CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6318 articles  ·  updated every 4 hours · grows forever

6318Total
4065Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39374 | makeplane up to 1.2.x IssueBulkUpdateDateEndpoint start_date/target_date authorization (GHSA-4q54-h4x9-m329)

A vulnerability, which was classified as problematic , was found in makeplane plane up to 1.2.x . Affected by this vulnerability is an unknown functionality of the component IssueBulkUpdateDateEndpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34080 | flatpak xdg-dbus-proxy up to 0.1.6 improper validation of unsafe equivalence in input (GHSA-vjp5-hjfm-7677)

A vulnerability has been found in flatpak xdg-dbus-proxy up to 0.1.6 and classified as problematic . Affected by this issue is some unknown functionality. This manipulation causes improper validation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-29181 | open-telemetry opentelemetry-go up to 1.40.x Header Field allocation of resources (GHSA-mh2q-q3fh-2475)

A vulnerability was found in open-telemetry opentelemetry-go up to 1.40.x and classified as problematic . This affects an unknown part of the component Header Field Handler . Such manipulation leads t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39364 | vitejs vite up to 7.3.1/8.0.4 Query Parameter incorrect behavior order: validate before canonicalize (GHSA-v2wj-q39q-566r)

A vulnerability was found in vitejs vite up to 7.3.1/8.0.4 . It has been classified as problematic . This vulnerability affects unknown code of the component Query Parameter Handler . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39395 | sigstore cosign up to 2.6.2/3.0.5 unusual condition (GHSA-w6c6-c85g-mmv6 / EUVD-2026-19919)

A vulnerability was found in sigstore cosign up to 2.6.2/3.0.5 . It has been declared as problematic . This issue affects some unknown processing. Executing a manipulation can lead to improper check f…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39401 | jhuckaby Cronicle up to 0.9.110 update_event authorization (GHSA-5j3v-cq96-xw6v / EUVD-2026-19925)

A vulnerability was found in jhuckaby Cronicle up to 0.9.110 . It has been rated as problematic . Impacted is the function update_event . The manipulation leads to missing authorization. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-14858 | Semtech LR1110/LR1120/LR1121 SPI Interface sensitive information in resource not removed before reuse (psa-2026-001)

A vulnerability categorized as problematic has been discovered in Semtech LR1110, LR1120 and LR1121 . The affected element is an unknown function of the component SPI Interface . The manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-14859 | Semtech LR1110/LR1120/LR1121 risky encryption (psa-2026-001)

A vulnerability identified as problematic has been detected in Semtech LR1110, LR1120 and LR1121 . The impacted element is an unknown function. This manipulation causes risky cryptographic algorithm. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39837 | Wikimedia Cargo Extension up to 3.8.6 on Mediawiki cross site scripting

A vulnerability labeled as problematic has been found in Wikimedia Cargo Extension up to 3.8.6 on Mediawiki. This affects an unknown function. Such manipulation leads to basic cross site scripting. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39361 | OpenObserve up to 0.70.3 mod.rs validate_enrichment_url server-side request forgery (GHSA-gcwf-3p7h-wm79)

A vulnerability marked as critical has been reported in OpenObserve up to 0.70.3 . This impacts the function validate_enrichment_url of the file src/handler/http/request/enrichment_table/mod.rs . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39841 | Wikimedia Cargo Extension up to 3.8.6 on Mediawiki cross site scripting (EUVD-2026-19931)

A vulnerability described as problematic has been identified in Wikimedia Cargo Extension up to 3.8.6 on Mediawiki. Affected is an unknown function. Executing a manipulation can lead to basic cross si…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2025-56015 | GenieACS 1.2.13 NBI API Endpoint improper authentication

A vulnerability classified as critical has been found in GenieACS 1.2.13 . Affected by this vulnerability is an unknown functionality of the component NBI API Endpoint . The manipulation leads to impr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39840 | Wikimedia Cargo Extension up to 3.8.6 on Mediawiki cross site scripting (EUVD-2026-19929)

A vulnerability classified as problematic was found in Wikimedia Cargo Extension up to 3.8.6 on Mediawiki. Affected by this issue is some unknown functionality. The manipulation results in cross site …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39397 | delmaredigital payload-puck up to 0.6.22 CRUD Endpoint createPuckPlugin authorization (EUVD-2026-19921)

A vulnerability, which was classified as critical , has been found in delmaredigital payload-puck up to 0.6.22 . This affects the function createPuckPlugin of the component CRUD Endpoint . This manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39370 | WWBN AVideo up to 26.0 aVideoEncoder.json.php downloadURL server-side request forgery (GHSA-cmcr-q4jf-p6q9)

A vulnerability, which was classified as critical , was found in WWBN AVideo up to 26.0 . This vulnerability affects unknown code of the file objects/aVideoEncoder.json.php . Such manipulation of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-4065 | nextendweb Smart Slider 3 Plugin up to 3.5.1.33 on WordPress display_admin_ajax authorization

A vulnerability has been found in nextendweb Smart Slider 3 Plugin up to 3.5.1.33 on WordPress and classified as critical . This issue affects the function display_admin_ajax . Performing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39369 | WWBN AVideo up to 26.0 aVideoEncoderReceiveImage.json.php path traversal (GHSA-f4f9-627c-jh33)

A vulnerability was found in WWBN AVideo up to 26.0 and classified as critical . Impacted is an unknown function of the file objects/aVideoEncoderReceiveImage.json.php . Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34765 | Electron up to 39.8.4/40.8.4/41.0.x window.open exposure of resource

A vulnerability was found in Electron up to 39.8.4/40.8.4/41.0.x . It has been classified as problematic . The affected element is the function window.open . The manipulation leads to exposure of reso…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34580 | randombit botan up to 3.11.0 Path Validation certificate_known certificate validation

A vulnerability was found in randombit botan up to 3.11.0 . It has been declared as critical . The impacted element is the function Certificate_Store::certificate_known of the component Path Validatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34582 | randombit botan up to 3.11.0 behavioral workflow

A vulnerability was found in randombit botan up to 3.11.0 . It has been rated as problematic . This affects an unknown function. This manipulation causes enforcement of behavioral workflow. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34781 | Electron up to 39.8.4/40.8.4/41.0.x clipboard.readImage null pointer dereference

A vulnerability categorized as problematic has been discovered in Electron up to 39.8.4/40.8.4/41.0.x . This impacts the function clipboard.readImage . Such manipulation leads to null pointer derefere…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39371 | redwoodjs sdk up to 1.0.5 GET Request serverAction cross-site request forgery (GHSA-x8rx-789c-2pxq)

A vulnerability identified as problematic has been detected in redwoodjs sdk up to 1.0.5 . Affected is the function serverAction of the component GET Request Handler . Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34371 | danny-avila LibreChat up to 0.8.3 writeFileSync path traversal

A vulnerability labeled as critical has been found in danny-avila LibreChat up to 0.8.3 . Affected by this vulnerability is the function writeFileSync . Executing a manipulation can lead to path trave…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-35568 | modelcontextprotocol java-sdk up to 0.x Model Context Protocol origin validation

A vulnerability marked as critical has been reported in modelcontextprotocol java-sdk up to 0.x . Affected by this issue is some unknown functionality of the component Model Context Protocol . The man…

VulDB Read →
← Prev 148 / 264 Next →