CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6258 articles  ·  updated every 4 hours · grows forever

6258Total
4063Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39942 | Directus up to 11.16.x /files/ filename_disk access control (GHSA-393c-p46r-7c95)

A vulnerability classified as critical was found in Directus up to 11.16.x . Impacted is an unknown function of the file /files/ . Such manipulation of the argument filename_disk leads to improper acc…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39943 | Directus up to 11.16.x information disclosure (GHSA-mvv8-v4jj-g47j)

A vulnerability, which was classified as problematic , has been found in Directus up to 11.16.x . The affected element is an unknown function. Performing a manipulation results in information disclosu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-30479 | OSGeo MapServer up to 7.x injection

A vulnerability, which was classified as critical , was found in OSGeo MapServer up to 7.x . The impacted element is an unknown function. Executing a manipulation can lead to injection. This vulnerabi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-30478 | GatewayGeo MapServer for Windows on Windows injection

A vulnerability has been found in GatewayGeo MapServer for Windows on Windows and classified as critical . This affects an unknown function. The manipulation leads to injection. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2025-70797 | LimeSurvey 6.15.20 Box[title]/box[url] cross site scripting

A vulnerability was found in LimeSurvey 6.15.20 and classified as problematic . This impacts an unknown function. The manipulation of the argument Box[title]/box[url] results in cross site scripting. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40071 | pyLoad up to 0.5.0b3.dev96 WebUI JSON Endpoint /json/package_order authorization

A vulnerability was found in pyLoad up to 0.5.0b3.dev96 . It has been classified as problematic . Affected is an unknown function of the file /json/package_order of the component WebUI JSON Endpoint .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40069 | sgbett bsv-ruby-sdk up to 0.8.1 Transaction BSV::Network txStatus unusual condition

A vulnerability was found in sgbett bsv-ruby-sdk up to 0.8.1 . It has been declared as problematic . Affected by this vulnerability is the function BSV::Network of the component Transaction Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40070 | sgbett bsv-ruby-sdk/bsv-sdk/bsv-wallet prior 0.8.2 WalletClient signature verification

A vulnerability was found in sgbett bsv-ruby-sdk, bsv-sdk and bsv-wallet . It has been rated as critical . Affected by this issue is the function BSV::Wallet::WalletClient . Performing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40072 | Ethereum web3.py up to 7.14.x/8.0.0b1 Backend Service eth_call/call offchain_lookup_payload["urls"] server-side request forgery

A vulnerability categorized as critical has been discovered in Ethereum web3.py up to 7.14.x/8.0.0b1 . This affects the function eth_call/call of the component Backend Service . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5329 | Rapid7 Velociraptor up to 0.74.6/0.75.6/0.76.1 Client Monitoring Message handler input validation

A vulnerability identified as critical has been detected in Rapid7 Velociraptor up to 0.74.6/0.75.6/0.76.1 . This vulnerability affects unknown code of the component Client Monitoring Message handler …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39315 | unjs unhead up to 2.1.12 safe.ts useHeadSafe incomplete blacklist (GHSA-95h2-gj7x-gx9w)

A vulnerability labeled as critical has been found in unjs unhead up to 2.1.12 . This issue affects the function useHeadSafe of the file packages/unhead/src/plugins/safe.ts . The manipulation results …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39911 | hashgraph guardian up to 3.5.0 Environment Variable exposure of resource

A vulnerability marked as critical has been reported in hashgraph guardian up to 3.5.0 . Impacted is an unknown function of the component Environment Variable Handler . This manipulation causes exposu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34941 | bytecodealliance wasmtime up to 24.0.6/36.0.6/42.0.1/44.0.0 out-of-bounds (GHSA-hx6p-xpx3-jvvv)

A vulnerability described as problematic has been identified in bytecodealliance wasmtime up to 24.0.6/36.0.6/42.0.1/44.0.0 . The affected element is an unknown function. Such manipulation leads to ou…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34942 | bytecodealliance wasmtime up to 24.0.6/36.0.6/42.0.1/44.0.0 array index (GHSA-jxhv-7h78-9775)

A vulnerability classified as problematic has been found in bytecodealliance wasmtime up to 24.0.6/36.0.6/42.0.1/44.0.0 . The impacted element is an unknown function. Performing a manipulation results…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-35207 | linuxdeepin dde-control-center/deepin-deepinid-plugin prior 5.9.9/6.1.80 Deepinid Cloud Service certificate validation (GHSA-jf2h-4vqc-3jgc)

A vulnerability classified as critical was found in linuxdeepin dde-control-center and deepin-deepinid-plugin . This affects an unknown function of the component Deepinid Cloud Service . Executing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-6014 | D-Link DIR-513 1.10 POST Request /goform/formAdvanceSetup webpage buffer overflow

A vulnerability has been found in D-Link DIR-513 1.10 and classified as critical . This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-6015 | Tenda AC9 15.03.02.13 POST Request /goform/QuickIndex formQuickIndex PPPOEPassword stack-based overflow

A vulnerability was found in Tenda AC9 15.03.02.13 and classified as critical . Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler . Such mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-6016 | Tenda AC9 15.03.02.13 POST Request /goform/WizardHandle decodePwd WANS stack-based overflow

A vulnerability was found in Tenda AC9 15.03.02.13 . It has been classified as critical . The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-34578 | opnsense core up to 26.1.5 ldap_escape Username ldap injection (GHSA-jpm7-f59c-mp54)

A vulnerability was found in opnsense core up to 26.1.5 . It has been declared as critical . The impacted element is the function ldap_escape . Executing a manipulation of the argument Username can le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2025-14551 | Canonical Subiquity up to 24.04.4/25.04/25.10 Wi-Fi Password exposure of sensitive system information due to uncleared debug information

A vulnerability was found in Canonical Subiquity up to 24.04.4/25.04/25.10 . It has been rated as problematic . This affects an unknown function of the component Wi-Fi Password Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2025-15480 | Canonical Ubuntu-desktop-provision up to 24.04.4/25.04/25.10 Password Hash exposure of sensitive system information due to uncleared debug information

A vulnerability categorized as problematic has been discovered in Canonical Ubuntu-desktop-provision up to 24.04.4/25.04/25.10 . This impacts an unknown function of the component Password Hash Handler…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5438 | Orthanc DICOM Server up to 1.12.10 Gzip Content-Encoding allocation of resources

A vulnerability identified as problematic has been detected in Orthanc DICOM Server up to 1.12.10 . Affected is an unknown function of the component Gzip Handler . This manipulation of the argument Co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4112 | SonicWall SMA1000 up to 12.4.3-03245/12.5.0-02283 sql injection (SNWLID-2026-0003)

A vulnerability labeled as critical has been found in SonicWall SMA1000 up to 12.4.3-03245/12.5.0-02283 . Affected by this vulnerability is an unknown functionality. Such manipulation leads to sql inj…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-35040 | nearform fast-jwt up to 6.2.0 verify comparison

A vulnerability marked as problematic has been reported in nearform fast-jwt up to 6.2.0 . Affected by this issue is the function verify . Performing a manipulation of the argument allowedAud/allowedI…

VulDB Read →
← Prev 136 / 261 Next →