CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6400 articles  ·  updated every 4 hours · grows forever

6400Total
4068Full Text
May 24, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-31937 | OISF Suricata up to 7.0.14 DCERPC Buffering algorithmic complexity

A vulnerability described as problematic has been identified in OISF Suricata up to 7.0.14 . This affects an unknown part of the component DCERPC Buffering . Such manipulation leads to inefficient alg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-32629 | thorsten phpMyFAQ up to 4.1.0 Remote Code Execution (GHSA-98gw-w575-h2ph)

A vulnerability classified as critical has been found in thorsten phpMyFAQ up to 4.1.0 . This vulnerability affects unknown code. Performing a manipulation results in Remote Code Execution. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-32871 | PrefectHQ fastmcp up to 3.1.x Template String /api/v1/users/ _build_url server-side request forgery (GHSA-vv7q-7jx5-f767)

A vulnerability classified as critical was found in PrefectHQ fastmcp up to 3.1.x . This issue affects the function _build_url of the file /api/v1/users/ of the component Template String Handler . Exe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34728 | thorsten phpMyFAQ up to 4.1.0 index Name path traversal (GHSA-38m8-xrfj-v38x)

A vulnerability, which was classified as critical , has been found in thorsten phpMyFAQ up to 4.1.0 . Impacted is the function MediaBrowserController::index . The manipulation of the argument Name lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34729 | thorsten phpMyFAQ up to 4.1.0 Filter::removeAttributes cross site scripting (GHSA-cv2g-8cj8-vgc7)

A vulnerability, which was classified as problematic , was found in thorsten phpMyFAQ up to 4.1.0 . The affected element is the function Filter::removeAttributes . The manipulation results in cross si…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-33544 | steveiliop56 tinyauth up to 5.0.4 GenericOAuthService VerifyCode race condition (GHSA-9q5m-jfc4-wc92)

A vulnerability has been found in steveiliop56 tinyauth up to 5.0.4 and classified as problematic . The impacted element is the function VerifyCode of the component GenericOAuthService/GithubOAuthServ…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-33641 | nicolargo glances up to 4.5.2 Configuration File Config.get_value os command injection (GHSA-qhj7-v7h7-q4c7)

A vulnerability was found in nicolargo glances up to 4.5.2 and classified as critical . This affects the function Config.get_value of the component Configuration File Handler . Such manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34792 | Endian Firewall 3.3.25 Regular Expression /cgi-bin/logs_clamav.cgi open Date os command injection

A vulnerability was found in Endian Firewall 3.3.25 . It has been classified as critical . This impacts the function Open of the file /cgi-bin/logs_clamav.cgi of the component Regular Expression Handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34790 | Endian Firewall 3.3.25 Parameter /cgi-bin/backup.cgi unlink Archive path traversal

A vulnerability was found in Endian Firewall 3.3.25 . It has been declared as critical . Affected is the function unlink of the file /cgi-bin/backup.cgi of the component Parameter Handler . Executing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34791 | Endian Firewall 3.3.25 Regular Expression /cgi-bin/logs_proxy.cgi open Date os command injection

A vulnerability was found in Endian Firewall 3.3.25 . It has been rated as critical . Affected by this vulnerability is the function Open of the file /cgi-bin/logs_proxy.cgi of the component Regular E…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34974 | thorsten phpMyFAQ up to 4.1.0 SVG SvgSanitizer.php edit_faq cross site scripting (GHSA-5crx-pfhq-4hgg)

A vulnerability categorized as problematic has been discovered in thorsten phpMyFAQ up to 4.1.0 . Affected by this issue is the function edit_faq of the file SvgSanitizer.php of the component SVG Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34796 | Endian Firewall 3.3.25 Regular Expression logs_openvpn.cgi open Date os command injection

A vulnerability identified as critical has been detected in Endian Firewall 3.3.25 . This affects the function Open of the file /cgi-bin/logs_openvpn.cgi of the component Regular Expression Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34973 | thorsten phpMyFAQ up to 4.1.0 Search.php searchCustomPages data query logic injection (GHSA-gcp9-5jc8-976x)

A vulnerability labeled as problematic has been found in thorsten phpMyFAQ up to 4.1.0 . This vulnerability affects the function searchCustomPages of the file phpmyfaq/src/phpMyFAQ/Search.php . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34798 | Endian Firewall 3.3.25 Parameter /cgi-bin/routing.cgi remark cross site scripting

A vulnerability marked as problematic has been reported in Endian Firewall 3.3.25 . This issue affects some unknown processing of the file /cgi-bin/routing.cgi of the component Parameter Handler . Per…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34799 | Endian Firewall 3.3.25 Parameter /manage/dnsmasq/hosts/ remark cross site scripting

A vulnerability described as problematic has been identified in Endian Firewall 3.3.25 . Impacted is an unknown function of the file /manage/dnsmasq/hosts/ of the component Parameter Handler . Executi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34800 | Endian Firewall 3.3.25 Parameter uplinkeditor.cgi Name cross site scripting

A vulnerability classified as problematic has been found in Endian Firewall 3.3.25 . The affected element is an unknown function of the file /cgi-bin/uplinkeditor.cgi of the component Parameter Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34794 | Endian Firewall 3.3.25 Regular Expression /cgi-bin/logs_ids.cgi open Date os command injection

A vulnerability classified as critical was found in Endian Firewall 3.3.25 . The impacted element is the function Open of the file /cgi-bin/logs_ids.cgi of the component Regular Expression Handler . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34795 | Endian Firewall 3.3.25 Regular Expression /cgi-bin/logs_log.cgi open Date os command injection

A vulnerability, which was classified as critical , has been found in Endian Firewall 3.3.25 . This affects the function Open of the file /cgi-bin/logs_log.cgi of the component Regular Expression Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34793 | Endian Firewall 3.3.25 Regular Expression logs_firewall.cgi open Date os command injection

A vulnerability, which was classified as critical , was found in Endian Firewall 3.3.25 . This impacts the function Open of the file /cgi-bin/logs_firewall.cgi of the component Regular Expression Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34797 | Endian Firewall 3.3.25 Regular Expression /cgi-bin/logs_smtp.cgi open Date os command injection

A vulnerability has been found in Endian Firewall 3.3.25 and classified as critical . Affected is the function Open of the file /cgi-bin/logs_smtp.cgi of the component Regular Expression Handler . Per…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34801 | Endian Firewall 3.3.25 Parameter fixed_leases remark cross site scripting

A vulnerability was found in Endian Firewall 3.3.25 and classified as problematic . Affected by this vulnerability is an unknown functionality of the file /manage/dhcp/fixed_leases/ of the component P…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34802 | Endian Firewall 3.3.25 Parameter /cgi-bin/salearn.cgi spam cross site scripting

A vulnerability was found in Endian Firewall 3.3.25 . It has been classified as problematic . Affected by this issue is some unknown functionality of the file /cgi-bin/salearn.cgi of the component Par…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-5246 | Cesanta Mongoose up to 7.20 P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorization

A vulnerability labeled as critical has been found in Cesanta Mongoose up to 7.20 . Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-5413 | Newgen OmniDocs up to 12.0.00 GetWebApiConfiguration connectionDetails information disclosure

A vulnerability marked as problematic has been reported in Newgen OmniDocs up to 12.0.00 . Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration . The…

VulDB Read →
← Prev 177 / 267 Next →