CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6225 articles  ·  updated every 4 hours · grows forever

6225Total
4060Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40180 | quarkiverse quarkus-openapi-generator up to 2.15.x ZIP ApicurioCodegenWrapper.java unzip path traversal (GHSA-jx2w-vp7f-456q)

A vulnerability was found in quarkiverse quarkus-openapi-generator up to 2.15.x . It has been classified as critical . The impacted element is the function unzip of the file ApicurioCodegenWrapper.jav…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-39921 | GeoNode up to 4.4.4/5.0.1 URL doc_url server-side request forgery

A vulnerability was found in GeoNode up to 4.4.4/5.0.1 . It has been declared as critical . This affects an unknown function of the component URL Handler . Such manipulation of the argument doc_url le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-30232 | Chartbrew up to 4.8.4 server-side request forgery (GHSA-p4rg-967r-w4cv)

A vulnerability was found in Chartbrew up to 4.8.4 . It has been rated as critical . This impacts an unknown function. Performing a manipulation results in server-side request forgery. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33737 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 simplexml_load_string xml external entity reference (GHSA-c4ww-qgf2-v89j)

A vulnerability categorized as problematic has been discovered in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . Affected is the function simplexml_load_string . Executing a manipulation can lead to xml exter…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-39922 | GeoNode up to 4.4.4/5.0.1 WMS Service server-side request forgery

A vulnerability identified as critical has been detected in GeoNode up to 4.4.4/5.0.1 . Affected by this vulnerability is an unknown functionality of the component WMS Service . The manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40191 | craigjbass clearancekit up to 5.0.3 Destination authorization

A vulnerability labeled as problematic has been found in craigjbass clearancekit up to 5.0.3 . Affected by this issue is some unknown functionality of the component Destination Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40184 | mauriceboe TREK up to 2.7.1 missing authentication (GHSA-wxx3-84fc-mrx2)

A vulnerability marked as critical has been reported in mauriceboe TREK up to 2.7.1 . This affects an unknown part. This manipulation causes missing authentication. This vulnerability is handled as CV…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40185 | mauriceboe TREK up to 2.7.1 authorization (GHSA-pcr3-6647-jh72)

A vulnerability described as critical has been identified in mauriceboe TREK up to 2.7.1 . This vulnerability affects unknown code. Such manipulation leads to missing authorization. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33118 | Microsoft Edge up to 146.0.3856.84

A vulnerability classified as problematic has been found in Microsoft Edge . This issue affects some unknown processing. Performing a manipulation results in an unknown weakness. This vulnerability wa…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40194 | phpseclib up to 1.0.27/2.0.52/3.0.50 SSH2::get_binary_packet timing discrepancy (GHSA-r854-jrxh-36qx)

A vulnerability classified as problematic was found in phpseclib up to 1.0.27/2.0.52/3.0.50 . Impacted is the function SSH2::get_binary_packet . Executing a manipulation can lead to observable timing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5724 | temporal up to 1.28.3/1.29.5/1.30.3 StreamWorkflowReplicationMessages endpoint missing authentication

A vulnerability, which was classified as critical , has been found in temporal up to 1.28.3/1.29.5/1.30.3 . The affected element is an unknown function of the file streaming AdminService/StreamWorkflo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33119 | Microsoft Edge up to 146.0.3856.84 on Android clickjacking

A vulnerability, which was classified as problematic , was found in Microsoft Edge on Android. The impacted element is an unknown function. The manipulation results in clickjacking. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40252 | labring FastGPT up to 4.14.10.4 access control (GHSA-gc8m-w37w-24hw)

A vulnerability has been found in labring FastGPT up to 4.14.10.4 and classified as critical . This affects an unknown function. This manipulation causes improper access controls. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40242 | getarcaneapp arcane up to 1.17.2 /api/templates/fetch url server-side request forgery (GHSA-ff24-4prj-gpmj)

A vulnerability was found in getarcaneapp arcane up to 1.17.2 and classified as critical . This impacts an unknown function of the file /api/templates/fetch . Such manipulation of the argument url lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35651 | OpenClaw up to 2026.3.24 ANSI Escape Sequence control sequence (GHSA-4hmj-39m8-jwc7)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.3.24 . Impacted is an unknown function of the component ANSI Escape Sequence Handler . Performing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35655 | OpenClaw up to 2026.3.21 rawInput reliance on untrusted inputs in a security decision (GHSA-74wf-h43j-vvmj)

A vulnerability, which was classified as problematic , was found in OpenClaw up to 2026.3.21 . The affected element is an unknown function. Executing a manipulation of the argument rawInput can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35658 | OpenClaw up to 2026.3.1 Image Parser exposure of resource (GHSA-cfp9-w5v9-3q4h)

A vulnerability has been found in OpenClaw up to 2026.3.1 and classified as problematic . The impacted element is an unknown function of the component Image Parser . The manipulation leads to exposure…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40074 | sveltejs SvelteKit up to 2.57.0 location exceptional condition (GHSA-3f6h-2hrp-w5wx)

A vulnerability was found in sveltejs SvelteKit up to 2.57.0 and classified as problematic . This affects an unknown function. The manipulation of the argument location results in handling of exceptio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40097 | smallstep certificates up to 0.30.0-rc2 array index (GHSA-9qq8-cgcv-qmc9)

A vulnerability was found in smallstep certificates up to 0.30.0-rc2 . It has been classified as problematic . This impacts an unknown function. This manipulation causes improper validation of array i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40157 | MervinPraison PraisonAI up to 4.5.127 tar.extract path traversal (GHSA-99g3-w8gr-x37c)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.127 . It has been declared as critical . Affected is the function tar.extract . Such manipulation leads to path traversal. This vulnerabi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35664 | OpenClaw up to 2026.3.24 Legacy Call authentication bypass (GHSA-77w2-crqv-cmv3)

A vulnerability was found in OpenClaw up to 2026.3.24 . It has been rated as critical . Affected by this vulnerability is an unknown functionality of the component Legacy Call Handler . Performing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40162 | Bugsink up to 2.1.0 File (GHSA-8hw4-fhww-273g)

A vulnerability categorized as critical has been discovered in Bugsink up to 2.1.0 . Affected by this issue is some unknown functionality of the component File Handler . Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2025-66447 | Chamilo LMS up to 1.11.0/2.0-beta.1/2.0-beta.2 /login redirect (GHSA-m82x-prv3-rwwv)

A vulnerability identified as problematic has been detected in Chamilo LMS up to 1.11.0/2.0-beta.1/2.0-beta.2 . This affects an unknown part of the file /login . The manipulation of the argument redir…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35666 | OpenClaw up to 2026.3.21 /usr/bin/time name resolution (GHSA-qm9x-v7cx-7rq4)

A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.21 . This vulnerability affects unknown code of the file /usr/bin/time . The manipulation results in incorrectly-resolved na…

VulDB Read →
← Prev 128 / 260 Next →