CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10243 articles  ·  updated every 4 hours · grows forever

10243Total
4232Full Text
Jun 30, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs
CVE-2026-21991 | Oracle Linux 8/9/10 dtprobed denial of service

A vulnerability categorized as critical has been discovered in Oracle Linux 8/9/10 . This impacts an unknown function of the component dtprobed . Such manipulation leads to denial of service. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-4308 | frdel/agent0ai agent-zero 0.9.7 document_query.py handle_pdf_document server-side request forgery

A vulnerability was found in frdel/agent0ai agent-zero 0.9.7 . It has been rated as critical . This affects the function handle_pdf_document of the file python/helpers/document_query.py . This manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-4307 | frdel/agent0ai agent-zero 0.9.7-10 python/helpers/files.py get_abs_path path traversal

A vulnerability was found in frdel/agent0ai agent-zero 0.9.7-10 . It has been declared as critical . The impacted element is the function get_abs_path of the file python/helpers/files.py . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2025-68971 | Forgejo up to 13.0.3 File Attachment denial of service

A vulnerability was found in Forgejo up to 13.0.3 . It has been classified as problematic . The affected element is an unknown function of the component File Attachment Handler . The manipulation lead…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-2454 | Mattermost up to 10.11.10/11.2.2/11.3.0 Websocket Message improper validation of specified type of input

A vulnerability was found in Mattermost up to 10.11.10/11.2.2/11.3.0 and classified as problematic . Impacted is an unknown function of the component Websocket Message Handler . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-29522 | ZwickRoell Test Data Management up to 3.0.7 node_upgrade_srv.js firmware path traversal

A vulnerability has been found in ZwickRoell Test Data Management up to 3.0.7 and classified as critical . This issue affects some unknown processing of the file /server/node_upgrade_srv.js . Performi…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2025-69902 | kubectl-mcp-server 1.2.0 minimal_wrapper.py os command injection

A vulnerability, which was classified as critical , was found in kubectl-mcp-server 1.2.0 . This vulnerability affects unknown code of the file minimal_wrapper.py . Such manipulation leads to os comma…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-26230 | Mattermost up to 10.11.10/11.3.x API Endpoint authorization

A vulnerability, which was classified as problematic , has been found in Mattermost up to 10.11.10/11.3.x . This affects an unknown part of the component API Endpoint . This manipulation causes incorr…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-1629 | Mattermost up to 10.11.10/11.3.x Private Channel operation after expiration

A vulnerability classified as problematic was found in Mattermost up to 10.11.10/11.3.x . Affected by this issue is some unknown functionality of the component Private Channel Handler . The manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-26304 | Mattermost up to 11.2.2/11.3.0 Playbook Run API authorization

A vulnerability classified as problematic has been found in Mattermost up to 11.2.2/11.3.0 . Affected by this vulnerability is an unknown functionality of the component Playbook Run API . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2025-50881 | Flow up to 9.x flow/admin/moniteur.php eval Action improper authentication

A vulnerability described as critical has been identified in Flow up to 9.x . Affected is the function eval of the file flow/admin/moniteur.php . Executing a manipulation of the argument Action can le…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-30882 | Chamilo LMS up to 1.11.35 keyword cross site scripting

A vulnerability marked as problematic has been reported in Chamilo LMS up to 1.11.35 . This impacts an unknown function. Performing a manipulation of the argument keyword results in cross site scripti…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-32262 | Craft CMS up to 4.17.4/5.9.10 replaceFile targetFilename path traversal

A vulnerability labeled as critical has been found in Craft CMS up to 4.17.4/5.9.10 . This affects the function replaceFile . Such manipulation of the argument targetFilename leads to path traversal. …

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-32267 | Craft CMS up to 4.17.5/5.9.11 authorization

A vulnerability identified as critical has been detected in Craft CMS up to 4.17.5/5.9.11 . The impacted element is an unknown function. This manipulation causes incorrect authorization. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-32264 | Craft CMS up to 4.17.4/5.9.10 externally-controlled input to select classes or code

A vulnerability categorized as problematic has been discovered in Craft CMS up to 4.17.4/5.9.10 . The affected element is an unknown function. The manipulation results in use of externally-controlled …

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-30881 | Chamilo LMS up to 1.11.35 AJAX Endpoint Database::escape_string sql injection

A vulnerability was found in Chamilo LMS up to 1.11.35 . It has been rated as critical . Impacted is the function Database::escape_string of the component AJAX Endpoint . The manipulation leads to sql…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-30876 | Chamilo LMS up to 1.11.35 response discrepancy

A vulnerability was found in Chamilo LMS up to 1.11.35 . It has been declared as problematic . This issue affects some unknown processing. Executing a manipulation can lead to observable response disc…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-29516 | Buffalo TeraStation NAS TS5400R up to 4.02-0.06 permission assignment

A vulnerability was found in Buffalo TeraStation NAS TS5400R up to 4.02-0.06 . It has been classified as problematic . This vulnerability affects unknown code. Performing a manipulation results in inc…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-28430 | Chamilo LMS up to 1.11.33 Legacy Password Reset custom_dates sql injection

A vulnerability was found in Chamilo LMS up to 1.11.33 and classified as critical . This affects an unknown part of the component Legacy Password Reset Handler . Such manipulation of the argument cust…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2025-69808 | p2r3 Bareiron 8e4d40 denial of service

A vulnerability has been found in p2r3 Bareiron 8e4d40 and classified as problematic . Affected by this issue is some unknown functionality. This manipulation causes denial of service. The identificat…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2025-69727 | Index-Education Pronote prior 2025.2.8 index.js composeUrlImgPhotoIndividu authorization

A vulnerability, which was classified as problematic , was found in Index-Education Pronote . Affected by this vulnerability is the function composeUrlImgPhotoIndividu of the file index.js . The manip…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2026-32261 | Webhooks Plugin up to 3.1.x on Craftcms That Call renderString special elements used in a template engine (GHSA-8wg7-wm29-2rvg)

A vulnerability, which was classified as problematic , has been found in Webhooks Plugin up to 3.1.x on Craftcms. Affected is the function renderString of the component That Call Handler . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2025-69809 | p2r3 Bareiron 8e4d40 improper authentication

A vulnerability classified as critical was found in p2r3 Bareiron 8e4d40 . This impacts an unknown function. Executing a manipulation can lead to improper authentication. This vulnerability is handled…

VulDB Read →
⬡ Vulnerabilities & CVEs
CVE-2025-69196 | jlowin fastmcp up to 2.14.1 resource authorization (GHSA-5h2m-4q8j-pqpj)

A vulnerability classified as problematic has been found in jlowin fastmcp up to 2.14.1 . This affects an unknown function. Performing a manipulation of the argument resource results in incorrect auth…

VulDB Read →
← Prev 416 / 427 Next →