulnerability classified as problematic has been found in Greenshot up to 1.3.312 . This affects an unknown part. This manipulation causes untrusted search path. This vulnerability is tracked as CVE…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33131 | h3js h3 up to 2.0.0-0/2.0.1-rc.14/2.0.1-rc.15 Host event.url/event.url.hostname/event.url._url authentication spoofing (GHSA-3vj8-jmxq-cgj5)

A vulnerability classified as critical was found in h3js h3 up to 2.0.0-0/2.0.1-rc.14/2.0.1-rc.15 . This vulnerability affects unknown code of the component Host Handler . Such manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-32595 | Traefik up to 2.11.40/3.6.10 timing discrepancy (GHSA-g3hg-j4jv-cwfr)

A vulnerability, which was classified as problematic , has been found in Traefik up to 2.11.40/3.6.10 . This issue affects some unknown processing. Performing a manipulation results in observable timi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33136 | LabRedesCefetRJ WeGIA up to 3.6.6 Memorando listar_memorandos_ativos.php msg cross site scripting (GHSA-xjqp-5q3h-2cxh)

A vulnerability, which was classified as problematic , was found in LabRedesCefetRJ WeGIA up to 3.6.6 . Impacted is an unknown function of the file /html/memorando/listar_memorandos_ativos.php of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33132 | Zitadel up to 3.4.8/4.12.2 API V2 Endpoint authorization (GHSA-g2pf-ww5m-2r9m)

A vulnerability has been found in Zitadel up to 3.4.8/4.12.2 and classified as problematic . The affected element is an unknown function of the component API V2 Endpoint . The manipulation leads to in…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33134 | LabRedesCefetRJ WeGIA up to 3.6.5 GET Parameter restaurar_produto.php id_produto sql injection (GHSA-qg95-x997-66wq)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.5 and classified as critical . The impacted element is an unknown function of the file html/matPat/restaurar_produto.php of the component G…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33135 | LabRedesCefetRJ WeGIA up to 3.6.6 novo_memorandoo.php msg cross site scripting (GHSA-w5rv-5884-w94v)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.6 . It has been classified as problematic . This affects an unknown function of the file /html/memorando/novo_memorandoo.php . This manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4500 | bagofwords1 bagofwords up to 0.0.297 code_execution.py generate_df injection (Issue 60)

A vulnerability was found in bagofwords1 bagofwords up to 0.0.297 . It has been declared as critical . This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.py…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4434 | Devolutions Server up to 2026.0 TLS Certificate Verification certificate validation (DEVO-2026-0005)

A vulnerability was found in Devolutions Server up to 2026.0 . It has been rated as critical . Affected is an unknown function of the component TLS Certificate Verification . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-31381 | Gainsight Assist OAuth Call state get request method with sensitive query strings

A vulnerability categorized as problematic has been discovered in Gainsight Assist . Affected by this vulnerability is an unknown functionality of the component OAuth Call Handler . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-31382 | Gainsight Assist Parameters error_description cross site scripting

A vulnerability identified as problematic has been detected in Gainsight Assist . Affected by this issue is some unknown functionality of the component Parameters Handler . The manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2024-44722 | SysAK up to 2.0 command injection

A vulnerability labeled as critical has been found in SysAK up to 2.0 . This affects an unknown part. The manipulation results in command injection. This vulnerability was named CVE-2024-44722 . The a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4504 | eosphoros-ai db-gpt up to 0.7.5 Incomplete Fix /api/v1/editor/ sql injection

A vulnerability marked as critical has been reported in eosphoros-ai db-gpt up to 0.7.5 . This vulnerability affects unknown code of the file /api/v1/editor/ of the component Incomplete Fix . This man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4505 | eosphoros-ai DB-GPT up to 0.7.5 FastAPI Endpoint controller.py module_plugin.refresh_plugins unrestricted upload

A vulnerability described as critical has been identified in eosphoros-ai DB-GPT up to 0.7.5 . This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4506 | Mindinventory MindSQL up to 0.2.1 mindsql_core.py ask_db code injection

A vulnerability classified as critical has been found in Mindinventory MindSQL up to 0.2.1 . Impacted is the function ask_db of the file mindsql/core/mindsql_core.py . Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4507 | Mindinventory MindSQL up to 0.2.1 mindsql_core.py ask_db sql injection

A vulnerability classified as critical was found in Mindinventory MindSQL up to 0.2.1 . The affected element is the function ask_db of the file mindsql/core/mindsql_core.py . Executing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4508 | PbootCMS up to 3.2.12 Member Login MemberController.php checkUsername sql injection

A vulnerability, which was classified as critical , has been found in PbootCMS up to 3.2.12 . The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php o…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4509 | PbootCMS up to 3.2.12 File Upload core/function/file.php black incomplete blacklist

A vulnerability, which was classified as critical , was found in PbootCMS up to 3.2.12 . This affects an unknown function of the file core/function/file.php of the component File Upload . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4510 | PbootCMS up to 3.2.12 Parameter MemberController.php alert_location backurl cross site scripting

A vulnerability has been found in PbootCMS up to 3.2.12 and classified as problematic . This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4511 | vanna-ai vanna up to 2.0.2 /src/vanna/legacy exec injection

A vulnerability was found in vanna-ai vanna up to 2.0.2 and classified as critical . Affected is the function exec of the file /src/vanna/legacy . Such manipulation leads to injection. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4513 | vanna-ai vanna up to 2.0.2 base.py ask sql injection

A vulnerability was found in vanna-ai vanna up to 2.0.2 . It has been classified as critical . Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py . Performing a m…

VulDB Read →
← Prev 394 / 422 Next →