CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6226 articles  ·  updated every 4 hours · grows forever

6226Total
4061Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35666 | OpenClaw up to 2026.3.21 /usr/bin/time name resolution (GHSA-qm9x-v7cx-7rq4)

A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.21 . This vulnerability affects unknown code of the file /usr/bin/time . The manipulation results in incorrectly-resolved na…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35670 | OpenClaw up to 2026.3.21 reliance on untrusted inputs in a security decision (GHSA-wv46-v6xc-2qhf)

A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.21 . This issue affects some unknown processing. This manipulation causes reliance on untrusted inputs in a security de…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-32894 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 delete_mark/resultdelete null pointer dereference (GHSA-rqpg-p95v-fv98)

A vulnerability described as problematic has been identified in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . Impacted is an unknown function. Such manipulation of the argument delete_mark/resultdelete leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-32930 | Chamilo LMS up to 1.11.37 editeval authorization

A vulnerability classified as critical has been found in Chamilo LMS up to 1.11.37 . The affected element is an unknown function. Performing a manipulation of the argument editeval results in authoriz…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-32932 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 External URL id_session redirect

A vulnerability classified as problematic was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . The impacted element is an unknown function of the component External URL Handler . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-33141 | Chamilo LMS up to 2.0.0-RC.2 REST API Stats Endpoint authorization

A vulnerability, which was classified as problematic , has been found in Chamilo LMS up to 2.0.0-RC.2 . This affects an unknown function of the component REST API Stats Endpoint . The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35669 | OpenClaw up to 2026.3.24 operator.admin incorrect privileged apis (GHSA-qm2m-28pf-hgjw)

A vulnerability, which was classified as critical , was found in OpenClaw up to 2026.3.24 . This impacts the function operator.admin . The manipulation results in incorrect use of privileged apis. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35668 | OpenClaw up to 2026.3.23 Configuration Data fileUrl path traversal (GHSA-hr5v-j9h9-xjhg)

A vulnerability has been found in OpenClaw up to 2026.3.23 and classified as critical . Affected is an unknown function of the component Configuration Data Handler . This manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-34727 | go-vikunja up to 2.2.x OIDC Call improper authentication (GHSA-8jvc-mcx6-r4cg)

A vulnerability was found in go-vikunja vikunja up to 2.2.x and classified as critical . Affected by this vulnerability is an unknown functionality of the component OIDC Call Handler . Such manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-31941 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 Social Wall read_url_with_open_graph social_wall_new_msg_main server-side request forgery (GHSA-q74c-mx8x-489h)

A vulnerability was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . It has been classified as critical . Affected by this issue is the function read_url_with_open_graph of the component Social Wall . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40160 | MervinPraison PraisonAIAgents up to 1.5.127 httpx.AsyncClient.get server-side request forgery (GHSA-qq9r-63f6-v542)

A vulnerability was found in MervinPraison PraisonAIAgents up to 1.5.127 . It has been declared as critical . This affects the function httpx.AsyncClient.get . Executing a manipulation can lead to ser…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35641 | OpenClaw up to 2026.3.23 Configuration File acceptance of extraneous untrusted data with trusted data (GHSA-m3mh-3mpg-37hw)

A vulnerability was found in OpenClaw up to 2026.3.23 . It has been rated as problematic . This vulnerability affects unknown code of the component Configuration File Handler . The manipulation leads …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40228 | systemd 259 ANSI Escape Sequence resource transfer

A vulnerability categorized as problematic has been discovered in systemd 259 . This issue affects some unknown processing of the component ANSI Escape Sequence Handler . The manipulation results in i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-22560 | Rocket.Chat up to 8.3.x SAML Endpoint redirect

A vulnerability identified as problematic has been detected in Rocket.Chat up to 8.3.x . Impacted is an unknown function of the component SAML Endpoint . This manipulation causes open redirect. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-32893 | Chamilo LMS up to 2.0.0-RC.2 array_merge cross site scripting (GHSA-37jh-g64j-88mc)

A vulnerability labeled as problematic has been found in Chamilo LMS up to 2.0.0-RC.2 . The affected element is the function array_merge . Such manipulation leads to cross site scripting. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-1502 | Python CPython up to 3.14.x HTTP Client Proxy Tunnel crlf injection (ID 146211)

A vulnerability marked as problematic has been reported in Python CPython up to 3.14.x . The impacted element is an unknown function of the component HTTP Client Proxy Tunnel Handler . Performing a ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-33618 | Chamilo LMS up to 2.0.0-RC.2 /platform-config/list decodeSettingArray eval injection

A vulnerability described as critical has been identified in Chamilo LMS up to 2.0.0-RC.2 . This affects the function PlatformConfigurationController::decodeSettingArray of the file /platform-config/l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-33698 | Chamilo LMS up to 1.11.37 file access

A vulnerability classified as problematic has been found in Chamilo LMS up to 1.11.37 . This impacts an unknown function. The manipulation leads to files or directories accessible. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-33702 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 lp_ajax_save_item.php authorization

A vulnerability classified as problematic was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . Affected is an unknown function of the file lp_ajax_save_item.php . The manipulation results in authorizat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-33703 | Chamilo LMS up to 2.0.0-RC.2 personal-data userId authorization

A vulnerability, which was classified as problematic , has been found in Chamilo LMS up to 2.0.0-RC.2 . Affected by this vulnerability is an unknown functionality of the file /social-network/personal-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-3446 | Python CPython up to 3.13.12/3.14.3/3.15.0a7 b64decode

A vulnerability, which was classified as problematic , was found in Python CPython up to 3.13.12/3.14.3/3.15.0a7 . Affected by this issue is the function b64decode . Such manipulation leads to an unkn…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
[webapps] D-Link DIR-650IN - Authenticated Command Injection

D-Link DIR-650IN - Authenticated Command Injection

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
[local] NetBT e-Fatura - Privilege Escalation

NetBT e-Fatura - Privilege Escalation

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-31412 | Linux Kernel up to 7.0-rc3 USB check_command_size_in_blocks integer overflow

A vulnerability has been found in Linux Kernel up to 7.0-rc3 and classified as critical . Affected by this vulnerability is the function check_command_size_in_blocks of the component USB Handler . The…

VulDB Read →
← Prev 129 / 260 Next →