CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  43007 articles  ·  updated every 4 hours · grows forever

43007Total
30565Full Text
Aug 10, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
🔍 Digital Forensics Apr 22, 2026
SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals
DFIR Training Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40889 | frappe hrms up to 15.58.1/16.4.1 API Endpoint access control (GHSA-6cg5-4q6m-vrgm)

A vulnerability classified as critical has been found in frappe hrms up to 15.58.1/16.4.1 . Affected by this vulnerability is an unknown functionality of the component API Endpoint . This manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40876 | patrickhener goshs up to 2.0.0-beta.5 sftpserver/sftpserver.go DefaultHandler.GetHandler path traversal (GHSA-5h6h-7rc9-3824)

A vulnerability classified as critical was found in patrickhener goshs up to 2.0.0-beta.5 . Affected by this issue is the function DefaultHandler.GetHandler of the file sftpserver/sftpserver.go . Such…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40890 | gomarkdown out-of-bounds (GHSA-77fj-vx54-gvh7)

A vulnerability, which was classified as problematic , has been found in gomarkdown markdown . This affects an unknown part. Performing a manipulation results in out-of-bounds read. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40885 | patrickhener goshs 2.0.0-beta.4/2.0.0-beta.5 Request Header information disclosure (GHSA-7h3j-592v-jcrp)

A vulnerability, which was classified as problematic , was found in patrickhener goshs 2.0.0-beta.4/2.0.0-beta.5 . This vulnerability affects unknown code of the component Request Header Handler . Exe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40903 | patrickhener goshs up to 2.0.0-beta.5 GITHUB_TOKEN inclusion of functionality from untrusted control sphere

A vulnerability has been found in patrickhener goshs up to 2.0.0-beta.5 and classified as critical . This issue affects some unknown processing. The manipulation of the argument GITHUB_TOKEN leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40884 | patrickhener goshs up to 2.0.0-beta.5 SFTP Service missing authentication (GHSA-c29w-qq4m-2gcv)

A vulnerability was found in patrickhener goshs up to 2.0.0-beta.5 and classified as critical . Impacted is an unknown function of the component SFTP Service . The manipulation results in missing auth…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40883 | patrickhener goshs 2.0.0-beta.4/2.0.0-beta.5 cross-site request forgery (GHSA-jrq5-hg6x-j6g3)

A vulnerability was found in patrickhener goshs 2.0.0-beta.4/2.0.0-beta.5 . It has been classified as problematic . The affected element is an unknown function. This manipulation causes cross-site req…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40925 | WWBN AVideo up to 29.0 configurationUpdate.json.php User::isAdmin cross-site request forgery (EUVD-2026-24485)

A vulnerability was found in WWBN AVideo up to 29.0 . It has been declared as problematic . The impacted element is the function User::isAdmin of the file objects/configurationUpdate.json.php . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40906 | electric-sql electric up to 1.4.x ORDER /v1/shape order_by sql injection

A vulnerability was found in electric-sql electric up to 1.4.x . It has been rated as critical . This affects an unknown function of the file /v1/shape of the component ORDER Handler . Performing a ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-41320 | Frappe hrms up to 14.38.0/15.53.x Request sql injection (GHSA-745c-5q8r-vgj2)

A vulnerability categorized as critical has been discovered in Frappe hrms up to 14.38.0/15.53.x . This impacts an unknown function of the component Request Handler . Executing a manipulation can lead…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40870 | decidim up to 0.30.4/0.31.0 Setting /api Decidim::Apiauth commentable authorization (GHSA-ghmh-q25g-gxxx)

A vulnerability identified as problematic has been detected in decidim up to 0.30.4/0.31.0 . Affected is the function Decidim::Apiauth of the file /api of the component Setting Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40872 | mailcow mailcow-dockerized prior 2026-03b EMailAddress cross site scripting (GHSA-f9xf-vc72-rcgm)

A vulnerability labeled as problematic has been found in mailcow mailcow-dockerized . Affected by this vulnerability is an unknown functionality. The manipulation of the argument EMailAddress results …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40905 | Kovah LinkAce up to 2.5.3 redirect (EUVD-2026-24473)

A vulnerability marked as problematic has been reported in Kovah LinkAce up to 2.5.3 . Affected by this issue is some unknown functionality. This manipulation causes open redirect. The identification …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40887 | vendurehq vendure up to 2.3.3/3.5.6/3.6.1 Vendure Shop API sql injection

A vulnerability described as critical has been identified in vendurehq vendure up to 2.3.3/3.5.6/3.6.1 . This affects an unknown part of the component Vendure Shop API . Such manipulation leads to sql…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40869 | Decidim up to 0.30.4/0.31.0 privileges assignment (GHSA-w5xj-99cg-rccm)

A vulnerability classified as problematic has been found in Decidim up to 0.30.4/0.31.0 . This vulnerability affects unknown code. Performing a manipulation results in incorrect privilege assignment. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40892 | pjsip pjproject up to 2.16 pjsip_auth_create_digest2 stack-based overflow

A vulnerability classified as critical was found in pjsip pjproject up to 2.16 . This issue affects the function pjsip_auth_create_digest2 . Executing a manipulation can lead to stack-based buffer ove…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40895 | follow-redirects up to 1.15.x information disclosure

A vulnerability, which was classified as problematic , has been found in follow-redirects up to 1.15.x . Impacted is an unknown function. The manipulation leads to information disclosure. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40871 | mailcow mailcow-dockerized prior 2026-03b API quarantine_category input validation (GHSA-r8fq-wrfm-cj2q)

A vulnerability, which was classified as problematic , was found in mailcow mailcow-dockerized . The affected element is an unknown function of the component API . The manipulation of the argument qua…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40878 | mailcow mailcow-dockerized prior 2026-03b Web Interface setLang REQUEST_URI cross site scripting (GHSA-xv9r-j862-5hqf)

A vulnerability has been found in mailcow mailcow-dockerized and classified as problematic . The impacted element is the function setLang of the component Web Interface . This manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40873 | mailcow mailcow-dockerized prior 2026-03b Attachment cross site scripting (GHSA-2xjc-rg88-jvpp)

A vulnerability was found in mailcow mailcow-dockerized and classified as problematic . This affects an unknown function of the component Attachment Handler . Such manipulation leads to cross site scr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40910 | fatedier frp up to 0.68.0 Authorization Header improper authentication

A vulnerability was found in fatedier frp up to 0.68.0 . It has been classified as critical . This impacts an unknown function of the component Authorization Header Handler . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40874 | mailcow mailcow-dockerized prior 2026-03b Mail Service access control (GHSA-jjxh-rm7p-hjc3)

A vulnerability was found in mailcow mailcow-dockerized . It has been declared as critical . Affected is an unknown function of the component Mail Service . Executing a manipulation can lead to improp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40888 | Frappe hrms up to 15.58.0/16.4.0 API Endpoint access control (GHSA-4375-7rxj-9hfx)

A vulnerability was found in Frappe hrms up to 15.58.0/16.4.0 . It has been rated as critical . Affected by this vulnerability is an unknown functionality of the component API Endpoint . The manipulat…

VulDB Read →
← Prev 1144 / 1792 Next →