CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5717 articles  ·  updated every 4 hours · grows forever

5717Total
4037Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41353 | OpenClaw up to 2026.3.21 external control of assumed-immutable web parameter (GHSA-h5hg-h7rr-gpf3)

A vulnerability classified as critical was found in OpenClaw up to 2026.3.21 . This vulnerability affects unknown code. Executing a manipulation can lead to external control of assumed-immutable web p…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41336 | OpenClaw up to 2026.3.30 Environment Variable OPENCLAW_BUNDLED_HOOKS_DIR inclusion of functionality from untrusted control sphere (GHSA-3qpv-xf3v-mm45)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.3.30 . This issue affects some unknown processing of the component Environment Variable Handler . The manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41350 | OpenClaw up to 2026.3.30 session_status authorization (GHSA-fwjq-xwfj-gv75)

A vulnerability, which was classified as problematic , was found in OpenClaw up to 2026.3.30 . Impacted is the function session_status . The manipulation results in incorrect authorization. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41344 | OpenClaw up to 2026.3.27 Gateway Call /verbose authorization (GHSA-5h2w-qmfp-ggp6)

A vulnerability has been found in OpenClaw up to 2026.3.27 and classified as critical . The affected element is an unknown function of the file /verbose of the component Gateway Call Handler . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41347 | OpenClaw up to 2026.3.30 validationHTTP Operator Endpoint cross-site request forgery (GHSA-mhr7-2xmv-4c4q)

A vulnerability was found in OpenClaw up to 2026.3.30 and classified as problematic . The impacted element is an unknown function of the component validationHTTP Operator Endpoint . Such manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41340 | OpenClaw up to 2026.3.30 Telegram Legacy state distinction (GHSA-f693-58pc-2gfr)

A vulnerability was found in OpenClaw up to 2026.3.30 . It has been classified as critical . This affects an unknown function of the component Telegram Legacy Handler . Performing a manipulation resul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41351 | OpenClaw up to 2026.3.30 Signature Verification authentication replay (GHSA-37v6-fxx8-xjmx)

A vulnerability was found in OpenClaw up to 2026.3.30 . It has been declared as critical . This impacts an unknown function of the component Signature Verification . Executing a manipulation can lead …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41354 | OpenClaw up to 2026.4.1 Silent Message name resolution (GHSA-rxmx-g7hr-8mx4)

A vulnerability was found in OpenClaw up to 2026.4.1 . It has been rated as problematic . Affected is an unknown function of the component Silent Message Handler . The manipulation leads to incorrectl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41337 | OpenClaw up to 2026.3.30 toctou (GHSA-89r3-6x4j-v7wf)

A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.3.30 . Affected by this vulnerability is an unknown functionality. The manipulation results in time-of-check time-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41339 | OpenClaw up to 2026.4.1 exposure of sensitive system information to an unauthorized control sphere (GHSA-2f7j-rp58-mr42)

A vulnerability identified as problematic has been detected in OpenClaw up to 2026.4.1 . Affected by this issue is some unknown functionality. This manipulation causes exposure of sensitive system inf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-5364 | addonsorg Drag and Drop File Upload for Contact Form 7 Plugin unrestricted upload

A vulnerability labeled as critical has been found in addonsorg Drag and Drop File Upload for Contact Form 7 Plugin up to 1.1.3 on WordPress. This affects an unknown part. Such manipulation leads to u…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41357 | OpenClaw up to 2026.3.30 Environment Variable invocation of process using visible sensitive information (GHSA-j9pv-rrcj-6pfx)

A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.30 . This vulnerability affects unknown code of the component Environment Variable Handler . Performing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41355 | OpenClaw up to 2026.3.27 inclusion of functionality from untrusted control sphere (GHSA-42mx-vp8m-j7qh)

A vulnerability described as problematic has been identified in OpenClaw up to 2026.3.27 . This issue affects some unknown processing. Executing a manipulation can lead to inclusion of functionality f…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-5347 | mhmrajib WP Books Gallery Plugin up to 4.8.0 on WordPress Setting admin_init permalink_structure authorization

A vulnerability classified as critical has been found in mhmrajib WP Books Gallery Plugin up to 4.8.0 on WordPress. Impacted is the function admin_init of the component Setting Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41359 | OpenClaw up to 2026.3.27 Send Endpoint privileges management (GHSA-767m-xrhc-fxm7)

A vulnerability classified as critical was found in OpenClaw up to 2026.3.27 . The affected element is an unknown function of the component Send Endpoint . The manipulation results in improper privile…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6810 | codepeople Booking Calendar Contact Form Plugin up to 1.2.63 on WordPress dex_bccf_admin_int_calendar_list.inc.php authorization

A vulnerability, which was classified as critical , has been found in codepeople Booking Calendar Contact Form Plugin up to 1.2.63 on WordPress. The impacted element is an unknown function of the file…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-1949 | DeltaWW AS320T up to 1.14 Web Service buffer size (PCSA-2026-00006)

A vulnerability, which was classified as very critical , was found in DeltaWW AS320T up to 1.14 . This affects an unknown function of the component Web Service . Such manipulation leads to incorrect c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-5428 | wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress Carousel Widget render_post_thumbnail cross site scripting

A vulnerability has been found in wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress and classified as problematic . This impacts the function render_post_thumbnail of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41356 | OpenClaw up to 2026.3.30 Websocket Connection session expiration (GHSA-rfqg-qgf8-xr9x)

A vulnerability was found in OpenClaw up to 2026.3.30 and classified as critical . Affected is an unknown function of the component Websocket Connection Handler . Executing a manipulation can lead to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41358 | OpenClaw up to 2026.4.1 Allowlisted Message origin validation (GHSA-qm77-8qjp-4vcm)

A vulnerability was found in OpenClaw up to 2026.4.1 . It has been classified as critical . Affected by this vulnerability is an unknown functionality of the component Allowlisted Message Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41361 | OpenClaw up to 2026.3.27 IPv6 Address incomplete blacklist (GHSA-g86v-f9qv-rh6m)

A vulnerability was found in OpenClaw up to 2026.3.27 . It has been declared as critical . Affected by this issue is some unknown functionality of the component IPv6 Address Handler . The manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41360 | OpenClaw up to 2026.4.1 pnpm dlx toctou (GHSA-w6wx-jq6j-6mcj)

A vulnerability was found in OpenClaw up to 2026.4.1 . It has been rated as problematic . This affects an unknown part of the component pnpm dlx . This manipulation causes time-of-check time-of-use. T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-21515 | Microsoft Azure IoT Central information disclosure

A vulnerability categorized as problematic has been discovered in Microsoft Azure IoT Central . This vulnerability affects unknown code. Such manipulation leads to information disclosure. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2025-62233 | Apache DolphinScheduler 3.2.x/3.3.0 RPC deserialization

A vulnerability identified as critical has been detected in Apache DolphinScheduler 3.2.x/3.3.0 . This issue affects some unknown processing of the component RPC Handler . Performing a manipulation re…

VulDB Read →
← Prev 51 / 239 Next →