CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6152 articles  ·  updated every 4 hours · grows forever

6152Total
4056Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33020 | saitoha libsixel up to 1.8.6 SIXEL Encoder sixel_frame_convert_to_rgb888 heap-based overflow

A vulnerability described as critical has been identified in saitoha libsixel up to 1.8.6 . Affected is the function sixel_frame_convert_to_rgb888 of the component SIXEL Encoder . The manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33146 | docmost up to 0.70.2 Public Search Endpoint /api/search/share-search improper authorization (GHSA-qq4c-8rjr-w42c)

A vulnerability classified as critical has been found in docmost up to 0.70.2 . Affected by this vulnerability is an unknown functionality of the file /api/search/share-search of the component Public …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-34212 | docmost up to 0.70.x cross site scripting (GHSA-cf68-cff9-hq4w)

A vulnerability classified as problematic was found in docmost up to 0.70.x . Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40091 | authzed spicedb up to 1.51.0 log file

A vulnerability, which was classified as problematic , has been found in authzed spicedb up to 1.51.0 . This affects an unknown part. Performing a manipulation results in sensitive information in log …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2025-54550 | Apache Airflow up to 3.1.x example_xcom code injection

A vulnerability, which was classified as critical , was found in Apache Airflow up to 3.1.x . This vulnerability affects the function example_xcom . Executing a manipulation can lead to code injection…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-6328 | XQUIC up to 1.8.3 on Linux QUIC Protocol input validation

A vulnerability has been found in XQUIC up to 1.8.3 on Linux and classified as critical . This issue affects some unknown processing of the component QUIC Protocol Handler . The manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33414 | containers podman up to 5.8.1 VM Image Parser stubber.go os command injection (GHSA-hc8w-h2mf-hp59)

A vulnerability was found in containers podman up to 5.8.1 and classified as critical . Impacted is an unknown function of the file pkg/machine/hyperv/stubber.go of the component VM Image Parser . The…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-35589 | HKUDS nanobot up to 0.1.4 Bridge API bridge/src/server.ts BRIDGE_TOKEN missing origin validation in websockets (GHSA-v5j3-4q66-58cf)

A vulnerability was found in HKUDS nanobot up to 0.1.4 . It has been classified as problematic . The affected element is an unknown function of the file bridge/src/server.ts of the component Bridge AP…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40688 | Fortinet FortiWeb up to 7.4.11/7.6.6/8.0.3 out-of-bounds write (FG-IR-26-127)

A vulnerability was found in Fortinet FortiWeb up to 7.4.11/7.6.6/8.0.3 . It has been declared as critical . The impacted element is an unknown function. Such manipulation leads to out-of-bounds write…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-34619 | Adobe ColdFusion up to 2023.18/2025.6 path traversal (apsb26-38)

A vulnerability was found in Adobe ColdFusion up to 2023.18/2025.6 . It has been rated as critical . This affects an unknown function. Performing a manipulation results in path traversal. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40291 | Chamilo LMS up to 2.0-RC.2 /api/users/ privileges management

A vulnerability categorized as critical has been discovered in Chamilo LMS up to 2.0-RC.2 . This impacts an unknown function of the file /api/users/ . Executing a manipulation can lead to improper pri…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-27282 | Adobe ColdFusion up to 2023.18/2025.6 input validation (apsb26-38)

A vulnerability identified as problematic has been detected in Adobe ColdFusion up to 2023.18/2025.6 . Affected is an unknown function. The manipulation leads to improper input validation. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40096 | immich up to 2.7.2 Name cross site scripting

A vulnerability labeled as problematic has been found in immich up to 2.7.2 . Affected by this vulnerability is an unknown functionality of the component Name Handler . The manipulation results in cro…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-34454 | oauth2-proxy OAuth2 Proxy up to 7.15.1 Logout/Sign-out session expiration (GHSA-f24x-5g9q-753f)

A vulnerability marked as critical has been reported in oauth2-proxy OAuth2 Proxy up to 7.15.1 . Affected by this issue is some unknown functionality of the component Logout/Sign-out . This manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40090 | zarf-dev zarf up to 0.74.1 Metadata.Name path traversal

A vulnerability described as critical has been identified in zarf-dev zarf up to 0.74.1 . This affects an unknown part. Such manipulation of the argument Metadata.Name leads to path traversal. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40499 | radareorg radare2 up to 6.1.3 PDB Parser print_gvars os command injection

A vulnerability classified as critical has been found in radareorg radare2 up to 6.1.3 . This vulnerability affects the function print_gvars of the component PDB Parser . Performing a manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-39884 | Flux159 mcp-server-kubernetes up to 3.4.x Model Context Protocol port_forward.ts spawn argument injection

A vulnerability classified as critical was found in Flux159 mcp-server-kubernetes up to 3.4.x . This issue affects the function spawn of the file src/tools/port_forward.ts of the component Model Conte…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-2834 | tokenoftrust Age Verification & Identity Verification by Token of Trust Plugin cross site scripting

A vulnerability, which was classified as problematic , has been found in tokenoftrust Age Verification & Identity Verification by Token of Trust Plugin up to 3.32.3 on WordPress. Impacted is an unknow…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-35032 | Jellyfin up to 10.11.6 /LiveTv/TunerHosts server-side request forgery (GHSA-8fw7-f233-ffr8)

A vulnerability, which was classified as critical , was found in Jellyfin up to 10.11.6 . The affected element is an unknown function of the file /LiveTv/TunerHosts . The manipulation results in serve…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33193 | Docmost up to 0.69.x MIME cross site scripting

A vulnerability has been found in Docmost up to 0.69.x and classified as problematic . The impacted element is an unknown function of the component MIME Handler . This manipulation causes cross site s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5397 | Omron Social Solutions PowerAttendant Standard Edition uncontrolled search path (OMSR-2026-001)

A vulnerability was found in Omron Social Solutions PowerAttendant Standard Edition and classified as problematic . This affects an unknown function. Such manipulation leads to uncontrolled search pat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33806 | Fastify up to 5.8.4 Header Content-Type improper validation of specified type of input

A vulnerability was found in Fastify up to 5.8.4 . It has been classified as problematic . This impacts an unknown function of the component Header Handler . Performing a manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-26291 | GROWI up to 7.4.6 cross site scripting

A vulnerability was found in GROWI up to 7.4.6 . It has been declared as problematic . Affected is an unknown function. Executing a manipulation can lead to cross site scripting. The identification of…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40105 | XWiki xwiki-platform up to 16.10.15/17.4.7/17.10.0 templates/changesdoc.vm cross site scripting

A vulnerability was found in XWiki xwiki-platform up to 16.10.15/17.4.7/17.10.0 . It has been rated as problematic . Affected by this vulnerability is an unknown functionality of the file templates/ch…

VulDB Read →
← Prev 108 / 257 Next →