CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6338 articles  ·  updated every 4 hours · grows forever

6338Total
4066Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35615 | MervinPraison PraisonAI up to 4.5.112 _validate_path path traversal (GHSA-693f-pf34-72c5)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.112 . It has been classified as critical . This affects the function _validate_path . This manipulation causes path traversal. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-24146 | NVIDIA Triton Inference Server memory allocation

A vulnerability was found in NVIDIA Triton Inference Server . It has been declared as problematic . This vulnerability affects unknown code. Such manipulation leads to uncontrolled memory allocation. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39305 | MervinPraison PraisonAI up to 4.5.112 Action Orchestrator Feature path traversal (GHSA-jfxc-v5g9-38xr)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.112 . It has been rated as critical . This issue affects some unknown processing of the component Action Orchestrator Feature . Performin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-24174 | NVIDIA Triton Inference Server numeric conversion (EUVD-2026-19757)

A vulnerability categorized as critical has been discovered in NVIDIA Triton Inference Server . Impacted is an unknown function. Executing a manipulation can lead to incorrect conversion between numer…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39335 | ChurchCRM up to 7.1.0 entity cross site scripting (GHSA-44j4-jjw2-wcr6)

A vulnerability identified as problematic has been detected in ChurchCRM up to 7.1.0 . The affected element is an unknown function. The manipulation of the argument entity leads to cross site scriptin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35608 | RoastSlav quickdrop up to 1.5.2 File Preview Endpoint /api/file/upload-chunk cross site scripting (GHSA-f577-ffvv-w6rr)

A vulnerability labeled as problematic has been found in RoastSlav quickdrop up to 1.5.2 . The impacted element is an unknown function of the file /api/file/upload-chunk of the component File Preview …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-31272 | MRCMS 3.1.2 UserController.java save access control (EUVD-2026-19767)

A vulnerability marked as critical has been reported in MRCMS 3.1.2 . This affects the function Save of the file src/main/java/org/marker/mushroom/controller/UserController.java . This manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35574 | ChurchCRM up to 6.5.2 cross site scripting (GHSA-cx82-8xrh-7f5c)

A vulnerability described as problematic has been identified in ChurchCRM up to 6.5.2 . This impacts an unknown function. Such manipulation leads to cross site scripting. This vulnerability is uniquel…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39336 | ChurchCRM up to 7.0.x Directory Reports Form cross site scripting (GHSA-r8cp-gg58-2r2r)

A vulnerability classified as problematic has been found in ChurchCRM up to 7.0.x . Affected is an unknown function of the component Directory Reports Form . Performing a manipulation results in cross…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35575 | ChurchCRM up to 6.5.2 cross site scripting (GHSA-gc8q-2gw7-qj7w)

A vulnerability classified as problematic was found in ChurchCRM up to 6.5.2 . Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2025-70844 | kantorge yaffa 2.0.0 Add Account Group cross site scripting

A vulnerability, which was classified as problematic , has been found in kantorge yaffa 2.0.0 . Affected by this issue is some unknown functionality of the component Add Account Group . The manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35576 | ChurchCRM up to 6.x cross site scripting (GHSA-8r36-fvxj-26qv)

A vulnerability, which was classified as problematic , was found in ChurchCRM up to 6.x . This affects an unknown part. The manipulation results in cross site scripting. This vulnerability is identifi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39344 | ChurchCRM up to 7.0.x Username cross site scripting (GHSA-rx8c-j7x8-w3hj)

A vulnerability has been found in ChurchCRM up to 7.0.x and classified as problematic . This vulnerability affects unknown code. This manipulation of the argument Username causes basic cross site scri…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35614 | Frappe up to 15.103.x/16.13.x bulk_update sql injection (GHSA-583g-fg76-fhfr)

A vulnerability was found in Frappe up to 15.103.x/16.13.x and classified as critical . This issue affects the function bulk_update . Such manipulation leads to sql injection. This vulnerability is li…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39345 | OrangeHRM up to 5.8.0 Email Template path traversal

A vulnerability was found in OrangeHRM up to 5.8.0 . It has been classified as critical . Impacted is an unknown function of the component Email Template Handler . Performing a manipulation results in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-31790 | OpenSSL up to 3.0.19/3.3.6/3.4.4/3.5.5/3.6.1 RSA KEM RSASVE Encapsulation RSA_public_encrypt uninitialized pointer

A vulnerability was found in OpenSSL up to 3.0.19/3.3.6/3.4.4/3.5.5/3.6.1 . It has been declared as problematic . The affected element is the function RSA_public_encrypt of the component RSA KEM RSASV…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-28386 | OpenSSL up to 3.6.1 on x86-64 AES-CFB-128 out-of-bounds

A vulnerability was found in OpenSSL up to 3.6.1 on x86-64. It has been rated as problematic . The impacted element is an unknown function of the component AES-CFB-128 Handler . The manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-28387 | OpenSSL up to 3.6.1 DANE Client Code use after free

A vulnerability categorized as critical has been discovered in OpenSSL up to 3.6.1 . This affects an unknown function of the component DANE Client Code . The manipulation results in use after free. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-28388 | OpenSSL up to 3.6.1 Delta CRL null pointer dereference

A vulnerability identified as problematic has been detected in OpenSSL up to 3.6.1 . This impacts an unknown function of the component Delta CRL Handler . This manipulation causes null pointer derefer…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-28389 | OpenSSL up to 3.6.1 CMS EnvelopedData Message CMS_decrypt null pointer dereference

A vulnerability labeled as problematic has been found in OpenSSL up to 3.6.1 . Affected is the function CMS_decrypt of the component CMS EnvelopedData Message Handler . Such manipulation leads to null…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-28390 | OpenSSL up to 3.6.1 CMS KeyTransportRecipientInfo CMS_decrypt null pointer dereference

A vulnerability marked as problematic has been reported in OpenSSL up to 3.6.1 . Affected by this vulnerability is the function CMS_decrypt of the component CMS KeyTransportRecipientInfo Handler . Per…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-31789 | OpenSSL up to 3.0.19/3.3.6/3.4.4/3.5.5/3.6.1 Hexadecimal Conversion heap-based overflow

A vulnerability described as critical has been identified in OpenSSL up to 3.0.19/3.3.6/3.4.4/3.5.5/3.6.1 . Affected by this issue is some unknown functionality of the component Hexadecimal Conversion…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39355 | MGeurts genealogy up to 5.9.0 authorization

A vulnerability classified as critical has been found in MGeurts genealogy up to 5.9.0 . This affects an unknown part. The manipulation leads to missing authorization. This vulnerability is uniquely i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2025-71058 | Dual DHCP DNS Server 8.01 UDP DNS Response injection

A vulnerability classified as problematic was found in Dual DHCP DNS Server 8.01 . This vulnerability affects unknown code of the component UDP DNS Response Handler . The manipulation results in injec…

VulDB Read →
← Prev 150 / 265 Next →