CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6258 articles  ·  updated every 4 hours · grows forever

6258Total
4063Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-5187 | wolfSSL up to 5.9.0 wolfcrypt/src/asn.c DecodeObjectId heap-based overflow

A vulnerability was found in wolfSSL up to 5.9.0 and classified as critical . The impacted element is the function DecodeObjectId of the file wolfcrypt/src/asn.c . The manipulation results in heap-bas…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40089 | sonicverse-eu audiostreaming-stack Dashboard api.ts server-side request forgery

A vulnerability was found in sonicverse-eu audiostreaming-stack . It has been classified as critical . This affects an unknown function in the library apps/dashboard/lib/api.ts of the component Dashbo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2025-13926 | Contemporary Controls BASControl20 3.1 Network Traffic reliance on untrusted inputs in a security decision

A vulnerability was found in Contemporary Controls BASControl20 3.1 . It has been declared as critical . This impacts an unknown function of the component Network Traffic Handler . Such manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability Exploited in the Wild - CyberSecurityNews

PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability Exploited in the Wild CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
Hackers Targeting Cisco Unified CM Zero-Day - SecurityWeek

Hackers Targeting Cisco Unified CM Zero-Day SecurityWeek

SecurityWeek Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
[local] ZSH 5.9 - RCE

ZSH 5.9 - RCE

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
[webapps] Jumbo Website Manager - Remote Code Execution

Jumbo Website Manager - Remote Code Execution

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
[webapps] RomM 4.4.0 - XSS_CSRF Chain

RomM 4.4.0 - XSS_CSRF Chain

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
[webapps] React Server 19.2.0 - Remote Code Execution

React Server 19.2.0 - Remote Code Execution

Exploit DB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39962 | MISP up to 2.5.35 ApacheAuthenticate.php Username ldap injection (GHSA-mc53-48w8-9g63)

A vulnerability classified as critical has been found in MISP up to 2.5.35 . Affected by this issue is some unknown functionality of the file ApacheAuthenticate.php . The manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39961 | aiven aiven-operator up to 0.36.x namespace privileges management

A vulnerability classified as critical was found in aiven aiven-operator up to 0.36.x . This affects an unknown part. The manipulation of the argument namespace results in improper privilege managemen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39987 | marimo-team marimo up to 0.22.x WebSocket Endpoint /terminal/ws validate_auth missing authentication

A vulnerability, which was classified as critical , has been found in marimo-team marimo up to 0.22.x . This vulnerability affects the function validate_auth of the file /terminal/ws of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39957 | Lychee up to 7.5.3 listAll authorization (GHSA-4v4c-g2jv-4g25)

A vulnerability, which was classified as problematic , was found in Lychee up to 7.5.3 . This issue affects the function SharingController::listAll . Such manipulation leads to incorrect authorization…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39958 | AOSC oma up to 1.25.0 topics.json Name crlf injection (GHSA-86jc-7r6q-cr3f)

A vulnerability has been found in AOSC oma up to 1.25.0 and classified as problematic . Impacted is an unknown function of the file {mirror}/debs/manifest/topics.json . Performing a manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2025-63238 | LimeSurvey up to 6.15.11 URL QuestionCreate.php getInstance gid cross site scripting

A vulnerability was found in LimeSurvey up to 6.15.11 and classified as problematic . The affected element is the function getInstance of the file application/models/QuestionCreate.php of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39959 | tmds Tmds.DBus/Tmds.DBus.Protocol up to 0.91.x SynchronizationContext allocation of resources (GHSA-xrw6-gwf8-vvr9)

A vulnerability was found in tmds Tmds.DBus and Tmds.DBus.Protocol up to 0.91.x . It has been classified as problematic . The impacted element is an unknown function of the component SynchronizationCo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39980 | OpenCTI up to 6.9.4 safeEjs.ts special elements used in a template engine

A vulnerability was found in OpenCTI up to 6.9.4 . It has been declared as problematic . This affects an unknown function of the file safeEjs.ts . The manipulation results in improper neutralization o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39855 | mtrojnar osslsigncode up to 2.12 pe_page_hash_calc out-of-bounds (GHSA-76vv-x5rr-q3mr)

A vulnerability was found in mtrojnar osslsigncode up to 2.12 . It has been rated as problematic . This impacts the function pe_page_hash_calc . This manipulation causes out-of-bounds read. The identi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39856 | mtrojnar osslsigncode up to 2.12 pe_page_hash_calc PointerToRawData/SizeOfRawData out-of-bounds (GHSA-rjrx-chvw-8jw8)

A vulnerability categorized as problematic has been discovered in mtrojnar osslsigncode up to 2.12 . Affected is the function pe_page_hash_calc . Such manipulation of the argument PointerToRawData/Siz…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39972 | dunglas mercure up to 0.21.x TopicSelectorStore improper validation of unsafe equivalence in input (GHSA-hwr4-mq23-wcv5)

A vulnerability identified as critical has been detected in dunglas mercure up to 0.21.x . Affected by this vulnerability is an unknown functionality of the component TopicSelectorStore . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39976 | laravel passport up to 13.7.0 retrieveById improper authentication (ID 1900)

A vulnerability labeled as critical has been found in laravel passport up to 13.7.0 . Affected by this issue is the function retrieveById . Executing a manipulation can lead to improper authentication…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39981 | Josh-XT AGiXT up to 1.9.1 safe_join path traversal

A vulnerability marked as critical has been reported in Josh-XT AGiXT up to 1.9.1 . This affects the function safe_join . The manipulation leads to path traversal. This vulnerability is listed as CVE-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39983 | patrickjuchli basic-ftp up to 5.2.0 path crlf injection

A vulnerability described as problematic has been identified in patrickjuchli basic-ftp up to 5.2.0 . This vulnerability affects the function cd/remove/rename/uploadFrom/downloadTo/list/removeDir . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39985 | aces Loris up to 27.0.2/28.0.0 redirect

A vulnerability classified as problematic has been found in aces Loris up to 27.0.2/28.0.0 . This issue affects some unknown processing. This manipulation causes open redirect. This vulnerability is r…

VulDB Read →
← Prev 135 / 261 Next →