CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6338 articles  ·  updated every 4 hours · grows forever

6338Total
4066Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5762 | Wikimedia Reportcident Extension 1.43.7/1.44.4/1.45.2 on MediaWiki allocation of resources

A vulnerability, which was classified as problematic , has been found in Wikimedia Reportcident Extension 1.43.7/1.44.4/1.45.2 on MediaWiki. This issue affects some unknown processing. This manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39354 | Erudika scoold up to 1.66.1 /questions/ask postId authorization

A vulnerability, which was classified as problematic , was found in Erudika scoold up to 1.66.1 . Impacted is an unknown function of the file /questions/ask . Such manipulation of the argument postId …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39360 | RustFS up to alpha.89 Multipart Upload authorization

A vulnerability has been found in RustFS up to alpha.89 and classified as problematic . The affected element is an unknown function of the component Multipart Upload Handler . Performing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-22711 | Wikimedia Wikilove Extension up to 1.43.6/1.44.3/1.45.1 on Mediawiki cross site scripting

A vulnerability was found in Wikimedia Wikilove Extension up to 1.43.6/1.44.3/1.45.1 on Mediawiki and classified as problematic . The impacted element is an unknown function. Executing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39351 | Frappe up to 15.103.x/16.13.x API authorization

A vulnerability was found in Frappe up to 15.103.x/16.13.x . It has been classified as problematic . This affects an unknown function of the component API Handler . The manipulation leads to missing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2025-39666 | Checkmk up to 2.2.0/2.3.0p45/2.4.0p24/2.5.0b2 untrusted search path

A vulnerability was found in Checkmk up to 2.2.0/2.3.0p45/2.4.0p24/2.5.0b2 . It has been declared as problematic . This vulnerability affects unknown code. Executing a manipulation can lead to untrust…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-3466 | Checkmk up to 2.2.0/2.3.0p45/2.4.0p24/2.5.0b2 Dashboard Dashlet Title Link cross site scripting

A vulnerability was found in Checkmk up to 2.2.0/2.3.0p45/2.4.0p24/2.5.0b2 . It has been rated as problematic . This issue affects some unknown processing of the component Dashboard Dashlet Title Link…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2021-4473 | Beijing Topsec Network Security Tianxin Internet Behavior Management System prior 4.0.0.7_20210716.180815 Reporter objClass os command injection (CNVD-2021-41972 / EUVD-2021-34776)

A vulnerability categorized as critical has been discovered in Beijing Topsec Network Security Tianxin Internet Behavior Management System . Impacted is an unknown function of the component Reporter C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-22666 | Dolibarr ERP CRM up to 23.0.1 dol_eval_standard eval injection (EUVD-2026-19606)

A vulnerability identified as problematic has been detected in Dolibarr ERP CRM up to 23.0.1 . The affected element is the function dol_eval_standard . This manipulation causes improper neutralization…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-22679 | Weaver Network e-cology 10.0/2026-03-31 POST Request method interfaceName/methodName missing authentication (EUVD-2026-19607)

A vulnerability labeled as critical has been found in Weaver Network e-cology 10.0/2026-03-31 . The impacted element is an unknown function of the file /papi/esearch/data/devops/dubboApi/debug/method …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-33865 | mlflow up to 3.10.1 Web Interface cross site scripting (EUVD-2026-19608)

A vulnerability marked as problematic has been reported in mlflow up to 3.10.1 . This affects an unknown function of the component Web Interface . Performing a manipulation results in cross site scrip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5731 | Mozilla Firefox up to 149.0.1 memory corruption

A vulnerability described as critical has been identified in Mozilla Firefox up to 149.0.1 . This impacts an unknown function. Executing a manipulation can lead to memory corruption. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5734 | Mozilla Firefox up to 149.0.1 memory corruption

A vulnerability classified as critical has been found in Mozilla Firefox up to 149.0.1 . Affected is an unknown function. The manipulation leads to memory corruption. This vulnerability is traded as C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5735 | Mozilla Firefox up to 149.0.1 memory corruption

A vulnerability classified as critical was found in Mozilla Firefox up to 149.0.1 . Affected by this vulnerability is an unknown functionality. The manipulation results in memory corruption. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-33866 | MLflow up to 3.10.1 AJAX Endpoint authorization (EUVD-2026-19609)

A vulnerability, which was classified as problematic , has been found in MLflow up to 3.10.1 . Affected by this issue is some unknown functionality of the component AJAX Endpoint . This manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5733 | Mozilla Firefox up to 149.0.1 WebGPU memory corruption

A vulnerability, which was classified as critical , was found in Mozilla Firefox up to 149.0.1 . This affects an unknown part of the component WebGPU . Such manipulation leads to memory corruption. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5732 | Mozilla Firefox up to 149.0.1 Text integer overflow

A vulnerability has been found in Mozilla Firefox up to 149.0.1 and classified as critical . This vulnerability affects unknown code of the component Text Component . Performing a manipulation results…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35554 | Apache Kafka Clients up to 3.9.1/4.0.1/4.1.1 Producer Message use after free

A vulnerability was found in Apache Kafka Clients up to 3.9.1/4.0.1/4.1.1 and classified as critical . This issue affects some unknown processing of the component Producer Message Handler . Executing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5736 | PowerJob 5.1.0/5.1.1/5.1.2 detailPlus Endpoint InstanceController.java customQuery sql injection (Issue 1167)

A vulnerability was found in PowerJob 5.1.0/5.1.1/5.1.2 . It has been classified as critical . Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/po…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5739 | PowerJob 5.1.0/5.1.1/5.1.2 OpenAPI Endpoint /openApi/addWorkflowNode GroovyEvaluator.evaluate nodeParams code injection (Issue 1168)

A vulnerability was found in PowerJob 5.1.0/5.1.1/5.1.2 . It has been declared as critical . The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5741 | suvarchal docker-mcp-server up to 0.1.0 HTTP Interface src/index.ts stop_container/remove_container/pull_image os command injection

A vulnerability was found in suvarchal docker-mcp-server up to 0.1.0 . It has been rated as critical . The impacted element is the function stop_container/remove_container/pull_image of the file src/i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5627 | mintplex-labs anything-llm up to 1.12.0 AgentFlows index.js loadFlow/deleteFlow path traversal

A vulnerability categorized as problematic has been discovered in mintplex-labs anything-llm up to 1.12.0 . This affects the function loadFlow/deleteFlow of the file server/utils/agentFlows/index.js o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-20884 | LibRaw File deflate_dng_load_raw integer overflow (TALOS-2026-2364)

A vulnerability identified as problematic has been detected in LibRaw . This impacts the function deflate_dng_load_raw of the component File Handler . Performing a manipulation results in integer over…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-20911 | LibRaw 0b56545/d20315b File HuffTable::initval buffer size (TALOS-2026-2330)

A vulnerability labeled as critical has been found in LibRaw 0b56545/d20315b . Affected is the function HuffTable::initval of the component File Handler . Executing a manipulation can lead to incorrec…

VulDB Read →
← Prev 151 / 265 Next →