CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6408 articles  ·  updated every 4 hours · grows forever

6408Total
4069Full Text
May 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-2265 | Replicator 1.0.5 deserialization

A vulnerability marked as critical has been reported in Replicator 1.0.5 . Affected by this issue is some unknown functionality. Performing a manipulation results in deserialization. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-33990 | docker model-runner up to 1.1.24 server-side request forgery

A vulnerability described as critical has been identified in docker model-runner up to 1.1.24 . This affects an unknown part. Executing a manipulation can lead to server-side request forgery. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-30273 | Sinaptik AI pandas-ai 3.0.0 pandasai.agent.base._execute_sql_query sql injection

A vulnerability classified as critical has been found in Sinaptik AI pandas-ai 3.0.0 . This vulnerability affects the function pandasai.agent.base._execute_sql_query . The manipulation leads to sql in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-33978 | streetwriters notesnook up to 3.3.16 cross site scripting

A vulnerability classified as problematic was found in streetwriters notesnook up to 3.3.16 . This issue affects some unknown processing. The manipulation results in cross site scripting. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-30643 | DedeCMS 5.7.118 Module setup tag unrestricted upload

A vulnerability, which was classified as critical , has been found in DedeCMS 5.7.118 . Impacted is an unknown function of the component Module Handler . This manipulation of the argument setup tag ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5360 | Free5GC 4.2.0 aper type confusion (Issue 831)

A vulnerability, which was classified as problematic , was found in Free5GC 4.2.0 . The affected element is an unknown function of the component aper . Such manipulation leads to type confusion. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34236 | auth0 auth0-PHP up to 8.18.x entropy (GHSA-w3wc-44p4-m4j7)

A vulnerability has been found in auth0 auth0-PHP up to 8.18.x and classified as problematic . The impacted element is an unknown function. Performing a manipulation results in insufficient entropy. T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34397 | himmelblau-idm himmelblau up to 2.3.8/3.1.0 NSS Module privileges management (GHSA-v7xx-7mqc-g835)

A vulnerability was found in himmelblau-idm himmelblau up to 2.3.8/3.1.0 and classified as critical . This affects an unknown function of the component NSS Module . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34222 | open-webui Open WebUI up to 0.8.10 improper authorization (GHSA-7429-hxcv-268m)

A vulnerability was found in open-webui Open WebUI up to 0.8.10 . It has been classified as critical . This impacts an unknown function. The manipulation leads to improper authorization. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34445 | onnx up to 1.20.x Model setattr input validation (GHSA-538c-55jv-c5g9)

A vulnerability was found in onnx up to 1.20.x . It has been declared as critical . Affected is the function setattr of the component Model Handler . The manipulation results in improper input validat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34159 | ggml-org llama.cpp up to 55abc39/up to 55d4206c8/b7824 GRAPH_COMPUTE Message deserialize_tensor memory corruption (GHSA-j8rj-fmpv-wcxw)

A vulnerability was found in ggml-org llama.cpp up to 55abc39/up to 55d4206c8/b7824 . It has been rated as critical . Affected by this vulnerability is the function deserialize_tensor of the file llam…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-27489 | onnx up to 1.20.x path traversal (GHSA-3r9x-f23j-gc73)

A vulnerability categorized as problematic has been discovered in onnx up to 1.20.x . Affected by this issue is some unknown functionality. Such manipulation leads to relative path traversal. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34446 | onnx up to 1.20.x path traversal (GHSA-cmw6-hcpp-c6jp)

A vulnerability identified as critical has been detected in onnx up to 1.20.x . This affects an unknown part. Performing a manipulation results in path traversal. This vulnerability is identified as C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34447 | onnx up to 1.20.x symlink (GHSA-p433-9wv8-28xj)

A vulnerability labeled as critical has been found in onnx up to 1.20.x . This vulnerability affects unknown code. Executing a manipulation can lead to symlink following. This vulnerability is tracked…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5199 | temporal up to 1.29.4/1.30.2 authorization

A vulnerability marked as problematic has been reported in temporal up to 1.29.4/1.30.2 . This issue affects some unknown processing. The manipulation leads to authorization bypass. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34874 | mbed TLS up to 3.6.5/4.0.0 null pointer dereference

A vulnerability described as problematic has been identified in mbed TLS up to 3.6.5/4.0.0 . Impacted is an unknown function. The manipulation results in null pointer dereference. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5368 | projectworlds Car Rental Project 1.0 Parameter /login.php uname sql injection

A vulnerability classified as critical has been found in projectworlds Car Rental Project 1.0 . The affected element is an unknown function of the file /login.php of the component Parameter Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34376 | mrmn2 PdfDing up to 1.6.x authorization (GHSA-42x7-vvj4-4cj3)

A vulnerability classified as problematic was found in mrmn2 PdfDing up to 1.6.x . The impacted element is an unknown function. Such manipulation leads to incorrect authorization. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34072 | fccview cronmaster up to 2.1.x improper authentication (GHSA-9whh-mffv-xvh6)

A vulnerability, which was classified as critical , has been found in fccview cronmaster up to 2.1.x . This affects an unknown function. Performing a manipulation results in improper authentication. T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34751 | payloadcms payload up to 3.79.0 Password Reset external control of assumed-immutable web parameter (GHSA-hp5w-3hxx-vmwf)

A vulnerability, which was classified as critical , was found in payloadcms payload up to 3.79.0 . This impacts an unknown function of the component Password Reset Handler . Executing a manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-35000 | dgtlmoon changedetection.io up to 0.54.6 SafeXPath3Parser json-doc incomplete blacklist

A vulnerability has been found in dgtlmoon changedetection.io up to 0.54.6 and classified as critical . Affected is the function json-doc of the component SafeXPath3Parser . The manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34076 | clerk javascript clerkFrontendApiProxy server-side request forgery (GHSA-gjxx-92w9-8v8f)

A vulnerability was found in clerk javascript and classified as critical . Affected by this vulnerability is the function clerkFrontendApiProxy . The manipulation results in server-side request forger…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34875 | mbed TLS up to 1.0.0/3.6.5 FFDH Key Export buffer overflow

A vulnerability was found in mbed TLS up to 1.0.0/3.6.5 . It has been classified as critical . Affected by this issue is some unknown functionality of the component FFDH Key Export Handler . This mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-25835 | mbed TLS up to 3.6.5 entropy

A vulnerability was found in mbed TLS up to 3.6.5 . It has been declared as problematic . This affects an unknown part. Such manipulation leads to insufficient entropy in prng. This vulnerability is u…

VulDB Read →
← Prev 181 / 267 Next →