CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6399 articles  ·  updated every 4 hours · grows forever

6399Total
4067Full Text
May 24, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5462 | Wahoo Fitness SYSTM App up to 7.2.1 on Android com.WahooFitness.SYSTM BuildConfig.java SEGMENT_WRITE_KEY hard-coded key

A vulnerability described as problematic has been identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android. Impacted is an unknown function of the file com/WahooFitness/SYSTM/BuildConfig.java of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
APT28 Exploits MSHTML Zero-Day Ahead of February 2026 Patch Tuesday - cyberpress.org

APT28 Exploits MSHTML Zero-Day Ahead of February 2026 Patch Tuesday cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34758 | oneuptime up to 10.0.41 Notification missing authentication (GHSA-q253-6wcm-h8hp)

A vulnerability was found in oneuptime up to 10.0.41 and classified as critical . This affects an unknown part of the component Notification Handler . Such manipulation leads to missing authentication…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34759 | oneuptime up to 10.0.41 API Endpoint /notification/ authorization (GHSA-6wc5-rhvj-cx7f)

A vulnerability was found in oneuptime up to 10.0.41 . It has been classified as problematic . This vulnerability affects unknown code of the file /notification/ of the component API Endpoint . Perfor…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2025-15620 | Belden Hirschmann HiOS Switch Platform up to 09.4.05/10.3.01 Web Interface missing authentication

A vulnerability was found in Belden Hirschmann HiOS Switch Platform up to 09.4.05/10.3.01 . It has been declared as critical . This issue affects some unknown processing of the component Web Interface…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2024-14033 | Belden Hirschmann HiLCOS BAT-R up to 10.34.6313 HiLCOS Web Interface heap-based overflow (EUVD-2024-55531)

A vulnerability was found in Belden Hirschmann HiLCOS BAT-R, Hirschmann HiLCOS BAT-F, Hirschmann HiLCOS BAT450-F, Hirschmann HiLCOS BAT867-R, Hirschmann HiLCOS BAT867-F, Hirschmann HiLCOS WLC and Hirs…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34761 | ellanetworks core up to 1.7.x NGAP Handover Failure Message null pointer dereference (GHSA-6gm8-3g4h-w82m)

A vulnerability categorized as problematic has been discovered in ellanetworks core up to 1.7.x . The affected element is an unknown function of the component NGAP Handover Failure Message Handler . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34762 | ellanetworks core up to 1.7.x JSON Request Body /api/v1/subscriber/ improper authentication (GHSA-xw45-cc32-442f)

A vulnerability identified as critical has been detected in ellanetworks core up to 1.7.x . The impacted element is an unknown function of the file /api/v1/subscriber/ of the component JSON Request Bo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34834 | bulwarkmail webmail up to 1.4.9 Setting verifyIdentity improper authentication (GHSA-4356-876g-rfmh)

A vulnerability labeled as critical has been found in bulwarkmail webmail up to 1.4.9 . This affects the function verifyIdentity of the component Setting Handler . Such manipulation leads to improper …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34743 | tukaani-project xz up to 5.8.2 Compression lzma_index_decoder heap-based overflow (GHSA-x872-m794-cxhv)

A vulnerability marked as critical has been reported in tukaani-project xz up to 5.8.2 . This impacts the function lzma_index_decoder of the component Compression Handler . Performing a manipulation r…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34745 | ShaneIsrael fireshare up to 1.5.2 Endpoint /api/uploadChunked checkSum path traversal (GHSA-fvvp-rj8g-c7gc)

A vulnerability described as critical has been identified in ShaneIsrael fireshare up to 1.5.2 . Affected is an unknown function of the file /api/uploadChunked of the component Endpoint . Executing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34736 | openedx openedx-platform REST API /api/user/v1/accounts/ activation_key improper authentication (GHSA-m6rg-rp98-4crw)

A vulnerability classified as critical has been found in openedx openedx-platform . Affected by this vulnerability is an unknown functionality of the file /api/user/v1/accounts/ of the component REST …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34848 | hoppscotch 2023.4.5/2023.12.6/2026.2.0/2026.2.1 Display Name cross site scripting (GHSA-vw93-4m6p-ccm9)

A vulnerability classified as problematic was found in hoppscotch 2023.4.5/2023.12.6/2026.2.0/2026.2.1 . Affected by this issue is some unknown functionality of the component Display Name Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-5429 | Amazon AWS Kiro IDE up to 0.8.139 Kiro Agent Webview cross site scripting

A vulnerability, which was classified as problematic , has been found in Amazon AWS Kiro IDE up to 0.8.139 . This affects an unknown part of the component Kiro Agent Webview . This manipulation causes…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34825 | nocobase NocoBase Plugin up to 2.0.29 Parameter getParsedValue sql injection (GHSA-vx58-fwwq-5g8j)

A vulnerability, which was classified as critical , was found in nocobase NocoBase Plugin up to 2.0.29 . This vulnerability affects the function getParsedValue of the component Parameter Handler . Suc…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34752 | Haraka up to 3.1.3 uncaught exception (GHSA-xph3-r2jf-4vp3)

A vulnerability has been found in Haraka up to 3.1.3 and classified as problematic . This issue affects some unknown processing. Performing a manipulation results in uncaught exception. This vulnerabi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34742 | modelcontextprotocol go-sdk up to 1.3.x insecure default initialization of resource (GHSA-xw59-hvm2-8pj6)

A vulnerability was found in modelcontextprotocol go-sdk up to 1.3.x and classified as critical . Impacted is an unknown function. Executing a manipulation can lead to insecure default initialization …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34833 | bulwarkmail webmail up to 1.4.9 /api/auth/session cleartext storage (GHSA-47pm-883h-885r)

A vulnerability was found in bulwarkmail webmail up to 1.4.9 . It has been classified as problematic . The affected element is an unknown function of the file /api/auth/session . The manipulation lead…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34932 | hoppscotch 2023.4.5/2023.12.6/2026.2.0/2026.2.1 cross site scripting (GHSA-wj4r-hr4h-g98v)

A vulnerability was found in hoppscotch 2023.4.5/2023.12.6/2026.2.0/2026.2.1 . It has been declared as problematic . The impacted element is an unknown function. The manipulation results in cross site…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2025-43238 | Apple macOS up to 13.7.6/14.7.6/15.5 App integer overflow

A vulnerability was found in Apple macOS up to 13.7.6/14.7.6/15.5 . It has been rated as problematic . This affects an unknown function of the component App . This manipulation causes integer overflow…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2022-4986 | Belden Hirschmann EagleSDV up to 05.4.0/05.4.1 TLS Connection resource consumption

A vulnerability categorized as problematic has been discovered in Belden Hirschmann EagleSDV up to 05.4.0/05.4.1 . This impacts an unknown function of the component TLS Connection Handler . Such manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-35466 | CERTCC cveClient up to 1.0.23 CVE API Service cveInterface.js cross site scripting

A vulnerability identified as problematic has been detected in CERTCC cveClient up to 1.0.23 . Affected is an unknown function of the file cveInterface.js of the component CVE API Service Handler . Pe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-34730 | copier-org copier up to 9.14.0 YAML File Parser _external_data path traversal (GHSA-hgjq-p8cr-gg4h)

A vulnerability labeled as critical has been found in copier-org copier up to 9.14.0 . Affected by this vulnerability is the function _external_data of the component YAML File Parser . Executing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 03, 2026
CVE-2026-35467 | CERTCC cveClient up to 1.1.14 Stored API encrypt-storage.js insufficiently protected credentials

A vulnerability marked as problematic has been reported in CERTCC cveClient up to 1.1.14 . Affected by this issue is some unknown functionality of the file encrypt-storage.js of the component Stored A…

VulDB Read →
← Prev 174 / 267 Next →