CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6400 articles  ·  updated every 4 hours · grows forever

6400Total
4068Full Text
May 24, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-26962 | Rack up to 3.2.5 HTTP Response Header Rack::Multipart crlf injection

A vulnerability classified as problematic was found in Rack up to 3.2.5 . This affects the function Rack::Multipart of the component HTTP Response Header Handler . Such manipulation leads to crlf inje…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34119 | TP-Link Tapo C520WS 2.6 HTTP Parser heap-based overflow

A vulnerability, which was classified as critical , has been found in TP-Link Tapo C520WS 2.6 . This impacts an unknown function of the component HTTP Parser . Performing a manipulation results in hea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34118 | TP-Link Tapo C520WS 2.6 heap-based overflow (EUVD-2026-18426)

A vulnerability, which was classified as critical , was found in TP-Link Tapo C520WS 2.6 . Affected is an unknown function. Executing a manipulation can lead to heap-based buffer overflow. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34124 | TP-Link Tapo C520WS 2.6 HTTP buffer overflow

A vulnerability has been found in TP-Link Tapo C520WS 2.6 and classified as critical . Affected by this vulnerability is an unknown functionality of the component HTTP Handler . The manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-35388 | OpenSSH up to 10.2 Proxy-mode Multiplexing Session unprotected alternate channel

A vulnerability was found in OpenSSH up to 10.2 and classified as problematic . Affected by this issue is some unknown functionality of the component Proxy-mode Multiplexing Session Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34121 | TP-Link Tapo C520WS 2.6 HTTP improper authentication (EUVD-2026-18432)

A vulnerability was found in TP-Link Tapo C520WS 2.6 . It has been classified as critical . This affects an unknown part of the component HTTP Handler . This manipulation causes improper authenticatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34577 | gitroomhq postiz-app up to 2.21.2 Endpoint /public/stream server-side request forgery

A vulnerability was found in gitroomhq postiz-app up to 2.21.2 . It has been declared as critical . This vulnerability affects unknown code of the file /public/stream of the component Endpoint . Such …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34122 | TP-Link Tapo C520WS 2.6 Configuration Parameter stack-based overflow (EUVD-2026-18434)

A vulnerability was found in TP-Link Tapo C520WS 2.6 . It has been rated as critical . This issue affects some unknown processing of the component Configuration Parameter Handler . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34524 | SillyTavern up to 1.16.x Chat Endpoint secrets.json avatar_url path traversal

A vulnerability categorized as critical has been discovered in SillyTavern up to 1.16.x . Impacted is an unknown function of the file secrets.json of the component Chat Endpoint . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34522 | SillyTavern up to 1.16.x /api/chats/import character_name path traversal

A vulnerability identified as critical has been detected in SillyTavern up to 1.16.x . The affected element is an unknown function of the file /api/chats/import . The manipulation of the argument char…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34576 | gitroomhq postiz-app up to 2.21.2 upload-from-url axios.get server-side request forgery

A vulnerability labeled as critical has been found in gitroomhq postiz-app up to 2.21.2 . The impacted element is the function axios.get of the file /public/v1/upload-from-url . The manipulation resul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34523 | SillyTavern up to 1.16.x path traversal

A vulnerability marked as critical has been reported in SillyTavern up to 1.16.x . This affects an unknown function. This manipulation causes path traversal. This vulnerability is tracked as CVE-2026-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34120 | TP-Link Tapo C520WS 2.6 heap-based overflow (EUVD-2026-18430)

A vulnerability described as critical has been identified in TP-Link Tapo C520WS 2.6 . This impacts an unknown function. Such manipulation leads to heap-based buffer overflow. This vulnerability is li…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-27774 | Acronis True Image up to 42389 uncontrolled search path (EUVD-2026-18418)

A vulnerability classified as problematic has been found in Acronis True Image up to 42389 . Affected is an unknown function. Performing a manipulation results in uncontrolled search path. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-28728 | Acronis True Image up to 42389 uncontrolled search path (EUVD-2026-18420)

A vulnerability classified as problematic was found in Acronis True Image up to 42389 . Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to uncontrolled se…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-33271 | Acronis True Image up to 42389 permission assignment (EUVD-2026-18424)

A vulnerability, which was classified as critical , has been found in Acronis True Image up to 42389 . Affected by this issue is some unknown functionality. The manipulation leads to incorrect permiss…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-31932 | OISF Suricata up to 7.0.14/8.0.3 KRB5 Buffering algorithmic complexity (ID 8305)

A vulnerability was found in OISF Suricata up to 7.0.14/8.0.3 and classified as problematic . Impacted is an unknown function of the component KRB5 Buffering . The manipulation results in inefficient …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-31933 | OISF Suricata up to 7.0.14/8.0.3 Traffic algorithmic complexity (ID 8272)

A vulnerability was found in OISF Suricata up to 7.0.14/8.0.3 . It has been classified as problematic . The affected element is an unknown function of the component Traffic Handler . This manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-2701 | Progress ShareFile Storage Zones Controller up to 5.12.3 unrestricted upload

A vulnerability was found in Progress ShareFile Storage Zones Controller up to 5.12.3 . It has been declared as critical . The impacted element is an unknown function of the component File Handler . S…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-30867 | emqx CocoaMQTT up to 2.2.1 Retained Message assertion (GHSA-r3fr-7m74-q7g2)

A vulnerability was found in emqx CocoaMQTT up to 2.2.1 . It has been rated as problematic . This affects an unknown function of the component Retained Message Handler . Performing a manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34890 | Mark O’Donnell MSTW League Manager Plugin up to 2.10 on WordPress cross site scripting

A vulnerability categorized as problematic has been discovered in Mark O’Donnell MSTW League Manager Plugin up to 2.10 on WordPress. This impacts an unknown function. Executing a manipulation can lead…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-35002 | Agno up to 2.3.23 Parameter eval field_type eval injection

A vulnerability identified as critical has been detected in Agno up to 2.3.23 . Affected is the function eval of the component Parameter Handler . The manipulation of the argument field_type leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-31935 | OISF Suricata up to 7.0.14/8.0.3 HTTP/2 CONTINUATION Frame resource consumption

A vulnerability labeled as problematic has been found in OISF Suricata up to 7.0.14/8.0.3 . Affected by this vulnerability is an unknown functionality of the component HTTP2 CONTINUATION Frame Handler…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-31934 | OISF Suricata up to 8.0.3 MIME Encoded Message algorithmic complexity

A vulnerability marked as problematic has been reported in OISF Suricata up to 8.0.3 . Affected by this issue is some unknown functionality of the component MIME Encoded Message Handler . This manipul…

VulDB Read →
← Prev 176 / 267 Next →