CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6338 articles  ·  updated every 4 hours · grows forever

6338Total
4066Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35390 | bulwarkmail webmail up to 1.4.10 Email Content-Security-Policy-Report-Only cross site scripting

A vulnerability classified as problematic was found in bulwarkmail webmail up to 1.4.10 . The impacted element is an unknown function of the component Email Handler . Such manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2017-18892 | Mattermost Server up to 4.0.4/4.1.0 Email Template neutralization

A vulnerability, which was classified as critical , has been found in Mattermost Server up to 4.0.4/4.1.0 . This affects an unknown function of the component Email Template Handler . Performing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35473 | LabRedesCefetRJ WeGIA up to 3.6.8 control.php nextPage redirect

A vulnerability, which was classified as problematic , was found in LabRedesCefetRJ WeGIA up to 3.6.8 . This impacts an unknown function of the file /WeGIA/controle/control.php . Executing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35395 | LabRedesCefetRJ WeGIA up to 3.6.8 DespachoDAO.php id_memorando sql injection (GHSA-43jm-pcrq-w7gv)

A vulnerability has been found in LabRedesCefetRJ WeGIA up to 3.6.8 and classified as critical . Affected is an unknown function of the file dao/memorando/DespachoDAO.php . The manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35396 | LabRedesCefetRJ WeGIA up to 3.6.8 control.php nextPage redirect (GHSA-4qxc-5j5f-4gp5)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.8 and classified as problematic . Affected by this vulnerability is an unknown functionality of the file /WeGIA/controle/control.php . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35398 | LabRedesCefetRJ WeGIA up to 3.6.8 control.php nextPage redirect (GHSA-jvmq-528w-q4xp)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.8 . It has been classified as problematic . Affected by this issue is some unknown functionality of the file /WeGIA/controle/control.php . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35472 | LabRedesCefetRJ WeGIA up to 3.6.8 control.php nextPage redirect (GHSA-h8wm-6xhv-r547)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.8 . It has been declared as problematic . This affects an unknown part of the file /WeGIA/controle/control.php . Such manipulation of the a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5707 | Amazon AWS Research and Engineering Studio up to 2025.12.01 os command injection

A vulnerability was found in Amazon AWS Research and Engineering Studio up to 2025.12.01 . It has been rated as critical . This vulnerability affects unknown code. Performing a manipulation results in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5708 | Amazon AWS Research and Engineering Studio up to 2025.12.01 API dynamically-determined object attributes

A vulnerability categorized as very critical has been discovered in Amazon AWS Research and Engineering Studio up to 2025.12.01 . This issue affects some unknown processing of the component API Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-34972 | OpenFGA up to 1.13.x BatchCheck Call authorization (GHSA-jwvj-g8pc-cx45)

A vulnerability identified as problematic has been detected in OpenFGA up to 1.13.x . Impacted is an unknown function of the component BatchCheck Call Handler . The manipulation leads to incorrect aut…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-5709 | Amazon AWS Research and Engineering Studio up to 2025.12.01 FileBrowser API os command injection

A vulnerability labeled as critical has been found in Amazon AWS Research and Engineering Studio up to 2025.12.01 . The affected element is an unknown function of the component FileBrowser API . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35408 | Directus up to 11.16.x origin validation

A vulnerability marked as problematic has been reported in Directus up to 11.16.x . The impacted element is an unknown function. This manipulation causes origin validation error. This vulnerability is…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35404 | openedx openedx-platform 302 Form Submission HttpResponseRedirect redirect

A vulnerability described as problematic has been identified in openedx openedx-platform 302 . This affects the function HttpResponseRedirect of the component Form Submission Handler . Such manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35475 | LabRedesCefetRJ WeGIA up to 3.6.8 URL Validation redirect

A vulnerability classified as problematic has been found in LabRedesCefetRJ WeGIA up to 3.6.8 . This impacts an unknown function of the component URL Validation Handler . Performing a manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35474 | LabRedesCefetRJ WeGIA up to 3.6.8 URL Validation redirect

A vulnerability classified as problematic was found in LabRedesCefetRJ WeGIA up to 3.6.8 . Affected is an unknown function of the component URL Validation Handler . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35394 | mobile-next mobile-mcp up to 0.0.49 mobile_open_url improper authorization in handler for custom url scheme (GHSA-5qhv-x9j4-c3vm)

A vulnerability, which was classified as critical , has been found in mobile-next mobile-mcp up to 0.0.49 . Affected by this vulnerability is an unknown functionality of the component mobile_open_url …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35441 | Directus up to 11.16.x GraphQL /graphql resource consumption

A vulnerability, which was classified as problematic , was found in Directus up to 11.16.x . Affected by this issue is some unknown functionality of the file /graphql of the component GraphQL . The ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35412 | Directus up to 11.16.0 /files/tus authorization

A vulnerability has been found in Directus up to 11.16.0 and classified as problematic . This affects an unknown part of the file /files/tus . This manipulation causes incorrect authorization. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35413 | Directus up to 11.16.0 /graphql/system information disclosure

A vulnerability was found in Directus up to 11.16.0 and classified as problematic . This vulnerability affects unknown code of the file /graphql/system . Such manipulation leads to information disclos…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-22675 | OCS Inventory NG Server up to 2.12.3 HTTP Header /ocsinventory User-Agent cross site scripting

A vulnerability was found in OCS Inventory NG Server up to 2.12.3 . It has been classified as problematic . This issue affects some unknown processing of the file /ocsinventory of the component HTTP H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35410 | Directus up to 11.16.0 isLoginRedirectAllowed incomplete blacklist

A vulnerability was found in Directus up to 11.16.0 . It has been declared as critical . Impacted is the function isLoginRedirectAllowed . Executing a manipulation can lead to incomplete blacklist. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35399 | LabRedesCefetRJ WeGIA up to 3.6.8 Backup Filename cross site scripting (GHSA-fmwv-62wf-2hgx)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.8 . It has been rated as problematic . The affected element is an unknown function of the component Backup Filename Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35442 | Directus up to 11.16.x directus_users information disclosure

A vulnerability categorized as problematic has been discovered in Directus up to 11.16.x . The impacted element is an unknown function of the component directus_users . The manipulation results in inf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35411 | Directus up to 11.16.0 /admin/tfa-setup redirect

A vulnerability identified as problematic has been detected in Directus up to 11.16.0 . This affects an unknown function of the file /admin/tfa-setup . This manipulation of the argument redirect cause…

VulDB Read →
← Prev 154 / 265 Next →