CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  39236 articles  ·  updated every 4 hours · grows forever

39236Total
28596Full Text
Jul 27, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-45346 | open-webui Open WebUI up to 0.6.30 cross site scripting (GHSA-r29h-37fj-x2w6)

A vulnerability categorized as problematic has been discovered in open-webui Open WebUI up to 0.6.30 . This issue affects some unknown processing. The manipulation results in basic cross site scriptin…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-44560 | open-webui Open WebUI up to 0.8.x get_sources_from_items authorization (GHSA-h36f-rqpx-j5wx)

A vulnerability identified as problematic has been detected in open-webui Open WebUI up to 0.8.x . Impacted is the function get_sources_from_items . This manipulation causes missing authorization. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-44562 | open-webui Open WebUI up to 0.8.x /api/v1/models/import authorization (GHSA-mqq6-cqcx-38vg)

A vulnerability labeled as problematic has been found in open-webui Open WebUI up to 0.8.x . The affected element is an unknown function of the file /api/v1/models/import . Such manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-44561 | open-webui Open WebUI up to 0.8.x API is_user_channel_member is_active authorization (GHSA-hmgr-67hw-j2cq)

A vulnerability marked as critical has been reported in open-webui Open WebUI up to 0.8.x . The impacted element is the function is_user_channel_member of the component API . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-44563 | open-webui Open WebUI up to 0.8.x /api/generate authorization (GHSA-rcvp-6fgw-c7fh)

A vulnerability described as critical has been identified in open-webui Open WebUI up to 0.8.x . This affects an unknown function of the file /api/generate . Executing a manipulation can lead to missi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8681 | essentialplugin Essential Chat Support Plugin up to 1.0.1 on WordPress Setting ecs_reset_settings authorization (EUVD-2026-30669)

A vulnerability classified as critical has been found in essentialplugin Essential Chat Support Plugin up to 1.0.1 on WordPress. This impacts the function ecs_reset_settings of the component Setting H…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-4053 | Mattermost up to 10.11.13/11.5.1/11.5.x API Endpoint operation after expiration

A vulnerability classified as problematic was found in Mattermost up to 10.11.13/11.5.1/11.5.x . Affected is an unknown function of the component API Endpoint . The manipulation results in operation o…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-4054 | Mattermost up to 10.11.13/11.4.3/11.5.1/11.5.x SVG File unusual condition

A vulnerability, which was classified as problematic , has been found in Mattermost up to 10.11.13/11.4.3/11.5.1/11.5.x . Affected by this vulnerability is an unknown functionality of the component SV…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8686 | FreeRTOS coreMQTT 5.0.0 out-of-bounds (GHSA-6qh9-r6jp-2wxc)

A vulnerability, which was classified as problematic , was found in FreeRTOS coreMQTT 5.0.0 . Affected by this issue is some unknown functionality. Such manipulation leads to out-of-bounds read. This …

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-45062 | dunglas frankenphp prior 1.12.3 CGI Path Splitting unicode encoding

A vulnerability has been found in dunglas frankenphp and classified as problematic . This affects an unknown part of the component CGI Path Splitting . Performing a manipulation results in improper ha…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8657 | jsondiffpatch up to 0.7.5 jsonpatch.patch jsondiffpatch.patch prototype pollution (SNYK-JS-JSONDIFFPATCH-16322990 / EUVD-2026-30670)

A vulnerability was found in jsondiffpatch up to 0.7.5 and classified as critical . This vulnerability affects the function jsondiffpatch.patch of the file jsondiffpatch/formatters/jsonpatch.patch . E…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8656 | Ruby jsondiffpatch up to 0.7.5 cross site scripting (SNYK-JS-JSONDIFFPATCH-16635946 / EUVD-2026-30671)

A vulnerability was found in Ruby jsondiffpatch up to 0.7.5 . It has been classified as problematic . This issue affects some unknown processing. The manipulation leads to cross site scripting. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8724 | Dataease 2.10.20 Data Dashboard SqlparserUtils.java SqlparserUtils.transFilter sql injection

A vulnerability was found in Dataease 2.10.20 . It has been declared as critical . Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard .…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8725 | CoreWorxLab CAAL up to 1.6.0 test-hass Endpoint src/caal/webhooks.py server-side request forgery

A vulnerability was found in CoreWorxLab CAAL up to 1.6.0 . It has been rated as critical . The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endp…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8728 | Open5GS up to 2.7.7 NRF /lib/sbi/conv.c ogs_sbi_discovery_option_parse_plmn_list target-plmn-list denial of service (Issue 4458)

A vulnerability categorized as problematic has been discovered in Open5GS up to 2.7.7 . The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of …

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8729 | Open5GS up to 2.7.7 NRF /lib/sbi/message.c service-names/snssais denial of service (Issue 4460)

A vulnerability identified as problematic has been detected in Open5GS up to 2.7.7 . This affects an unknown function in the library /lib/sbi/message.c of the component NRF . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8730 | Open5GS up to 2.7.6 NRF /lib/sbi/context.c ogs_sbi_nf_instance_set_id nfInstanceId denial of service (Issue 4462)

A vulnerability labeled as problematic has been found in Open5GS up to 2.7.6 . This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/sbi/context.c of the component NRF . Executing a…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8731 | Open5GS up to 2.7.7 NRF /lib/sbi/client.c ogs_sbi_client_add client_pool denial of service (Issue 4464)

A vulnerability marked as problematic has been reported in Open5GS up to 2.7.7 . Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF . The manipulation of…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8733 | Investintech SlimPDFReader up to 2.0.13 SlimPDFReader.exe sub_3B4610 stack-based overflow

A vulnerability described as critical has been identified in Investintech SlimPDFReader up to 2.0.13 . Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8734 | Oinone Pamirs up to 7.2.0 queryListByWrapper Interface RSQLToSQLNodeConnector.makeVariable sql injection

A vulnerability classified as critical has been found in Oinone Pamirs up to 7.2.0 . Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the component queryListByWrapper Inte…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8735 | Oinone Pamirs up to 7.2.0 appConfigQuery Interface PamirsParserConfig.java JsonUtils.parseMap deserialization

A vulnerability classified as critical was found in Oinone Pamirs up to 7.2.0 . This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interfa…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8736 | Oinone Pamirs up to 7.2.0 RestController LocalFileClient.java request.getParameter uniqueFileName path traversal

A vulnerability, which was classified as critical , has been found in Oinone Pamirs up to 7.2.0 . This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8737 | Sanluan PublicCMS 5.202506.d Trade Address Query TradeAddressListDirective.java execute userId/id missing authentication

A vulnerability, which was classified as problematic , was found in Sanluan PublicCMS 5.202506.d . This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8738 | Sanluan PublicCMS 5.202506.d Trade Payment Flow TradeOrderController.java logic error

A vulnerability has been found in Sanluan PublicCMS 5.202506.d and classified as critical . Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of …

VulDB Read →
← Prev 780 / 1635 Next →