A vulnerability was found in OpenMage magento-lts up to 20.16.x and classified as critical . This impacts an unknown function of the component Dataflow Module . Such manipulation leads to path travers…
cyberintel.kalymoon.com · 43564 articles · updated every 4 hours · grows forever
A vulnerability was found in OpenMage magento-lts up to 20.16.x and classified as critical . This impacts an unknown function of the component Dataflow Module . Such manipulation leads to path travers…
A vulnerability was found in mborgerding kissfft . It has been classified as critical . Affected is the function kiss_fftndr_alloc of the file kiss_fftndr.c . Performing a manipulation results in inte…
A vulnerability was found in Buffalo Link Station 1.85-0.01 . It has been declared as problematic . Affected by this vulnerability is an unknown functionality of the file /nasapi . Executing a manipul…
A vulnerability was found in Doorman 0.1.0/1.0.2 . It has been rated as critical . Affected by this issue is the function manage_users of the file /platform/user/ . The manipulation of the argument ro…
A vulnerability categorized as critical has been discovered in stm32duino Arduino_Core_STM32 up to 1.6.x . This affects the function pwm_start . The manipulation results in memory corruption. This vul…
A vulnerability identified as critical has been detected in Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6 . This vulnerability affects unknown code. This manipulation causes stack-based b…
A vulnerability labeled as critical has been found in Dell PowerProtect Data Domain appliances up to 7.13.1.60/8.3.1.20/8.7.0.0 . This issue affects some unknown processing. Such manipulation leads to…
A vulnerability marked as problematic has been reported in GFI HelpDesk up to 4.99.8 . Impacted is the function Controller_Step.InsertSubmit of the component Troubleshooter Module . Performing a manip…
A vulnerability described as critical has been identified in Vexa-ai vexa . The affected element is an unknown function of the component HTTP POST Request Handler . Executing a manipulation can lead t…
A vulnerability classified as problematic has been found in GFI HelpDesk up to 4.99.8 . The impacted element is the function Controller_Ticket.EditSubmit of the component POST Parameter Handler . The …
A vulnerability classified as critical was found in DeepCool DeepCreative up to 1.2.7 . This affects an unknown function of the component File Handler . The manipulation results in permission issues. …
A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.4.14 . This impacts an unknown function of the component UNC File Handler . This manipulation causes file i…
A vulnerability, which was classified as problematic , was found in GFI HelpDesk up to 4.99.8 . Affected is an unknown function of the component Groups Page . Such manipulation of the argument company…
A vulnerability has been found in GFI HelpDesk up to 4.99.8 and classified as problematic . Affected by this vulnerability is the function SWIFT_Language::Create of the component Languages Page . Perf…
A vulnerability was found in GFI HelpDesk up to 4.99.9 and classified as problematic . Affected by this issue is the function SWIFT_Report::Create of the component Reports Module . Executing a manipul…
How Microsoft secures Dynamics 365 and Power Platform by removing credentials, reducing attack surfaces, and using platform engineering to block opportunistic threats. The post Making opportunistic cy…
Key Points The Gentlemen RaaS The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. The operators advertise their services across multiple unde…
For the latest discoveries in cyber research for the week of 20th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Booking.com, the Amsterdam-based travel platform, ha…
Outsiders Could Exploit Misconfig to Stream Commands, Credentials A misconfiguration in Microsoft's Azure SRE Agent may have allowed any Azure account holder from any company to tap into another organ…
A critical Broken Object Level Authorization (BOLA) vulnerability in Lovable, the popular AI-powered app builder platform, is reportedly allowing unauthorized users to access sensitive project data, i…
Iran’s Ministry of Intelligence and Security (MOIS) has been running a long and carefully organized cyber campaign using three separate hacker identities. These identities, known as Homeland Justice, …
A North Korean threat group known as UNC1069 has been running a sophisticated campaign that tricks cryptocurrency and Web3 professionals into joining fake online meetings, only to infect their compute…
The OT devices that translate machine talk into Internet-speak are riddled with vulnerabilities and more frequently targeted for attacks, researchers say.