CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8254 articles  ·  updated every 4 hours · grows forever

8254Total
4161Full Text
Jun 10, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33707 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 Password Reset email password recovery (GHSA-f27g-66gq-g7v2)

A vulnerability was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . It has been declared as problematic . Impacted is an unknown function of the component Password Reset Handler . The manipulation of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33710 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 time random values (GHSA-rpmg-j327-mr39)

A vulnerability was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . It has been rated as problematic . The affected element is the function Time . This manipulation causes insufficiently random values…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-32252 | Chartbrew up to 4.8.x :project_id improper authorization (GHSA-mw4f-cf22-qpcj)

A vulnerability categorized as critical has been discovered in Chartbrew up to 4.8.x . The impacted element is an unknown function of the file /team/:team_id/template/generate/:project_id . Such manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40168 | gitroomhq postiz-app up to 2.21.4 /api/public/stream server-side request forgery

A vulnerability identified as critical has been detected in gitroomhq postiz-app up to 2.21.4 . This affects an unknown function of the file /api/public/stream . Performing a manipulation results in s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40189 | patrickhener goshs up to 2.0.0-beta.3 ACL/basic-auth authorization (GHSA-wvhv-qcqf-f3cx)

A vulnerability labeled as critical has been found in patrickhener goshs up to 2.0.0-beta.3 . This impacts an unknown function of the file ACL/basic-auth . Executing a manipulation can lead to missing…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40190 | langchain-ai langsmith-sdk up to 0.5.17 set prototype pollution

A vulnerability marked as problematic has been reported in langchain-ai langsmith-sdk up to 0.5.17 . Affected is the function Set . The manipulation leads to improperly controlled modification of obje…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-27460 | TandoorRecipes recipes up to 2.6.4 ZIP File Parser data amplification (GHSA-w8pq-4pwf-r2m8)

A vulnerability described as problematic has been identified in TandoorRecipes recipes up to 2.6.4 . Affected by this vulnerability is an unknown functionality of the component ZIP File Parser . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33706 | Chamilo LMS up to 1.11.37 update_user_from_username Status privileges management (GHSA-3gqc-xr75-pcpw)

A vulnerability classified as critical has been found in Chamilo LMS up to 1.11.37 . Affected by this issue is the function update_user_from_username . This manipulation of the argument Status causes …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33736 | Chamilo LMS up to 2.0.0-RC.2 Personal Information /api/users authorization (GHSA-fp2p-fj6c-x3x9)

A vulnerability classified as problematic was found in Chamilo LMS up to 2.0.0-RC.2 . This affects an unknown part of the file /api/users of the component Personal Information Handler . Such manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33705 | Chamilo LMS up to 1.11.37 AJAX Endpoint /main/template/default/ file information disclosure (GHSA-5wjg-8x28-px57)

A vulnerability, which was classified as problematic , has been found in Chamilo LMS up to 1.11.37 . This vulnerability affects unknown code of the file /main/template/default/ of the component AJAX E…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40177 | ajenti up to 0.111 2FA improper authentication (GHSA-3mcx-6wxm-qr8v)

A vulnerability, which was classified as critical , was found in ajenti up to 0.111 . This issue affects some unknown processing of the component 2FA . Executing a manipulation can lead to improper au…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33708 | Chamilo LMS up to 1.11.37 REST API Endpoint get_user_info_from_username authorization (GHSA-qwch-82q9-q999)

A vulnerability has been found in Chamilo LMS up to 1.11.37 and classified as problematic . Impacted is the function get_user_info_from_username of the component REST API Endpoint . The manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40178 | ajenti up to 0.111 improper authentication (GHSA-8647-755q-fw9p)

A vulnerability was found in ajenti up to 0.111 and classified as critical . The affected element is an unknown function. The manipulation results in improper authentication. This vulnerability is cat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40180 | quarkiverse quarkus-openapi-generator up to 2.15.x ZIP ApicurioCodegenWrapper.java unzip path traversal (GHSA-jx2w-vp7f-456q)

A vulnerability was found in quarkiverse quarkus-openapi-generator up to 2.15.x . It has been classified as critical . The impacted element is the function unzip of the file ApicurioCodegenWrapper.jav…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-39921 | GeoNode up to 4.4.4/5.0.1 URL doc_url server-side request forgery

A vulnerability was found in GeoNode up to 4.4.4/5.0.1 . It has been declared as critical . This affects an unknown function of the component URL Handler . Such manipulation of the argument doc_url le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-30232 | Chartbrew up to 4.8.4 server-side request forgery (GHSA-p4rg-967r-w4cv)

A vulnerability was found in Chartbrew up to 4.8.4 . It has been rated as critical . This impacts an unknown function. Performing a manipulation results in server-side request forgery. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33737 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 simplexml_load_string xml external entity reference (GHSA-c4ww-qgf2-v89j)

A vulnerability categorized as problematic has been discovered in Chamilo LMS up to 1.11.37/2.0.0-RC.2 . Affected is the function simplexml_load_string . Executing a manipulation can lead to xml exter…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-39922 | GeoNode up to 4.4.4/5.0.1 WMS Service server-side request forgery

A vulnerability identified as critical has been detected in GeoNode up to 4.4.4/5.0.1 . Affected by this vulnerability is an unknown functionality of the component WMS Service . The manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40191 | craigjbass clearancekit up to 5.0.3 Destination authorization

A vulnerability labeled as problematic has been found in craigjbass clearancekit up to 5.0.3 . Affected by this issue is some unknown functionality of the component Destination Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40184 | mauriceboe TREK up to 2.7.1 missing authentication (GHSA-wxx3-84fc-mrx2)

A vulnerability marked as critical has been reported in mauriceboe TREK up to 2.7.1 . This affects an unknown part. This manipulation causes missing authentication. This vulnerability is handled as CV…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40185 | mauriceboe TREK up to 2.7.1 authorization (GHSA-pcr3-6647-jh72)

A vulnerability described as critical has been identified in mauriceboe TREK up to 2.7.1 . This vulnerability affects unknown code. Such manipulation leads to missing authorization. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-33118 | Microsoft Edge up to 146.0.3856.84

A vulnerability classified as problematic has been found in Microsoft Edge . This issue affects some unknown processing. Performing a manipulation results in an unknown weakness. This vulnerability wa…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-40194 | phpseclib up to 1.0.27/2.0.52/3.0.50 SSH2::get_binary_packet timing discrepancy (GHSA-r854-jrxh-36qx)

A vulnerability classified as problematic was found in phpseclib up to 1.0.27/2.0.52/3.0.50 . Impacted is the function SSH2::get_binary_packet . Executing a manipulation can lead to observable timing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 11, 2026
CVE-2026-5724 | temporal up to 1.28.3/1.29.5/1.30.3 StreamWorkflowReplicationMessages endpoint missing authentication

A vulnerability, which was classified as critical , has been found in temporal up to 1.28.3/1.29.5/1.30.3 . The affected element is an unknown function of the file streaming AdminService/StreamWorkflo…

VulDB Read →
← Prev 212 / 344 Next →