CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5629 articles  ·  updated every 4 hours · grows forever

5629Total
4034Full Text
May 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44222 | vllm-project vllm up to 0.19.x Placeholder image_grid_thw/video_grid_thw array index (ID 32656)

A vulnerability was found in vllm-project vllm up to 0.19.x . It has been declared as problematic . This affects the function image_grid_thw/video_grid_thw of the component Placeholder Handler . Such …

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44223 | vllm-project vllm up to 0.19.x extract_hidden_states buffer size (GHSA-83vm-p52w-f9pw)

A vulnerability was found in vllm-project vllm up to 0.19.x . It has been rated as problematic . This impacts the function extract_hidden_states . Performing a manipulation of the argument repetition_…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-34655 | Adobe Commerce cross site scripting (apsb26-49)

A vulnerability categorized as problematic has been discovered in Adobe Commerce . Affected is an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is han…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-34658 | Adobe Commerce cross site scripting (apsb26-49)

A vulnerability identified as problematic has been detected in Adobe Commerce . Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-34686 | Adobe Commerce up to 2.4.4-p17 cross site scripting (apsb26-49)

A vulnerability labeled as problematic has been found in Adobe Commerce up to 2.4.4-p17 . Affected by this issue is some unknown functionality. The manipulation results in cross site scripting. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44225 | enesgkky Pulpy up to 0.1.0 validateFsPath path traversal (GHSA-h9q2-w73v-g7hf)

A vulnerability marked as critical has been reported in enesgkky Pulpy up to 0.1.0 . This affects the function validateFsPath . This manipulation causes path traversal. The identification of this vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44260 | efwGrp efw4.X up to 4.08.9 elfinder_checkRisk authorization

A vulnerability described as critical has been identified in efwGrp efw4.X up to 4.08.9 . This vulnerability affects the function elfinder_checkRisk . Such manipulation leads to incorrect authorizatio…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44262 | dedoc scramble up to 0.13.21 code injection

A vulnerability classified as critical has been found in dedoc scramble up to 0.13.21 . This issue affects some unknown processing. Performing a manipulation results in code injection. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-43948 | wger-project wger up to 2.5 Response Body reset_user_password/gym_permissions_user_edit authorization

A vulnerability classified as critical was found in wger-project wger up to 2.5 . Impacted is the function reset_user_password/gym_permissions_user_edit of the component Response Body Handler . Execut…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44257 | efwGrp efw4.X up to 4.08.9 zipEntry.getName command injection

A vulnerability, which was classified as critical , has been found in efwGrp efw4.X up to 4.08.9 . The affected element is the function zipEntry.getName . The manipulation leads to command injection. …

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44871 | HPE Aruba Networking Wireless Operating System up to 10.8.0.0 PAPI Protocol command injection

A vulnerability, which was classified as critical , was found in HPE Aruba Networking Wireless Operating System up to 10.8.0.0 . The impacted element is an unknown function of the component PAPI Proto…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-26289 | Subnet Solutions PowerSYSTEM Center 2026 up to 5.28.x REST API Endpoint authorization (icsa-26-132-02)

A vulnerability has been found in Subnet Solutions PowerSYSTEM Center 2020, PowerSYSTEM Center 2024 and PowerSYSTEM Center 2026 up to 5.28.x and classified as problematic . This affects an unknown fun…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44296 | Deskflow up to 1.26.0.167 secureAccept resource consumption

A vulnerability was found in Deskflow up to 1.26.0.167 and classified as problematic . This impacts the function SecureSocket::secureAccept . Such manipulation leads to resource consumption. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-42196 | codingjoe django-s3file up to 7.0.1 File Upload path traversal

A vulnerability was found in codingjoe django-s3file up to 7.0.1 . It has been classified as critical . Affected is an unknown function of the component File Upload Handler . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44259 | efwGrp efw4.X up to 4.08.9 File Extension cross site scripting

A vulnerability was found in efwGrp efw4.X up to 4.08.9 . It has been declared as problematic . Affected by this vulnerability is an unknown functionality of the component File Extension Handler . Exe…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44258 | efwGrp efw4.X up to 4.08.9 elfinder_checkRisk os command injection

A vulnerability was found in efwGrp efw4.X up to 4.08.9 . It has been rated as critical . Affected by this issue is the function elfinder_checkRisk . The manipulation leads to os command injection. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-33570 | Subnet Solutions PowerSYSTEM Center 2020 up to 5.28.x REST API Endpoint authorization (icsa-26-132-02)

A vulnerability categorized as problematic has been discovered in Subnet Solutions PowerSYSTEM Center 2020 up to 5.28.x . This affects an unknown part of the component REST API Endpoint . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-35555 | Subnet Solutions PowerSYSTEM Center 2024/PowerSYSTEM Center 2026 up to 6.1.x authorization (icsa-26-132-02)

A vulnerability identified as problematic has been detected in Subnet Solutions PowerSYSTEM Center 2024 and PowerSYSTEM Center 2026 up to 6.1.x . This vulnerability affects unknown code. This manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-45225 | heymrun heym up to 0.0.20 File Upload Endpoint upload_file path traversal

A vulnerability labeled as critical has been found in heymrun heym up to 0.0.20 . This issue affects the function upload_file of the component File Upload Endpoint . Such manipulation leads to path tr…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
CVE-2026-44015 | 0xJacky nginx-ui up to 2.3.4 server-side request forgery

A vulnerability marked as critical has been reported in 0xJacky nginx-ui up to 2.3.4 . Impacted is an unknown function. Performing a manipulation results in server-side request forgery. This vulnerabi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 13, 2026
Microsoft Patch Tuesday May 2026 - 120 Vulnerabilities Fixed, Including 29 Critical RCE Flaws - CyberSecurityNews

Microsoft Patch Tuesday May 2026 - 120 Vulnerabilities Fixed, Including 29 Critical RCE Flaws CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42300 | l3montree-dev devguard up to 1.2.1 HTTP Request Header authentication bypass (GHSA-2g9v-7mr5-fgjg)

A vulnerability was found in l3montree-dev devguard up to 1.2.1 . It has been declared as critical . This vulnerability affects unknown code of the component HTTP Request Header Handler . Such manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42303 | ethyca fides up to 2.83.1 authentication bypass (GHSA-qx5f-ghc2-7g5c)

A vulnerability was found in ethyca fides up to 2.83.1 . It has been rated as critical . This issue affects some unknown processing. Performing a manipulation results in authentication bypass using al…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42348 | open-telemetry opentelemetry-dotnet-contrib up to 0.2.0-alpha.0 OpenTelemetry.OpAmp.Client memory allocation (GHSA-w2jh-77fq-7gp8)

A vulnerability categorized as problematic has been discovered in open-telemetry opentelemetry-dotnet-contrib up to 0.2.0-alpha.0 . Impacted is an unknown function of the component OpenTelemetry.OpAmp…

VulDB Read →
← Prev 17 / 235 Next →