A vulnerability, which was classified as problematic , was found in laurent22 joplin up to 3.5.6 . Affected is an unknown function. The manipulation results in path traversal: '../filedir'. This vulne…
cyberintel.kalymoon.com · 39048 articles · updated every 4 hours · grows forever
A vulnerability, which was classified as problematic , was found in laurent22 joplin up to 3.5.6 . Affected is an unknown function. The manipulation results in path traversal: '../filedir'. This vulne…
A vulnerability has been found in steipete summarize up to 0.15.0 and classified as problematic . Affected by this vulnerability is an unknown functionality of the file /v1/summarize . This manipulati…
A vulnerability was found in steipete summarize up to 0.15.0 and classified as critical . Affected by this issue is some unknown functionality. Such manipulation leads to missing authorization. This v…
A vulnerability was found in FreePBX up to 16.0.70/17.0.5 . It has been classified as critical . This affects the function unserialize of the component Backup Module . Performing a manipulation result…
A vulnerability was found in dokploy up to 0.26.6 . It has been declared as critical . This vulnerability affects the function execAsync . Executing a manipulation of the argument appName can lead to …
A vulnerability was found in Alinto SOGo up to 5.12.7 . It has been rated as critical . This issue affects the function sogo_acl of the file /acls of the component addUserInAcls Endpoint . The manipul…
A vulnerability categorized as problematic has been discovered in jarrodwatts claude-hud up to 0.0.12 on Windows. Impacted is the function execFile of the component Environment Variable Handler . The …
A vulnerability identified as problematic has been detected in BigBlueButton up to 3.0.18 . The affected element is an unknown function. This manipulation causes cross site scripting. This vulnerabili…
A vulnerability labeled as problematic has been found in DumbWareio DumbAssets up to 1.0.11 . The impacted element is an unknown function of the component Asset API Endpoint . Such manipulation leads …
A vulnerability marked as critical has been reported in steipete summarize up to 0.15.0 . This affects an unknown function. Performing a manipulation results in server-side request forgery. This vulne…
A vulnerability described as problematic has been identified in steipete summarize up to 0.15.0 . This impacts an unknown function of the component Config File . Executing a manipulation can lead to i…
A vulnerability classified as problematic has been found in NeoRazorX facturascripts up to 2025.7 . Affected is an unknown function. The manipulation leads to cross site scripting. This vulnerability …
A vulnerability classified as critical was found in HCL Connections 8.0 . Affected by this vulnerability is an unknown functionality. The manipulation results in incorrect authorization. This vulnerab…
Since the last update, the TeamPCP supply chain campaign produced its loudest stretch since the March Trivy disclosure: an officially confirmed Checkmarx Jenkins plugin compromise and a new self-sprea…
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovC…
AI Rebuilds $50B Pharma Giant's Thinking, Plan Could Help Every Data-Driven Firm GSK is redesigning pharmaceutical research around AI, from data infrastructure to autonomous scientific agents. Its pla…
Déjà Vu: Is Mythos in Hands of Bad Actors Akin to Cobalt Strike, Brute Ratel Abuse? Anthropic's Claude Mythos and similarly powerful artificial intelligence tools pose elevated cyber risk to the healt…
Musk's Claims Against Altman and Microsoft Dismissed After Less Than Two Hours A federal jury took less than two hours to dismiss Elon Musk's lawsuit against OpenAI and Sam Altman, finding his claims …
“Something didn’t go as planned. Undoing changes.” That’s all the clue some Windows 11 users will get when Microsoft’s May Security Update fails to install because of insufficient free space on the EF…
From the MGM and Caesars fiasco and MOVEit's patch nightmare to epic business blunders and the jaded reality of living in a post-breach world, Dark Reading looks back at the mistakes, miscalculations,…
The release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm could scale.
The now patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence.
CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes.
A new variant of the 'SHub' macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. [...]