CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  21231 articles  ·  updated every 4 hours · grows forever

21231Total
18373Full Text
May 19, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43885 | WWBN AVideo up to 29.0 API Endpoint objects/plugins.json.php users_list information disclosure (GHSA-xr49-f4rh-qcjf)

A vulnerability categorized as problematic has been discovered in WWBN AVideo up to 29.0 . This impacts the function users_list of the file objects/plugins.json.php of the component API Endpoint . Suc…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43876 | WWBN AVideo up to 29.0 Raw Message notifySubscribers.json.php sendSiteEmail cross site scripting (GHSA-g9cm-rxp7-6gv5)

A vulnerability identified as problematic has been detected in WWBN AVideo up to 29.0 . Affected is the function sendSiteEmail of the file objects/notifySubscribers.json.php of the component Raw Messa…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43884 | WWBN AVideo up to 29.0 objects/EpgParser.php isSSRFSafeURL server-side request forgery (GHSA-2hch-c97c-g99x)

A vulnerability labeled as critical has been found in WWBN AVideo up to 29.0 . Affected by this vulnerability is the function isSSRFSafeURL of the file objects/EpgParser.php . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43879 | WWBN AVideo up to 29.0 metadata isValidURL server-side request forgery (GHSA-wp38-whx3-xffh)

A vulnerability marked as critical has been reported in WWBN AVideo up to 29.0 . Affected by this issue is the function isValidURL of the file /internal/loopback/metadata . The manipulation leads to s…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43873 | WWBN AVideo up to 29.0 Rejection Message cloneClient.json.php die objClone information exposure (GHSA-qm9p-p5pw-jrx2)

A vulnerability described as problematic has been identified in WWBN AVideo up to 29.0 . This affects the function die of the file plugin/CloneSite/cloneClient.json.php of the component Rejection Mess…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43875 | WWBN AVideo up to 29.0 Password Hash oauth2.php get request method with sensitive query strings (GHSA-5w8w-26ch-v5cw)

A vulnerability classified as problematic has been found in WWBN AVideo up to 29.0 . This vulnerability affects unknown code of the file plugin/MobileManager/oauth2.php of the component Password Hash …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43877 | WWBN AVideo up to 29.0 userSavePhoto.php User::isLogged cross-site request forgery (GHSA-jw8g-5j46-44rp)

A vulnerability classified as problematic was found in WWBN AVideo up to 29.0 . This issue affects the function User::isLogged of the file objects/userSavePhoto.php . Such manipulation leads to cross-…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43878 | WWBN AVideo up to 29.0 URL plugin/Meet/iframe.php cross site scripting (GHSA-mm5f-8q57-4fc4)

A vulnerability, which was classified as problematic , has been found in WWBN AVideo up to 29.0 . Impacted is an unknown function of the file plugin/Meet/iframe.php of the component URL Handler . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43880 | WWBN AVideo up to 29.0 Endpoint sendEmail.json.php sendTo verification of source (GHSA-5hgj-7gm9-cff5)

A vulnerability, which was classified as problematic , was found in WWBN AVideo up to 29.0 . The affected element is an unknown function of the file objects/sendEmail.json.php of the component Endpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43882 | WWBN AVideo up to 29.0 downloadICS.php Scheduler::downloadICS joinURL crlf injection (GHSA-mwgh-92m2-wvhv)

A vulnerability has been found in WWBN AVideo up to 29.0 and classified as problematic . The impacted element is the function Scheduler::downloadICS of the file plugin/Scheduler/downloadICS.php . The …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43883 | WWBN AVideo up to 29.0 Subscription agreementCancel.json.php authorization (GHSA-958h-qp3x-q4gj)

A vulnerability was found in WWBN AVideo up to 29.0 and classified as problematic . This affects an unknown function of the file plugin/PayPalYPT/agreementCancel.json.php of the component Subscription…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43887 | Outline up to 1.6.x cross site scripting (GHSA-rqrg-f3qc-xvgh)

A vulnerability was found in Outline up to 1.6.x . It has been classified as problematic . This impacts an unknown function. This manipulation causes cross site scripting. The identification of this v…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43897 | OP-Engineering link-preview-js up to 4.0.0 Link Preview server-side request forgery (GHSA-4gp8-rjrq-ch6q)

A vulnerability was found in OP-Engineering link-preview-js up to 4.0.0 . It has been declared as critical . Affected is an unknown function of the component Link Preview Handler . Such manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43893 | photostructure exiftool-vendored.js up to 35.18.x argument injection (GHSA-cw26-7653-2rp5)

A vulnerability was found in photostructure exiftool-vendored.js up to 35.18.x . It has been rated as critical . Affected by this vulnerability is an unknown functionality. Performing a manipulation r…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43889 | Outline up to 1.6.x shares.create API authorization (GHSA-rg4j-pmch-w6pm)

A vulnerability categorized as problematic has been discovered in Outline up to 1.6.x . Affected by this issue is some unknown functionality of the component shares.create API . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-44695 | Outline up to 1.7.0 /auth/slack.post team_id/user_id cross-site request forgery (GHSA-mjgw-5j7q-gv8v)

A vulnerability identified as problematic has been detected in Outline up to 1.7.0 . This affects an unknown part of the file /auth/slack.post . The manipulation of the argument team_id/user_id leads …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43874 | WWBN AVideo up to 29.0 Outbound Message getWebSocket.json.php msgToResourceId json code injection (GHSA-ghcv-22jf-vfxm)

A vulnerability labeled as critical has been found in WWBN AVideo up to 29.0 . This vulnerability affects the function msgToResourceId of the file plugin/YPTSocket/getWebSocket.json.php of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43890 | Outline up to 1.7.0 API Endpoint subscriptions.create authorization (GHSA-gf8h-cv9v-q4fw)

A vulnerability marked as problematic has been reported in Outline up to 1.7.0 . This issue affects the function subscriptions.create of the component API Endpoint . This manipulation causes authoriza…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43888 | Outline up to 1.6.x fs.createWriteStream path traversal (GHSA-hw32-2v7j-mgqc)

A vulnerability described as critical has been identified in Outline up to 1.6.x . Impacted is the function fs.createWriteStream . Such manipulation leads to path traversal. This vulnerability is docu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-7010 | HAARG HTTP::Tiny up to 0.092 on Perl HTTP Request Host response splitting (EUVD-2026-29344)

A vulnerability classified as critical has been found in HAARG HTTP::Tiny up to 0.092 on Perl. The affected element is an unknown function of the component HTTP Request Handler . Performing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-34960 | barebox up to 2026.04.0 DHCP dhcp_message_type out-of-bounds

A vulnerability classified as problematic was found in barebox up to 2026.04.0 . The impacted element is the function dhcp_message_type of the component DHCP Handler . Executing a manipulation can lea…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42888 | advplyr audiobookshelf up to 2.33.1 Podcast Creation Endpoint PodcastController.js path traversal (GHSA-phch-9734-wrp3)

A vulnerability, which was classified as critical , has been found in advplyr audiobookshelf up to 2.33.1 . This affects an unknown function of the file server/controllers/PodcastController.js of the …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-41489 | Pi-hole up to 6.4.1 pihole-FTL-prestart.sh permission assignment (GHSA-6w8x-p785-6pm4)

A vulnerability, which was classified as problematic , was found in Pi-hole up to 6.4.1 . This impacts an unknown function of the file pihole-FTL-prestart.sh . The manipulation results in incorrect pe…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-37630 | QuickJS-NG 0.12.1 js_mapped_arguments_mark privilege escalation (Issue 1400)

A vulnerability has been found in QuickJS-NG 0.12.1 and classified as critical . Affected is the function js_mapped_arguments_mark . This manipulation causes privilege escalation. This vulnerability i…

VulDB Read →
← Prev 92 / 885 Next →