CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6401 articles  ·  updated every 4 hours · grows forever

6401Total
4068Full Text
May 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-33616 | MB connect line mbCONNECT24/mymbCONNECT24 up to 2.19.4 mb24api Endpoint sql injection (VDE-2026-030)

A vulnerability was found in MB connect line mbCONNECT24 and mymbCONNECT24 up to 2.19.4 . It has been rated as critical . This affects an unknown part of the component mb24api Endpoint . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-33617 | MB connect line mbCONNECT24/mymbCONNECT24 up to 2.19.4 Configuration File exposure of sensitive system information to an unauthorized control sphere (VDE-2026-030)

A vulnerability categorized as problematic has been discovered in MB connect line mbCONNECT24 and mymbCONNECT24 up to 2.19.4 . This vulnerability affects unknown code of the component Configuration Fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-5417 | Dataease SQLbot up to 1.6.0 Elasticsearch es_engine.py get_es_data_by_http address server-side request forgery

A vulnerability identified as critical has been detected in Dataease SQLbot up to 1.6.0 . This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-5418 | appsmithorg appsmith up to 1.97 Dashboard WebClientUtils.java computeDisallowedHosts server-side request forgery (GHSA-9m89-5jw7-q5cr)

A vulnerability labeled as critical has been found in appsmithorg appsmith up to 1.97 . Impacted is the function computeDisallowedHosts of the file app/server/appsmith-interfaces/src/main/java/com/app…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-5420 | Shinrays Games Goods Triple App up to 1.200 cats.goods.sort.sorting.games jRwTX.java AES_IV/AES_PASSWORD hard-coded key

A vulnerability marked as problematic has been reported in Shinrays Games Goods Triple App up to 1.200 . The affected element is an unknown function of the file jRwTX.java of the component cats.goods.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
Google patches 2026’s first Chrome zero-day vulnerability - escudodigital.com

Google patches 2026’s first Chrome zero-day vulnerability escudodigital.com

escudodigital.com Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution - The Hacker News

CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
Firefox 149 Released With Patch for 37 Vulnerabilities that Enables Remote Attacks - CyberSecurityNews

Firefox 149 Released With Patch for 37 Vulnerabilities that Enables Remote Attacks CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-4820 | IBM Maximo Application Suite up to 8.10/8.11.0/9.0/10.6.5.0 Authorization Token missing secure attribute

A vulnerability has been found in IBM Maximo Application Suite up to 8.10/8.11.0/9.0/10.6.5.0 and classified as problematic . This affects an unknown function of the component Authorization Token Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34513 | aio-libs aiohttp up to 3.13.3 DNS Cache allocation of resources (GHSA-hcc4-c3v8-rx92)

A vulnerability was found in aio-libs aiohttp up to 3.13.3 and classified as problematic . This impacts an unknown function of the component DNS Cache Handler . The manipulation results in allocation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34514 | aio-libs aiohttp up to 3.13.3 Parameter content_type response splitting (GHSA-2vrm-gr82-f7m5)

A vulnerability was found in aio-libs aiohttp up to 3.13.3 . It has been classified as problematic . Affected is an unknown function of the component Parameter Handler . This manipulation of the argum…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34516 | aio-libs aiohttp up to 3.13.3 allocation of resources (GHSA-m5qp-6w8w-w647)

A vulnerability was found in aio-libs aiohttp up to 3.13.3 . It has been declared as problematic . Affected by this vulnerability is an unknown functionality. Such manipulation leads to allocation of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34517 | aio-libs aiohttp up to 3.13.3 Multipart Form client_max_size allocation of resources (GHSA-3wq7-rqq7-wx6j)

A vulnerability was found in aio-libs aiohttp up to 3.13.3 . It has been rated as problematic . Affected by this issue is the function client_max_size of the component Multipart Form Handler . Perform…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34518 | aio-libs aiohttp up to 3.13.3 Proxy-Authorization Header information disclosure (GHSA-966j-vmvw-g2g9)

A vulnerability categorized as problematic has been discovered in aio-libs aiohttp up to 3.13.3 . This affects an unknown part of the component Proxy-Authorization Header Handler . Executing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34545 | AcademySoftwareFoundation OpenEXR up to 3.4.6 EXR File Parser heap-based overflow (GHSA-ghfj-fx47-wg97)

A vulnerability identified as critical has been detected in AcademySoftwareFoundation OpenEXR up to 3.4.6 . This vulnerability affects unknown code of the component EXR File Parser . The manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-3987 | WatchGuard Fireware OS up to 12.11.8/2026.1.2 Web UI path traversal (wgsa-2026-00009)

A vulnerability labeled as critical has been found in WatchGuard Fireware OS up to 12.11.8/2026.1.2 . This issue affects some unknown processing of the component Web UI . The manipulation results in p…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2025-13916 | IBM Aspera Shares up to 1.11.0 risky encryption

A vulnerability marked as problematic has been reported in IBM Aspera Shares up to 1.11.0 . Impacted is an unknown function. This manipulation causes risky cryptographic algorithm. The identification …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34531 | miguelgrinberg Flask-HTTPAuth up to 4.8.0 on Flask improper authentication (GHSA-p44q-vqpr-4xmg)

A vulnerability described as critical has been identified in miguelgrinberg Flask-HTTPAuth up to 4.8.0 on Flask. The affected element is an unknown function. Such manipulation leads to improper authen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34543 | AcademySoftwareFoundation OpenEXR up to 3.4.7 EXR File Parser uninitialized resource (GHSA-vc68-257w-m432)

A vulnerability classified as problematic has been found in AcademySoftwareFoundation OpenEXR up to 3.4.7 . The impacted element is an unknown function of the component EXR File Parser . Performing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34544 | AcademySoftwareFoundation OpenEXR up to 3.4.7 EXR File Parser exr_decoding_run integer overflow (GHSA-h762-rhv3-h25v)

A vulnerability classified as critical was found in AcademySoftwareFoundation OpenEXR up to 3.4.7 . This affects the function exr_decoding_run of the component EXR File Parser . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34570 | ci4-cms-erp ci4ms 0.28.5.0 access control (GHSA-4vxv-4xq4-p84h)

A vulnerability, which was classified as critical , has been found in ci4-cms-erp ci4ms 0.28.5.0 . This impacts an unknown function. The manipulation leads to improper access controls. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34572 | ci4-cms-erp ci4ms 0.28.5.0 access control (GHSA-8fq3-c5w3-pj3q)

A vulnerability, which was classified as critical , was found in ci4-cms-erp ci4ms 0.28.5.0 . Affected is an unknown function. The manipulation results in improper access controls. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34561 | ci4-cms-erp ci4ms 0.28.5.0 Setting cross site scripting (GHSA-gcfj-cf7j-vwgj)

A vulnerability has been found in ci4-cms-erp ci4ms 0.28.5.0 and classified as problematic . Affected by this vulnerability is an unknown functionality of the component Setting Handler . This manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34873 | mbed TLS up to 3.5.0/4.0.0 TLS 1.3 Session privilege escalation

A vulnerability was found in mbed TLS up to 3.5.0/4.0.0 and classified as critical . Affected by this issue is some unknown functionality of the component TLS 1.3 Session Handler . Such manipulation l…

VulDB Read →
← Prev 179 / 267 Next →