CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6258 articles  ·  updated every 4 hours · grows forever

6258Total
4063Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-2104 | GitLab Community Edition/Enterprise Edition up to 18.8.8/18.9.4/18.10.2 authorization

A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . It has been rated as problematic . This impacts an unknown function. Performing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-2619 | GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 Private Project authorization (EUVD-2026-20799)

A vulnerability categorized as problematic has been discovered in GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . Affected is an unknown function of the component Private Project Handler . Exe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-4332 | GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 Analytics Dashboard cross site scripting (EUVD-2026-20800)

A vulnerability identified as problematic has been detected in GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . Affected by this vulnerability is an unknown functionality of the component Analy…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-3199 | Sonatype Nexus Repository up to 3.90.x deserialization

A vulnerability labeled as critical has been found in Sonatype Nexus Repository up to 3.90.x . Affected by this issue is some unknown functionality. The manipulation results in deserialization. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5173 | GitLab Community Edition/Enterprise Edition up to 18.8.8/18.9.4/18.10.2 Websocket Connection routine (EUVD-2026-20802)

A vulnerability marked as critical has been reported in GitLab Community Edition and Enterprise Edition up to 18.8.8/18.9.4/18.10.2 . This affects an unknown part of the component Websocket Connection…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40029 | khyrenz parseusbs up to 1.8 LNK File Parser parseUSBs.py os.popen os command injection

A vulnerability described as critical has been identified in khyrenz parseusbs up to 1.8 . This vulnerability affects the function os.popen of the file parseUSBs.py of the component LNK File Parser . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40030 | khyrenz parseusbs up to 1.8 Volume popen path os command injection

A vulnerability classified as critical has been found in khyrenz parseusbs up to 1.8 . This issue affects the function popen of the component Volume Handler . Performing a manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40032 | tclahr UAC up to 3.2.0 Placeholder _run_command os command injection (ID 429)

A vulnerability classified as critical was found in tclahr UAC up to 3.2.0 . Impacted is the function _run_command of the component Placeholder Handler . Executing a manipulation can lead to os comman…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40037 | OpenClaw up to 2026.3.30/2026.4.7 Request Body redirect (GHSA-qx8j-g322-qj6m)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.3.30/2026.4.7 . The affected element is an unknown function of the component Request Body Handler . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5711 | pubudu-malalasekara Post Blocks & Tools Plugin up to 1.3.0 on WordPress cross site scripting

A vulnerability, which was classified as problematic , was found in pubudu-malalasekara Post Blocks & Tools Plugin up to 1.3.0 on WordPress. The impacted element is an unknown function. The manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39901 | monetr up to 1.12.2 Transaction Update Endpoint improper authorization (GHSA-hqxq-hwqf-wg83)

A vulnerability has been found in monetr up to 1.12.2 and classified as critical . This affects an unknown function of the component Transaction Update Endpoint . This manipulation causes improper aut…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39889 | MervinPraison PraisonAI up to 4.5.114 Endpoint /a2u/ create_a2u_routes information disclosure (GHSA-f292-66h9-fpmf)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.114 and classified as problematic . This impacts the function create_a2u_routes of the file /a2u/ of the component Endpoint . Such manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39891 | MervinPraison PraisonAI up to 4.5.114 File Content create_agent_centric_tools code injection (GHSA-hwg5-x759-7wjg)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.114 . It has been classified as critical . Affected is the function create_agent_centric_tools of the component File Content Handler . Pe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-5451 | hupe13 Extensions for Leaflet Map Plugin up to 4.14 on WordPress Shortcode elevation-track cross site scripting

A vulnerability was found in hupe13 Extensions for Leaflet Map Plugin up to 4.14 on WordPress. It has been declared as problematic . Affected by this vulnerability is the function elevation-track of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39411 | LobeHub up to 2.1.47 /webapi/chat/ improper authentication (GHSA-5mwj-v5jw-5c97)

A vulnerability was found in LobeHub up to 2.1.47 . It has been rated as critical . Affected by this issue is some unknown functionality of the file /webapi/chat/ . The manipulation leads to improper …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39883 | open-telemetry opentelemetry-go up to 1.42.x untrusted search path (GHSA-hfvc-g4fc-pqhx)

A vulnerability categorized as problematic has been discovered in open-telemetry opentelemetry-go up to 1.42.x . This affects an unknown part. The manipulation results in untrusted search path. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39862 | Shopify tophat up to 2.5.0 URL Parser /bin/bash os command injection (GHSA-8x8g-6rv5-mgg2)

A vulnerability identified as critical has been detected in Shopify tophat up to 2.5.0 . This vulnerability affects unknown code of the file /bin/bash of the component URL Parser . This manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-35479 | InvenTree up to 1.2.6 improper authorization (GHSA-7c3q-vwcv-2vp7)

A vulnerability labeled as critical has been found in InvenTree up to 1.2.6 . This issue affects some unknown processing. Such manipulation leads to improper authorization. This vulnerability is uniqu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-3438 | Sonatype Nexus Repository up to 3.90.x cross site scripting

A vulnerability marked as problematic has been reported in Sonatype Nexus Repository up to 3.90.x . Impacted is an unknown function. Performing a manipulation results in cross site scripting. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-40028 | Yamato-Security hayabusa up to 3.7.0/3.7.x Computer cross site scripting

A vulnerability described as problematic has been identified in Yamato-Security hayabusa up to 3.7.0/3.7.x . The affected element is an unknown function. Executing a manipulation of the argument Compu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39416 | ail-project ail-framework up to 6.7 cross site scripting (GHSA-fj6v-43r7-gcjm)

A vulnerability classified as problematic has been found in ail-project ail-framework up to 6.7 . The impacted element is an unknown function. The manipulation leads to cross site scripting. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
CVE-2026-39885 | agentfront frontmcp/adapters/sdk/mcp-from-openapi Model Context Protocol initialize ref server-side request forgery (GHSA-v6ph-xcq9-qxxj)

A vulnerability classified as critical was found in agentfront frontmcp, adapters, sdk and mcp-from-openapi . This affects the function initialize of the component Model Context Protocol . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 09, 2026
Critical Airleader Vulnerability Exposes Systems to Exploitable Remote Attacks - gbhackers.com

Critical Airleader Vulnerability Exposes Systems to Exploitable Remote Attacks gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-33350 | aces Loris up to 27.0.2/28.0.0 sql injection

A vulnerability categorized as critical has been discovered in aces Loris up to 27.0.2/28.0.0 . Impacted is an unknown function. Executing a manipulation can lead to sql injection. This vulnerability …

VulDB Read →
← Prev 139 / 261 Next →