CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6399 articles  ·  updated every 4 hours · grows forever

6399Total
4067Full Text
May 24, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-35536 | tornadoweb Tornado up to 6.5.4 Attributes RequestHandler.set_cookie samesite invalid special elements (GHSA-78cv-mqj4-43f7)

A vulnerability marked as critical has been reported in tornadoweb Tornado up to 6.5.4 . The impacted element is the function RequestHandler.set_cookie of the component Attributes Handler . Performing…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-35507 | milesmcc Shynet up to 0.13.x Password Reset Host less trusted source

A vulnerability described as problematic has been identified in milesmcc Shynet up to 0.13.x . This affects an unknown function of the component Password Reset Handler . Executing a manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-35538 | Roundcube Webmail up to 1.5.13/1.6.13 IMAP SEARCH Command Argument argument injection

A vulnerability classified as critical has been found in Roundcube Webmail up to 1.5.13/1.6.13 . This impacts an unknown function of the component IMAP SEARCH Command Argument Handler . The manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-35508 | milesmcc Shynet up to 0.13.x Template Filter urldisplay/iconify cross site scripting

A vulnerability classified as problematic was found in milesmcc Shynet up to 0.13.x . Affected is the function urldisplay/iconify of the component Template Filter Handler . The manipulation results in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-32186 | Microsoft Bing server-side request forgery

A vulnerability, which was classified as critical , has been found in Microsoft Bing . Affected by this vulnerability is an unknown functionality. This manipulation causes server-side request forgery.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5467 | Casdoor 2.356.0 OAuth Authorization Request redirect_uri

A vulnerability, which was classified as problematic , was found in Casdoor 2.356.0 . Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5468 | Casdoor 2.356.0 dangerouslySetInnerHTML formCss/formCssMobile/formSideHtml cross site scripting

A vulnerability has been found in Casdoor 2.356.0 and classified as problematic . This affects the function dangerouslySetInnerHTML . Performing a manipulation of the argument formCss/formCssMobile/fo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5469 | Casdoor 2.356.0 Webhook URL server-side request forgery

A vulnerability was found in Casdoor 2.356.0 and classified as critical . This vulnerability affects unknown code of the component Webhook URL Handler . Executing a manipulation can lead to server-sid…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5470 | mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent URL server-side request forgery

A vulnerability was found in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83 . It has been classified as critical . This issue affects t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5471 | Investory Toy Planet Trouble App up to 1.5.5 on Android app.investory.toyfactory google-services-desktop.json current_key hard-coded key

A vulnerability was found in Investory Toy Planet Trouble App up to 1.5.5 on Android. It has been declared as problematic . Impacted is an unknown function of the file assets/google-services-desktop.j…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5472 | ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59 Profile Picture settings.php File unrestricted upload

A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59 . It has been rated as critical . The affected element is an unknown function o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5473 | NASA cFS up to 7.0.0 Pickle pickle.load deserialization (Issue 951)

A vulnerability categorized as problematic has been discovered in NASA cFS up to 7.0.0 . The impacted element is the function pickle.load of the component Pickle Module . Such manipulation leads to de…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5474 | NASA cFS up to 7.0.0 CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow (Issue 952)

A vulnerability identified as critical has been detected in NASA cFS up to 7.0.0 . This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5475 | NASA cFS up to 7.0.0 CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruption (Issue 953)

A vulnerability labeled as critical has been found in NASA cFS up to 7.0.0 . This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler . Executi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5476 | NASA cFS up to 7.0.0 on 32-bit cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflow (Issue 954)

A vulnerability marked as critical has been reported in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_code…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-4350 | Perfmatters Plugin up to 2.5.9.1 on WordPress PMCS::action_handler delete path traversal

A vulnerability described as critical has been identified in Perfmatters Plugin up to 2.5.9.1 on WordPress. Affected by this vulnerability is the function PMCS::action_handler . The manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2025-7024 | Airbus PSS TETRA Connectivity Server 7.0 on Windows File default permission

A vulnerability classified as critical has been found in Airbus PSS TETRA Connectivity Server 7.0 on Windows. Affected by this issue is some unknown functionality of the component File Handler . This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
MSHTML Zero-Day in Windows Exploited by APT28 Prior to Feb 2026 Security Update - gbhackers.com

MSHTML Zero-Day in Windows Exploited by APT28 Prior to Feb 2026 Security Update gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-33105 | Microsoft Azure Kubernetes Service improper authorization (EUVD-2026-18562)

A vulnerability was found in Microsoft Azure Kubernetes Service . It has been declared as critical . Affected is an unknown function. Such manipulation leads to improper authorization. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-32173 | Microsoft Azure SRE Agent Gateway improper authentication (EUVD-2026-18558)

A vulnerability was found in Microsoft Azure SRE Agent Gateway . It has been rated as critical . Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-32211 | Microsoft Azure Web Apps MCP Server missing authentication (EUVD-2026-18560)

A vulnerability categorized as critical has been discovered in Microsoft Azure Web Apps . Affected by this issue is some unknown functionality of the component MCP Server . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-32213 | Microsoft Azure AI Foundry improper authorization (EUVD-2026-18561)

A vulnerability identified as critical has been detected in Microsoft Azure AI Foundry . This affects an unknown part. The manipulation leads to improper authorization. This vulnerability is traded as…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-26135 | Microsoft Azure Custom Locations Resource Provider server-side request forgery

A vulnerability labeled as critical has been found in Microsoft Azure Custom Locations Resource Provider . This vulnerability affects unknown code. The manipulation results in server-side request forg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-33107 | Microsoft Azure Databricks server-side request forgery (EUVD-2026-18564)

A vulnerability marked as critical has been reported in Microsoft Azure Databricks . This issue affects some unknown processing. This manipulation causes server-side request forgery. This vulnerabilit…

VulDB Read →
← Prev 173 / 267 Next →