CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10182 articles  ·  updated every 4 hours · grows forever

10182Total
4231Full Text
Jun 29, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-2571 | codename065 Download Manager Plugin up to 3.3.49 on WordPress reviewUserStatus information disclosure

A vulnerability identified as problematic has been detected in codename065 Download Manager Plugin up to 3.3.49 on WordPress. Impacted is the function reviewUserStatus . Performing a manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-4068 | pattihis Add Custom Fields to Media Plugin up to 2.0.3 on WordPress update_option cross-site request forgery

A vulnerability labeled as problematic has been found in pattihis Add Custom Fields to Media Plugin up to 2.0.3 on WordPress. The affected element is the function update_option . Executing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-27091 | UiPress lite Plugin up to 3.5.09 on WordPress authorization

A vulnerability marked as critical has been reported in UiPress lite Plugin up to 3.5.09 on WordPress. The impacted element is an unknown function. The manipulation leads to missing authorization. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-4006 | dartiss Draft List Plugin up to 2.6.2 on WordPress Shortcode WP_Post::__get cross site scripting

A vulnerability described as problematic has been identified in dartiss Draft List Plugin up to 2.6.2 on WordPress. This affects the function WP_Post::__get of the component Shortcode Handler . The ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CISA Warns of Actively Exploited Google Chromium 0‑Day Vulnerability - gbhackers.com

CISA Warns of Actively Exploited Google Chromium 0‑Day Vulnerability gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32743 | PX4 PX4-Autopilot up to 1.17.0-rc2 sscanf stack-based overflow (EUVD-2026-13003)

A vulnerability was found in PX4 PX4-Autopilot up to 1.17.0-rc2 and classified as critical . Impacted is the function sscanf . The manipulation results in stack-based buffer overflow. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32255 | kanbn kan up to 0.5.4 Attachment Download Endpoint attatchment fetch server-side request forgery (GHSA-qrx8-9hc6-jvqg / EUVD-2026-12997)

A vulnerability was found in kanbn kan up to 0.5.4 . It has been classified as critical . The affected element is the function fetch of the file /api/download/attatchment of the component Attachment D…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
Apple fixes zero-day flaw exploited in targeted attacks (CVE-2026-20700) - Help Net Security

Apple fixes zero-day flaw exploited in targeted attacks (CVE-2026-20700) Help Net Security

Help Net Security Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32698 | opf openproject up to 16.6.8/17.0.5/17.1.2/17.2.0 Repositories sql injection (GHSA-jqhf-rf9x-9rhx)

A vulnerability, which was classified as critical , was found in opf openproject up to 16.6.8/17.0.5/17.1.2/17.2.0 . This affects an unknown function of the component Repositories Module . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32722 | bloomberg memray up to 1.19.1 cross site scripting (GHSA-r5pr-887v-m2w9)

A vulnerability has been found in bloomberg memray up to 1.19.1 and classified as problematic . This impacts an unknown function. This manipulation causes cross site scripting. This vulnerability appe…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-31970 | samtools htslib up to 1.21.0/1.22.1/1.23 GZI File Parser bgzf_index_load_hfile heap-based overflow (GHSA-p345-84hx-fq6q)

A vulnerability was found in samtools htslib up to 1.21.0/1.22.1/1.23 and classified as critical . Affected is the function bgzf_index_load_hfile of the component GZI File Parser . Such manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32944 | parse-community parse-server up to 8.6.44/9.6.0-alpha.20 recursion (GHSA-9xp9-j92r-p88v)

A vulnerability was found in parse-community parse-server up to 8.6.44/9.6.0-alpha.20 . It has been classified as problematic . Affected by this vulnerability is an unknown functionality. Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-25745 | OpenEMR up to 8.0.0 Message Update authorization (GHSA-jm78-x5p7-52qh)

A vulnerability was found in OpenEMR up to 8.0.0 . It has been declared as problematic . Affected by this issue is some unknown functionality of the component Message Update Handler . Executing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-25873 | Beijing Academy of Artificial Intelligence OmniGen2-RL HTTP POST Request deserialization

A vulnerability was found in Beijing Academy of Artificial Intelligence OmniGen2-RL . It has been rated as critical . This affects an unknown part of the component HTTP POST Request Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32770 | parse-community parse-server up to 8.6.42/9.6.0-alpha.18 Regular Expression uncaught exception (GHSA-827p-g5x5-h86c)

A vulnerability categorized as problematic has been discovered in parse-community parse-server up to 8.6.42/9.6.0-alpha.18 . This vulnerability affects unknown code of the component Regular Expression…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32886 | parse-community parse-server up to 8.6.46/9.6.0-alpha.23 prototype pollution (GHSA-4263-jgmp-7pf4)

A vulnerability identified as problematic has been detected in parse-community parse-server up to 8.6.46/9.6.0-alpha.23 . This issue affects some unknown processing. This manipulation causes improperl…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32943 | parse-community parse-server up to 8.6.47/9.6.0-alpha.27 Password Reset Token toctou (GHSA-r3xq-68wh-gwvh)

A vulnerability labeled as problematic has been found in parse-community parse-server up to 8.6.47/9.6.0-alpha.27 . Impacted is an unknown function of the component Password Reset Token Handler . Such…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2025-15031 | mlflow tar path traversal

A vulnerability marked as critical has been reported in mlflow . The affected element is an unknown function of the component tar Handler . Performing a manipulation results in path traversal. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-33163 | parse-community parse-server up to 8.6.49/9.6.0-alpha.36 Personal Information toJSONwithObjects information disclosure (GHSA-5hmj-jcgp-6hff)

A vulnerability described as problematic has been identified in parse-community parse-server up to 8.6.49/9.6.0-alpha.36 . The impacted element is the function toJSONwithObjects of the component Perso…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-31969 | samtools htslib up to 1.21.0/1.22.1/1.23 cram_byte_array_stop_decode_char heap-based overflow (GHSA-q4cj-f4h5-fqgc)

A vulnerability classified as critical has been found in samtools htslib up to 1.21.0/1.22.1/1.23 . This affects the function cram_byte_array_stop_decode_char . The manipulation leads to heap-based bu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-31971 | samtools htslib up to 1.21.0/1.22.1/1.23 cram_byte_array_len_decode stack-based overflow (GHSA-jvx4-4wq7-6fmh)

A vulnerability classified as critical was found in samtools htslib up to 1.21.0/1.22.1/1.23 . This impacts the function cram_byte_array_len_decode . The manipulation results in stack-based buffer ove…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32700 | heartcombo devise up to 5.0.2 Confirmable confirmation_token/unconfirmed_email race condition (ID 5783)

A vulnerability, which was classified as problematic , has been found in heartcombo devise up to 5.0.2 . Affected is an unknown function of the component Confirmable Module . This manipulation of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-31972 | SAMtools up to 1.21.0 use after free (GHSA-72c8-4jf3-f27p)

A vulnerability, which was classified as critical , was found in SAMtools up to 1.21.0 . Affected by this vulnerability is an unknown functionality. Such manipulation leads to use after free. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 19, 2026
CVE-2026-32636 | ImageMagick up to 6.9.13-41/7.1.2-16 Image Parser NewXMLTree out-of-bounds write (GHSA-gc62-2v5p-qpmp)

A vulnerability has been found in ImageMagick up to 6.9.13-41/7.1.2-16 and classified as critical . Affected by this issue is the function NewXMLTree of the component Image Parser . Performing a manip…

VulDB Read →
← Prev 406 / 425 Next →