A vulnerability classified as problematic has been found in Keycloak on Red Hat. This vulnerability affects unknown code of the component JWT Handler . This manipulation of the argument azp causes ori…
cyberintel.kalymoon.com · 46885 articles · updated every 4 hours · grows forever
A vulnerability classified as problematic has been found in Keycloak on Red Hat. This vulnerability affects unknown code of the component JWT Handler . This manipulation of the argument azp causes ori…
A vulnerability classified as critical was found in Totolink A8000R 5.9c.681_B20180413 . This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi . Such manipulation of the argu…
A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi . Performing a manipu…
A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi . Executin…
A vulnerability has been found in Totolink A3300R 17.0.0cu.557_B20221024 and classified as critical . The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi . The manipulat…
A vulnerability was found in libtheora and classified as problematic . This affects the function avi_parse_input_file of the component AVI File Parser . The manipulation results in out-of-bounds read.…
A vulnerability was found in itsourcecode sanitize or validate this input 1.0 . It has been classified as critical . This impacts an unknown function of the file /borrowedequip.php of the component Pa…
A vulnerability was found in Meesho Online Shopping App up to 27.3 on Android. It has been declared as problematic . Affected is an unknown function of the file /api/endpoint of the component com.mees…
A vulnerability was found in Tenda CX12L 16.03.53.12 . It has been rated as critical . Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter . Performing a…
A vulnerability categorized as critical has been discovered in Tenda CX12L 16.03.53.12 . Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter . Exec…
A vulnerability identified as critical has been detected in Tenda CX12L 16.03.53.12 . This affects the function fromAddressNat of the file /goform/addressNat . The manipulation of the argument page le…
A vulnerability labeled as critical has been found in Tenda CX12L 16.03.53.12 . This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic . The manipulation of the argume…
A vulnerability marked as critical has been reported in Tenda CX12L 16.03.53.12 . This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting . This manipulation of the a…
A vulnerability described as critical has been identified in Totolink A7100RU 7.4cu.2313_b20191024 . Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi . Such manipulation of the arg…
A vulnerability classified as critical has been found in Totolink A7100RU 7.4cu.2313_b20191024 . The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi . Performing a manipula…
A vulnerability classified as critical was found in Totolink A7100RU 7.4cu.2313_b20191024 . The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi . Executing a manipulatio…
A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi . The manipulat…
A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi . The manipulation o…
For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The European Commission, the European Union’s execut…
In one of his recent diaries, Johannes discussed how open redirects are actively being sought out by threat actors[1], which made me wonder about how commonly these mechanisms are actually misused…
Cybercriminals are launching a sophisticated new wave of attacks using fake Microsoft Teams domains. According to recent threat intelligence shared by SEAL Org, hackers are actively tricking corporate…
A high-severity security bypass vulnerability in Anthropic’s Claude Code AI coding agent allows malicious actors to silently evade user-configured deny rules through a simple command-padding technique…
One of the most widely used JavaScript libraries in the world was turned into a weapon on March 30, 2026, when attackers poisoned the Axios npm package and silently deployed malware on developer machi…
A new supply chain attack targeting developers after threat actors compromised the official WordPress domain for ILSpy on April 6, 2026. Instead of providing the legitimate software, the hijacked webs…