CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10298 articles  ·  updated every 4 hours · grows forever

10298Total
4235Full Text
Jun 30, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-49414 | FreeBSD ELF Image early validation

A vulnerability was found in FreeBSD . It has been classified as critical . This issue affects some unknown processing of the component ELF Image Handler . The manipulation leads to incorrect behavior…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13335 | codepeople CodePeople Post Map for Google Maps Plugin up to 1.2.6 on WordPress cross site scripting

A vulnerability classified as problematic has been found in codepeople CodePeople Post Map for Google Maps Plugin up to 1.2.6 on WordPress. Affected by this vulnerability is an unknown functionality. …

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-53576 | kestra-io kestra up to 1.0.44/1.3.20 /api/v1 code injection (GHSA-2q47-568g-9h4f)

A vulnerability classified as critical was found in kestra-io kestra up to 1.0.44/1.3.20 . Affected by this issue is some unknown functionality of the file /api/v1 . The manipulation results in code i…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-54353 | budibase up to 3.39.8 Socket Connection toctou (GHSA-gfq7-5x4g-3xhf)

A vulnerability, which was classified as critical , has been found in budibase up to 3.39.8 . This affects an unknown part of the component Socket Connection Handler . This manipulation causes time-of…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-36478 | Technitium DNS Server up to 14.3 DnsServerApp.exe denial of service

A vulnerability, which was classified as problematic , was found in Technitium DNS Server up to 14.3 . This vulnerability affects unknown code in the library DnsServerApp.dll of the file DnsServerApp.…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-33560 | Daktronics VFC-DMP-5000/DMP-5000/DMP-8000 prior 8.117.x.x/9.43.x.x/10.34.x.x File Extension unrestricted upload (icsa-26-176-04)

A vulnerability has been found in Daktronics VFC-DMP-5000, DMP-5000 and DMP-8000 and classified as critical . This issue affects some unknown processing of the component File Extension Handler . Perfo…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-28701 | Daktronics VFC-DMP-5000/DMP-5000/DMP-8000 prior 8.117.x.x/9.43.x.x/10.34.x.x path traversal (icsa-26-176-04)

A vulnerability was found in Daktronics VFC-DMP-5000, DMP-5000 and DMP-8000 and classified as critical . Impacted is an unknown function. Executing a manipulation can lead to path traversal. The ident…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-53577 | kestra-io kestra up to 1.0.44/1.3.20 previewFileFromExecution Endpoint /api/v1 authorization (GHSA-r6v3-xxwj-9h42 / EUVD-2026-39918)

A vulnerability was found in kestra-io kestra up to 1.0.44/1.3.20 . It has been classified as problematic . The affected element is an unknown function of the file /api/v1 of the component previewFile…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-50136 | budibase up to 3.39.2 missing authentication (GHSA-jj36-r9w3-3pfh / EUVD-2026-39912)

A vulnerability was found in budibase up to 3.39.2 . It has been declared as critical . The impacted element is an unknown function. The manipulation results in missing authentication. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-50137 | budibase up to 3.38.x /api/attachments getSignedUploadURL authorization (GHSA-35c4-rvc8-frhm)

A vulnerability was found in budibase up to 3.38.x . It has been rated as problematic . This affects the function packages/server/src/api/controllers/static/index.ts::getSignedUploadURL of the file /a…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-52884 | notepad-plus-plus Notepad++ 8.9.6.1 RunDlg.cpp isInTrustedDirectory path equivalence (GHSA-p58x-r3c9-x9p6)

A vulnerability categorized as critical has been discovered in notepad-plus-plus Notepad++ 8.9.6.1 . This impacts the function isInTrustedDirectory of the file RunDlg.cpp . Such manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-52885 | notepad-plus-plus Notepad++ up to 8.9.6.4 NppCommands.cpp toctou (GHSA-qm4c-qg8p-qfcr)

A vulnerability identified as problematic has been detected in notepad-plus-plus Notepad++ up to 8.9.6.4 . Affected is an unknown function of the file NppCommands.cpp . Performing a manipulation resul…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-54351 | budibase up to 3.39.8 Webhook Trigger Endpoint externalTrigger dynamically-determined object attributes (GHSA-rgvg-3wpc-h44p)

A vulnerability labeled as problematic has been found in budibase up to 3.39.8 . Affected by this vulnerability is the function externalTrigger of the component Webhook Trigger Endpoint . Executing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-54352 | budibase up to 3.39.8 /api/pwa/process-zip createReadStream path traversal (GHSA-w7mq-r738-x278 / EUVD-2026-39910)

A vulnerability marked as critical has been reported in budibase up to 3.39.8 . Affected by this issue is the function createReadStream of the file /api/pwa/process-zip . The manipulation leads to pat…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-36908 | Axiomatic axiomatic-systems prior 1.8.9allow EnsureCapacity stack-based overflow (Issue 1005)

A vulnerability described as critical has been identified in Axiomatic axiomatic-systems . This affects the function AP4_Array::EnsureCapacity . The manipulation results in stack-based buffer overflow…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-11356 | vinod-dalvi Ivory Search Plugin up to 5.5.15 on WordPress Setting menu_magnifier_color cross site scripting

A vulnerability classified as problematic has been found in vinod-dalvi Ivory Search Plugin up to 5.5.15 on WordPress. This vulnerability affects unknown code of the component Setting Handler . This m…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-13422 | harmonic_design HD Quiz Plugin up to 2.2.1 on WordPress Setting hdq_validate_nonce cross-site request forgery

A vulnerability classified as problematic was found in harmonic_design HD Quiz Plugin up to 2.2.1 on WordPress. This issue affects the function hdq_validate_nonce of the component Setting Handler . Su…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-55975 | H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229 Certificate os command injection

A vulnerability, which was classified as critical , has been found in H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229 . Impacted is an unknown function of the component Certificate Handler . Performin…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-56414 | H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229 unrestricted upload

A vulnerability, which was classified as critical , was found in H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229 . The affected element is an unknown function. Executing a manipulation can lead to unr…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-45807 | kestra-io kestra up to 1.0.42/1.3.18 Local Storage Backend URI.toString path traversal (GHSA-3529-p4wf-xp79)

A vulnerability has been found in kestra-io kestra up to 1.0.42/1.3.18 and classified as critical . The impacted element is the function URI.toString of the component Local Storage Backend . The manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-49984 | kestra-io kestra up to 1.0.44/1.3.22 Local internal-storage Backend /api/v1 path traversal (GHSA-qw4v-6w32-xx9h)

A vulnerability was found in kestra-io kestra up to 1.0.44/1.3.22 and classified as critical . This affects an unknown function of the file /api/v1 of the component Local internal-storage Backend . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-38571 | Tenda N300 missing authentication

A vulnerability was found in Tenda N300 . It has been classified as critical . This impacts an unknown function. This manipulation causes missing authentication. The identification of this vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-54350 | budibase up to 3.39.11 JSON Parser queries.ts collection.find sql injection (GHSA-8qv3-p479-cj62)

A vulnerability was found in budibase up to 3.39.11 . It has been declared as critical . Affected is the function collection.find of the file packages/server/src/sdk/workspace/queries/queries.ts of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 27, 2026
CVE-2026-50765 | Koha Library Management System up to 25.11 cross site scripting

A vulnerability was found in Koha Library Management System up to 25.11 . It has been rated as problematic . Affected by this vulnerability is an unknown functionality. Performing a manipulation resul…

VulDB Read →
← Prev 14 / 430 Next →