CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  6455 articles  ·  updated every 4 hours · grows forever

6455Total
4070Full Text
May 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34453 | SiYuan up to 3.6.1 Publish Service authorization (ID 17246)

A vulnerability was found in SiYuan up to 3.6.1 . It has been rated as problematic . This affects an unknown function of the component Publish Service . This manipulation causes incorrect authorizatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34539 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile CTiffImg::WriteLine heap-based overflow (ID 672)

A vulnerability categorized as critical has been discovered in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 . This impacts the function CTiffImg::WriteLine of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34585 | SiYuan up to 3.6.1 Block cross site scripting (ID 17246)

A vulnerability identified as problematic has been detected in SiYuan up to 3.6.1 . Affected is an unknown function of the component Block Handler . Performing a manipulation results in cross site scr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34400 | Alerta up to 9.0.x Query String Search API sql injection (GHSA-8prr-286p-4w7j)

A vulnerability labeled as critical has been found in Alerta up to 9.0.x . Affected by this vulnerability is an unknown functionality of the component Query String Search API . Executing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34405 | nuxt-modules og-image up to 6.2.4 /_og/d/ cross site scripting (GHSA-mg36-wvcr-m75h)

A vulnerability marked as problematic has been reported in nuxt-modules og-image up to 6.2.4 . Affected by this issue is some unknown functionality of the file /_og/d/ . The manipulation leads to cros…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34541 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile CIccCombinedConnectionConditions null pointer dereference (ID 676)

A vulnerability described as problematic has been identified in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 . This affects the function CIccCombinedConnectionConditions…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34540 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile IccProfLib/IccUtil.cpp icMemDump heap-based overflow (ID 674)

A vulnerability classified as critical has been found in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 . This vulnerability affects the function icMemDump in the library …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34542 | InternationalColorConsortium iccDEV up to 2.3.1.6 ICC Color Profile IccMpeCalc.cpp Apply stack-based overflow (ID 678)

A vulnerability classified as critical was found in InternationalColorConsortium iccDEV up to 2.3.1.6 . This issue affects the function CIccCalculatorFunc::Apply in the library IccProfLib/IccMpeCalc.c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34404 | nuxt-modules og-image up to 6.2.4 /_og/d/ width/height resource consumption (GHSA-c7xp-q6q8-hg76)

A vulnerability, which was classified as problematic , has been found in nuxt-modules og-image up to 6.2.4 . Impacted is an unknown function of the file /_og/d/ . Performing a manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34441 | yhirose cpp-httplib up to 0.39.x HTTP Request request smuggling (GHSA-jv63-rm9j-6jwc)

A vulnerability, which was classified as problematic , was found in yhirose cpp-httplib up to 0.39.x . The affected element is an unknown function of the component HTTP Request Handler . Executing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34451 | Anthropic anthropic-sdk-typescript up to 0.80.x Claude API path traversal (GHSA-5474-4w2j-mq4c)

A vulnerability has been found in Anthropic anthropic-sdk-typescript up to 0.80.x and classified as critical . The impacted element is an unknown function of the component Claude API . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34448 | SiYuan up to 3.6.1 mAsse cross site scripting (ID 17246)

A vulnerability was found in SiYuan up to 3.6.1 and classified as problematic . This affects an unknown function. The manipulation of the argument mAsse results in cross site scripting. This vulnerabi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34605 | SiYuan up to 3.6.1 /api/icon/getDynamicIcon SanitizeSVG cross site scripting (ID 17246)

A vulnerability was found in SiYuan up to 3.6.1 . It has been classified as problematic . This impacts the function SanitizeSVG of the file /api/icon/getDynamicIcon . This manipulation causes cross si…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34401 | Microsoft XmlNotepad prior 2.9.0.21 HTTP/SMB xml external entity reference (GHSA-5j32-486h-42ch)

A vulnerability was found in Microsoft XmlNotepad . It has been declared as problematic . Affected is an unknown function of the component HTTP/SMB . Such manipulation leads to xml external entity ref…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34716 | WWBN AVideo up to 26.0 cross site scripting (GHSA-w4hp-w536-jg64)

A vulnerability was found in WWBN AVideo up to 26.0 . It has been rated as problematic . Affected by this vulnerability is an unknown functionality. Performing a manipulation results in cross site scr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34528 | File Browser 0.4b14/1.0/2.0 Signup permission

A vulnerability categorized as critical has been discovered in File Browser 0.4b14/1.0/2.0 . Affected by this issue is some unknown functionality of the component Signup . Executing a manipulation can…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34529 | File Browser 0.4b14/1.0/2.0 EPUB File Parser cross site scripting

A vulnerability identified as problematic has been detected in File Browser 0.4b14/1.0/2.0 . This affects an unknown part of the component EPUB File Parser . The manipulation leads to cross site scrip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE - The Hacker News

Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
Critical Vulnerability in VM2 Sandbox Library for Node.js Let Attackers run Untrusted Code - CyberSecurityNews

Critical Vulnerability in VM2 Sandbox Library for Node.js Let Attackers run Untrusted Code CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-24165 | NVIDIA BioNeMo Framework deserialization (EUVD-2026-17518)

A vulnerability has been found in NVIDIA BioNeMo Framework and classified as problematic . This affects an unknown part. The manipulation leads to deserialization. This vulnerability is referenced as …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5190 | AWS aws-c-event-stream up to 0.5.x event-stream Message out-of-bounds write

A vulnerability was found in AWS aws-c-event-stream up to 0.5.x and classified as critical . This vulnerability affects unknown code of the component event-stream Message Handler . The manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-30284 | UXGROUP Voice Recorder 10.0 privilege escalation (ID 25 / EUVD-2026-17520)

A vulnerability was found in UXGROUP Voice Recorder 10.0 . It has been classified as critical . This issue affects some unknown processing. This manipulation causes privilege escalation. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-34243 | njzjz wenxian up to 0.3.1 BIBTEX File Parser issue_comment.body command injection (GHSA-r4fj-r33x-8v88)

A vulnerability was found in njzjz wenxian up to 0.3.1 . It has been declared as critical . Impacted is an unknown function of the component BIBTEX File Parser . Such manipulation of the argument issu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 31, 2026
CVE-2026-5087 | JJNAPIORK PAGI::Middleware::Session::Store::Cookie up to 0.001003 /dev/urandom rand weak prng (EUVD-2026-17531)

A vulnerability was found in JJNAPIORK PAGI::Middleware::Session::Store::Cookie up to 0.001003 . It has been rated as problematic . The affected element is the function rand of the file /dev/urandom .…

VulDB Read →
← Prev 188 / 269 Next →