CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5599 articles  ·  updated every 4 hours · grows forever

5599Total
4034Full Text
May 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-44283 | etcd-io etcd up to 3.4.43/3.5.29/3.6.10 Attachments authorization

A vulnerability described as problematic has been identified in etcd-io etcd up to 3.4.43/3.5.29/3.6.10 . The impacted element is an unknown function of the component Attachments Handler . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-44542 | gtsteffaniak filebrowser up to 1.3.0/1.3.8 path traversal

A vulnerability classified as critical has been found in gtsteffaniak filebrowser up to 1.3.0/1.3.8 . This affects an unknown function. This manipulation causes path traversal. This vulnerability appe…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-44511 | katalyst koi up to 4.19.x Session Cookie session expiration (GHSA-4cx3-3c38-j9vv)

A vulnerability classified as problematic was found in katalyst koi up to 4.19.x . This impacts an unknown function of the component Session Cookie Handler . Such manipulation leads to session expirat…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-42572 | hatchet-dev hatchet up to 0.83.37 tasks authorization

A vulnerability, which was classified as problematic , has been found in hatchet-dev hatchet up to 0.83.37 . Affected is an unknown function of the file /api/v1/stable/dags/tasks . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-42597 | Gotenberg up to 8.31.x PDF File url file inclusion (GHSA-g924-cjx7-2rjw)

A vulnerability, which was classified as problematic , was found in Gotenberg up to 8.31.x . Affected by this vulnerability is an unknown functionality of the file /forms/chromium/convert/url of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-44514 | kubetail cli/dashboard prior 0.14.0 WebSocket Endpoint missing origin validation in websockets (GHSA-v8j7-hp7c-738f)

A vulnerability has been found in kubetail cli and dashboard and classified as problematic . Affected by this issue is some unknown functionality of the component WebSocket Endpoint . The manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-44515 | Nextcloud news up to 28.3.0-beta.0 Web Interface/API server-side request forgery (GHSA-jcfr-rmj6-cpfj)

A vulnerability was found in Nextcloud news up to 28.3.0-beta.0 and classified as critical . This affects an unknown part of the component Web Interface/API . The manipulation results in server-side r…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-44520 | docling-project docling-graph up to 1.5.0 handlers.py requests.head redirect

A vulnerability was found in docling-project docling-graph up to 1.5.0 . It has been classified as problematic . This vulnerability affects the function requests.head of the file docling_graph/core/in…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-45448 | ntop ntopng 6.7.251215 redirect

A vulnerability was found in ntop ntopng 6.7.251215 . It has been declared as problematic . This issue affects some unknown processing. Such manipulation leads to open redirect. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6923 | Nuvoton NPCT7xx Elliptic Curve improper protection of physical side channels

A vulnerability was found in Nuvoton NPCT7xx . It has been rated as problematic . Impacted is an unknown function of the component Elliptic Curve Handler . Performing a manipulation results in imprope…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE - The Hacker News

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6225 | taskbuilder Taskbuilder Plugin up to 5.0.6 on WordPress project_search sql injection

A vulnerability has been found in taskbuilder Taskbuilder Plugin up to 5.0.6 on WordPress and classified as critical . Affected is an unknown function. This manipulation of the argument project_search…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-3892 | stylemix Motors Plugin up to 1.4.107 on WordPress file inclusion

A vulnerability was found in stylemix Motors Plugin up to 1.4.107 on WordPress and classified as problematic . Affected by this vulnerability is an unknown functionality. Such manipulation leads to fi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-5395 | techjewel Fluent Forms Plugin up to 6.2.0 on WordPress exportEntries authorization

A vulnerability was found in techjewel Fluent Forms Plugin up to 6.2.0 on WordPress. It has been classified as critical . Affected by this issue is the function exportEntries . Performing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6271 | shahinurislam Career Section Plugin up to 1.7 on WordPress unrestricted upload

A vulnerability was found in shahinurislam Career Section Plugin up to 1.7 on WordPress. It has been declared as critical . This affects an unknown part. Executing a manipulation can lead to unrestric…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6506 | Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress infusedwoo_gdpr_upddata authorization

A vulnerability was found in Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress. It has been rated as critical . This vulnerability affects the function infusedwoo_gdpr_upddata . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6670 | erolsk8 Media Sync Plugin up to 1.4.9 on WordPress sub_dir/media_items path traversal

A vulnerability categorized as critical has been discovered in erolsk8 Media Sync Plugin up to 1.4.9 on WordPress. This issue affects some unknown processing. The manipulation of the argument sub_dir/…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6510 | Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress AJAX iwar_save_recipe authorization

A vulnerability identified as critical has been detected in Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress. Impacted is the function iwar_save_recipe of the component AJAX Handler . Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-3694 | boldthemes Bold Page Builder Plugin up to 5.6.8 on WordPress bt_bb_button text cross site scripting

A vulnerability labeled as problematic has been found in boldthemes Bold Page Builder Plugin up to 5.6.8 on WordPress. The affected element is the function bt_bb_button . Such manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-5193 | wpdevteam Essential Addons for Elementor Plugin up to 6.5.13 on WordPress register_user privileges management

A vulnerability marked as critical has been reported in wpdevteam Essential Addons for Elementor Plugin up to 6.5.13 on WordPress. The impacted element is the function register_user . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-3718 | managewp ManageWP Worker Plugin up to 4.9.31 on WordPress HTTP Request Header cross site scripting

A vulnerability described as problematic has been identified in managewp ManageWP Worker Plugin up to 4.9.31 on WordPress. This affects an unknown function of the component HTTP Request Header Handler…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-5365 | LatePoint Plugin up to 5.3.2 on WordPress request_cancellation cross-site request forgery

A vulnerability classified as problematic has been found in LatePoint Plugin up to 5.3.2 on WordPress. This impacts the function request_cancellation . The manipulation leads to cross-site request for…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6252 | mr2p Meta Field Block Plugin up to 1.5.2 on WordPress Block Attribute tagName cross site scripting

A vulnerability classified as problematic was found in mr2p Meta Field Block Plugin up to 1.5.2 on WordPress. Affected is an unknown function of the component Block Attribute Handler . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6145 | wpeverest User Registration & Membership Plugin up to 5.1.5 on WordPress is_admin_creation_process authorization

A vulnerability, which was classified as critical , has been found in wpeverest User Registration & Membership Plugin up to 5.1.5 on WordPress. Affected by this vulnerability is the function is_admin_…

VulDB Read →
← Prev 7 / 234 Next →