CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6338 articles  ·  updated every 4 hours · grows forever

6338Total
4066Full Text
May 23, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35471 | patrickhener goshs up to 2.0.0-beta.2 tdeleteFile path traversal

A vulnerability labeled as critical has been found in patrickhener goshs up to 2.0.0-beta.2 . This impacts the function tdeleteFile . Such manipulation leads to path traversal. This vulnerability is t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35392 | patrickhener goshs up to 2.0.0-beta.2 httpserver/updown.go path traversal (GHSA-g8mv-vp7j-qp64)

A vulnerability marked as critical has been reported in patrickhener goshs up to 2.0.0-beta.2 . Affected is an unknown function of the file httpserver/updown.go . Performing a manipulation results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35393 | patrickhener goshs up to 2.0.0-beta.2 Multipart Upload path traversal (GHSA-jg56-wf8x-qrv5)

A vulnerability described as critical has been identified in patrickhener goshs up to 2.0.0-beta.2 . Affected by this vulnerability is an unknown functionality of the component Multipart Upload Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35409 | Directus up to 11.15.x server-side request forgery

A vulnerability classified as critical has been found in Directus up to 11.15.x . Affected by this issue is some unknown functionality. The manipulation leads to server-side request forgery. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35030 | BerriAI litellm up to 1.82.x JWT/OIDC enable_jwt_auth improper authentication (GHSA-jjhc-v7c2-5hh6)

A vulnerability labeled as critical has been found in BerriAI litellm up to 1.82.x . This affects the function enable_jwt_auth of the component JWT/OIDC . Such manipulation leads to improper authentic…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35039 | nearform fast-jwt up to 6.0.x data authenticity (GHSA-rp9m-7r4c-75qg)

A vulnerability marked as critical has been reported in nearform fast-jwt up to 6.0.x . This vulnerability affects unknown code. Performing a manipulation results in insufficient verification of data …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35036 | lin-snow Ech0 up to 4.2.7 Response Body /api/website/title server-side request forgery (GHSA-wc4h-2348-jc3p)

A vulnerability described as critical has been identified in lin-snow Ech0 up to 4.2.7 . This issue affects some unknown processing of the file /api/website/title of the component Response Body Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35035 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0 Setting cross site scripting (GHSA-5ghq-42rg-769x)

A vulnerability classified as problematic has been found in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0 . Impacted is an unknown function of the component Setting Handler . The manipulation leads to cross sit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35037 | lin-snow Ech0 up to 4.2.7 Endpoint /api/website/title website_url server-side request forgery (GHSA-cqgf-f4x7-g6wc)

A vulnerability classified as critical was found in lin-snow Ech0 up to 4.2.7 . The affected element is an unknown function of the file /api/website/title of the component Endpoint . The manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35174 | xenocrat chyrp-lite prior 2026.01 Setting config.json.php path traversal (GHSA-p6pf-2grm-8257)

A vulnerability, which was classified as critical , has been found in xenocrat chyrp-lite . The impacted element is an unknown function of the file config.json.php of the component Setting Handler . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35470 | devcode-it openstamanager up to 2.10.1 Customer Information confronta_righe.php righe sql injection (GHSA-mmm5-3g4x-qw39)

A vulnerability, which was classified as critical , was found in devcode-it openstamanager up to 2.10.1 . This affects an unknown function of the file confronta_righe.php of the component Customer Inf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35164 | Ajax30 BraveCMS up to 2.0.5 CkEditorController.php unrestricted upload (GHSA-2j4q-6p52-4rhw)

A vulnerability has been found in Ajax30 BraveCMS up to 2.0.5 and classified as critical . This impacts an unknown function of the file app/Http/Controllers/Dashboard/CkEditorController.php . Performi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35044 | BentoML up to 1.4.37 generate.py generate_containerfile special elements used in a template engine (GHSA-v959-cwq9-7hr6)

A vulnerability was found in BentoML up to 1.4.37 and classified as critical . Affected is the function generate_containerfile of the file src/bentoml/_internal/container/generate.py . Executing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35050 | oobabooga text-generation-webui up to 4.1.0 Setting download-model.py path traversal (GHSA-jg96-p5p6-q3cv)

A vulnerability was found in oobabooga text-generation-webui up to 4.1.0 . It has been classified as critical . Affected by this vulnerability is an unknown functionality of the file download-model.py…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35171 | kedro-org kedro up to 1.2.x dictConfig KEDRO_LOGGING_CONFIG code injection (GHSA-9cqf-439c-j96r)

A vulnerability was found in kedro-org kedro up to 1.2.x . It has been declared as critical . Affected by this issue is the function dictConfig . The manipulation of the argument KEDRO_LOGGING_CONFIG …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35052 | man-group dtale up to 3.21.x cross site scripting (GHSA-436g-fhfc-9g5w)

A vulnerability was found in man-group dtale up to 3.21.x . It has been rated as problematic . This affects an unknown part. This manipulation causes cross site scripting. This vulnerability is handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35045 | TandoorRecipes recipes up to 2.6.3 batch_update authorization (GHSA-v8x3-w674-55p5)

A vulnerability categorized as critical has been discovered in TandoorRecipes recipes up to 2.6.3 . This vulnerability affects unknown code of the file /api/recipe/batch_update/ . Such manipulation le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35209 | unjs defu up to 6.1.4 prototype pollution (GHSA-737v-mqg7-c878)

A vulnerability identified as problematic has been detected in unjs defu up to 6.1.4 . This issue affects the function defu . Performing a manipulation results in improperly controlled modification of…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2025-57835 | Modem Mobile Processor/Wearable Processor/Modem Exynos up to 9110 RRC initialization

A vulnerability labeled as critical has been found in Modem Mobile Processor, Wearable Processor and Modem Exynos up to 9110 . Impacted is an unknown function of the component RRC . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2025-59440 | Samsung Mobile Processor/Wearable Processor/Modem Exynos up to 9110 USIM denial of service

A vulnerability marked as problematic has been reported in Samsung Mobile Processor, Wearable Processor and Modem Exynos up to 9110 . The affected element is an unknown function of the component USIM …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35167 | kedro-org kedro up to 1.2.x kedro/io/core.py _get_versioned_path path traversal (GHSA-6326-w46w-ppjw)

A vulnerability described as critical has been identified in kedro-org kedro up to 1.2.x . The impacted element is the function _get_versioned_path of the file kedro/io/core.py . The manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2025-54324 | Samsung Mobile Processor/Wearable Processor/Modem Exynos up to 9110 NAS denial of service

A vulnerability classified as problematic has been found in Samsung Mobile Processor, Wearable Processor and Modem Exynos up to 9110 . This affects an unknown function of the component NAS . This mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2025-58349 | Modem Mobile Processor/Wearable Processor/Modem Exynos up to 9110 L2 denial of service

A vulnerability classified as problematic was found in Modem Mobile Processor, Wearable Processor and Modem Exynos up to 9110 . This impacts an unknown function of the component L2 . Such manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35047 | Ajax30 BraveCMS up to 2.0.5 CKEditor Endpoint unrestricted upload (GHSA-9rcc-w59j-965v)

A vulnerability, which was classified as critical , has been found in Ajax30 BraveCMS up to 2.0.5 . Affected is an unknown function of the component CKEditor Endpoint . Performing a manipulation resul…

VulDB Read →
← Prev 155 / 265 Next →