CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10115 articles  ·  updated every 4 hours · grows forever

10115Total
4231Full Text
Jun 29, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33072 | error311 FileRise up to 3.8.x Environment Variable default_please_change_this_key PERSISTENT_TOKENS_KEY hard-coded credentials

A vulnerability was found in error311 FileRise up to 3.8.x . It has been rated as critical . This issue affects the function default_please_change_this_key of the component Environment Variable Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33070 | error311 FileRise up to 3.7.x deleteShareLink Endpoint missing authentication

A vulnerability categorized as critical has been discovered in error311 FileRise up to 3.7.x . Impacted is the function FileController::deleteShareLink of the component deleteShareLink Endpoint . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-27625 | Stirling-Tools Stirling-PDF up to 2.5.1 PDF File Parser pdf path traversal

A vulnerability identified as critical has been detected in Stirling-Tools Stirling-PDF up to 2.5.1 . The affected element is an unknown function of the file /api/v1/convert/markdown/pdf of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33075 | labring FastGPT up to 4.14.8.3 pull_request_target code download

A vulnerability labeled as problematic has been found in labring FastGPT up to 4.14.8.3 . The impacted element is the function pull_request_target . Such manipulation leads to download of code without…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-32701 | QwikDev qwik up to 1.19.1 FormData Parser type confusion

A vulnerability marked as problematic has been reported in QwikDev qwik up to 1.19.1 . This affects an unknown function of the component FormData Parser . Performing a manipulation results in type con…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-2432 | creativemindssolutions CM Custom Reports Plugin up to 1.2.7 on WordPress Setting cross site scripting (EUVD-2026-13637)

A vulnerability described as problematic has been identified in creativemindssolutions CM Custom Reports Plugin up to 1.2.7 on WordPress. This impacts an unknown function of the component Setting Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33080 | filamentphp filament up to 4.8.4/5.3.4 cross site scripting

A vulnerability classified as problematic has been found in filamentphp filament up to 4.8.4/5.3.4 . Affected is an unknown function. The manipulation leads to cross site scripting. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4496 | sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880 src/gitUtils.ts child_process.exec os command injection

A vulnerability classified as critical was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880 . Affected by this vulnerability is the function child_process.exec of the fil…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4497 | Totolink WA300 5.2cu.7112_B20190227 /cgi-bin/cstecgi.cgi recvUpgradeNewFw os command injection

A vulnerability, which was classified as critical , has been found in Totolink WA300 5.2cu.7112_B20190227 . Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33123 | py-pdf pypdf up to 6.9.0 PDF resource consumption

A vulnerability, which was classified as problematic , was found in py-pdf pypdf up to 6.9.0 . This affects an unknown part of the component PDF Handler . Such manipulation leads to resource consumpti…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33128 | h3js h3 up to 1.15.5 SSE Message formatEventStreamMessage id/event/data/comment crlf injection

A vulnerability has been found in h3js h3 up to 1.15.5 and classified as problematic . This vulnerability affects the function formatEventStreamMessage of the component SSE Message Handler . Performin…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33081 | PinchTab up to 0.8.2 Internal Service /download validateDownloadURL server-side request forgery

A vulnerability was found in PinchTab up to 0.8.2 and classified as critical . This issue affects the function validateDownloadURL of the file /download of the component Internal Service . Executing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33125 | blakeblackshear frigate up to 0.16.2 improper authorization

A vulnerability was found in blakeblackshear frigate up to 0.16.2 . It has been classified as critical . Impacted is an unknown function. The manipulation leads to improper authorization. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33124 | blakeblackshear frigate up to 0.16.x Password Reset password improper authentication

A vulnerability was found in blakeblackshear frigate up to 0.16.x . It has been declared as critical . The affected element is an unknown function of the file /users/{username}/password of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-0677 | TotalSuite TotalContest Lite Plugin up to 2.9.1 on WordPress deserialization

A vulnerability was found in TotalSuite TotalContest Lite Plugin up to 2.9.1 on WordPress. It has been rated as problematic . The impacted element is an unknown function. This manipulation causes dese…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33130 | louislam uptime-kuma up to 2.2.0 notification-provider.js require.resolve filename control (EUVD-2026-13670)

A vulnerability categorized as problematic has been discovered in louislam uptime-kuma up to 2.2.0 . This affects the function require.resolve of the file notification-provider.js . Such manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33129 | h3js h3 up to 2.0.0-rc.8/2.0.1-rc.9 requireBasicAuth timing discrepancy

A vulnerability identified as problematic has been detected in h3js h3 up to 2.0.0-rc.8/2.0.1-rc.9 . This impacts the function requireBasicAuth . Performing a manipulation results in observable timing…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-29106 | SuiteCRM up to 7.15.0/8.9.2 Content Security Policy return_id cross site scripting (GHSA-7qrj-5hj6-7c2m)

A vulnerability, which was classified as problematic , has been found in SuiteCRM up to 7.15.0/8.9.2 . This affects an unknown function of the component Content Security Policy Handler . Performing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-28282 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest policy_enabled authorization (GHSA-6cc8-x3rm-j5pf)

A vulnerability, which was classified as problematic , was found in Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest . This impacts an unknown function of the component policy_enabled Handler . Execu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-29072 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest policy_enabled Setting authorization (GHSA-7ph8-vprq-4jrp)

A vulnerability has been found in Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest and classified as problematic . Affected is an unknown function of the component policy_enabled Setting Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-29107 | SuiteCRM up to 7.15.0/8.9.2 server-side request forgery (GHSA-g7cv-4ghj-x98h)

A vulnerability was found in SuiteCRM up to 7.15.0/8.9.2 and classified as critical . Affected by this vulnerability is an unknown functionality. The manipulation results in server-side request forger…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-3549 | wofSSL up to 5.8.x ECH Parser heap-based overflow

A vulnerability was found in wofSSL up to 5.8.x . It has been classified as critical . Affected by this issue is some unknown functionality of the component ECH Parser . This manipulation causes heap-…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33288 | SuiteCRM up to 7.15.0/8.9.2 sql injection (GHSA-7g39-m4fg-vrq7)

A vulnerability was found in SuiteCRM up to 7.15.0/8.9.2 . It has been declared as critical . This affects an unknown part. Such manipulation leads to sql injection. This vulnerability is referenced a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-32004 | OpenClaw up to 2026.3.1 /api/channels authentication bypass (GHSA-v865-p3gq-hw6m)

A vulnerability was found in OpenClaw up to 2026.3.1 . It has been rated as critical . This vulnerability affects unknown code of the file /api/channels . Performing a manipulation results in authenti…

VulDB Read →
← Prev 396 / 422 Next →