CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6408 articles  ·  updated every 4 hours · grows forever

6408Total
4069Full Text
May 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-25834 | mbed TLS up to 3.6.5/4.0.0 downgrade

A vulnerability was found in mbed TLS up to 3.6.5/4.0.0 . It has been rated as problematic . This vulnerability affects unknown code. Performing a manipulation results in algorithm downgrade. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-25833 | mbed TLS up to 3.6.5 x509_inet_pton_ipv6 buffer overflow

A vulnerability categorized as critical has been discovered in mbed TLS up to 3.6.5 . This issue affects the function x509_inet_pton_ipv6 . Executing a manipulation can lead to buffer overflow. The id…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5370 | krayin laravel-crm up to 2.2 Activities Module/Notes inbox.spec.ts composeMail cross site scripting (Issue 2419)

A vulnerability identified as problematic has been detected in krayin laravel-crm up to 2.2 . Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34872 | mbed TLS up to 3.6.5 FFDH entropy

A vulnerability labeled as problematic has been found in mbed TLS up to 3.6.5 . The affected element is an unknown function of the component FFDH Handler . The manipulation results in insufficient ent…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34871 | mbed TLS up to 3.6.5/4.0.x entropy

A vulnerability marked as problematic has been reported in mbed TLS up to 3.6.5/4.0.x . The impacted element is an unknown function. This manipulation causes insufficient entropy in prng. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
New Chrome Zero-Day Vulnerability Actively Exploited in Attacks — Patch Now - CyberSecurityNews

New Chrome Zero-Day Vulnerability Actively Exploited in Attacks — Patch Now CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5322 | AlejandroArciniegas mcp-data-vis MCP server.js request sql injection

A vulnerability was found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d . It has been classified as critical . This affects the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5323 | priyankark a11y-mcp up to 1.0.5 src/index.js A11yServer server-side request forgery

A vulnerability was found in priyankark a11y-mcp up to 1.0.5 . It has been declared as critical . This vulnerability affects the function A11yServer of the file src/index.js . The manipulation results…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5325 | SourceCodester Simple Customer Relationship Management System 1.0 Create Ticket /create-ticket.php Description cross site scripting

A vulnerability was found in SourceCodester Simple Customer Relationship Management System 1.0 . It has been rated as problematic . This issue affects some unknown processing of the file /create-ticke…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5326 | SourceCodester Leave Application System 1.0 User Information index.php?page=manage_user ID authorization

A vulnerability categorized as problematic has been discovered in SourceCodester Leave Application System 1.0 . Impacted is an unknown function of the file /index.php?page=manage_user of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5327 | efforthye fast-filesystem-mcp up to 3.5.1 src/index.ts handleGetDiskUsage command injection (Issue 15)

A vulnerability identified as critical has been detected in efforthye fast-filesystem-mcp up to 3.5.1 . The affected element is the function handleGetDiskUsage of the file src/index.ts . Performing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5328 | shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6 ProductItemDao Interface ProductIndexServiceImpl.java listItem sidx/sort sql injection

A vulnerability labeled as critical has been found in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6 . The impacted element is the function listItem of the file src/main/java/c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-35091 | Corosync UDP Packet function return value

A vulnerability marked as critical has been reported in Corosync . This affects an unknown function of the component UDP Packet Handler . The manipulation leads to incorrect check of function return v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-35092 | Corosync UDP Packet integer overflow

A vulnerability described as problematic has been identified in Corosync . This impacts an unknown function of the component UDP Packet Handler . The manipulation results in integer overflow. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-0522 | VertiGIS FM up to 10.11.362 external reference

A vulnerability classified as critical has been found in VertiGIS FM up to 10.11.362 . Affected is an unknown function. This manipulation causes externally controlled reference. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-3877 | VertiGIS FM up to 10.13.402 cross site scripting

A vulnerability classified as problematic was found in VertiGIS FM up to 10.13.402 . Affected by this vulnerability is an unknown functionality. Such manipulation leads to cross site scripting. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5330 | SourceCodester/mayuri_k Best Courier Management System 1.0 User Delete ajax.php?action=delete_user ID access control

A vulnerability, which was classified as critical , has been found in SourceCodester/mayuri_k Best Courier Management System 1.0 . Affected by this issue is some unknown functionality of the file /aja…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5331 | OpenCart 4.1.0.3 Extension Installer Page installer.php path traversal

A vulnerability, which was classified as critical , was found in OpenCart 4.1.0.3 . This affects an unknown part of the file installer.php of the component Extension Installer Page . Executing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5332 | Xiaopi Panel 1.0.0 WAF Firewall /demo.php param cross site scripting

A vulnerability has been found in Xiaopi Panel 1.0.0 and classified as problematic . This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall . The manipulation of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5333 | DefaultFuction Content-Management-System 1.0 /admin/tools.php host command injection

A vulnerability was found in DefaultFuction Content-Management-System 1.0 and classified as critical . This issue affects some unknown processing of the file /admin/tools.php . The manipulation of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5334 | itsourcecode Online Enrollment System 1.0 Parameter index.php?view=edit&id=3 deptid sql injection

A vulnerability was found in itsourcecode Online Enrollment System 1.0 . It has been classified as critical . Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5338 | Tenda G103 1.0.0.5 Setting system.lua action_set_system_settings lanIp command injection

A vulnerability was found in Tenda G103 1.0.0.5 . It has been declared as critical . The affected element is the function action_set_system_settings of the file system.lua of the component Setting Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5339 | Tenda G103 1.0.0.5 Setting gpon.lua action_set_net_settings command injection

A vulnerability was found in Tenda G103 1.0.0.5 . It has been rated as critical . The impacted element is the function action_set_net_settings of the file gpon.lua of the component Setting Handler . P…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5342 | LibRaw up to 0.22.0 TIFF/NEF decoders_libraw.cpp nikon_load_padded_packed_raw load_flags/raw_width out-of-bounds (Issue 795)

A vulnerability categorized as problematic has been discovered in LibRaw up to 0.22.0 . This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw.cpp of t…

VulDB Read →
← Prev 182 / 267 Next →