CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5637 articles  ·  updated every 4 hours · grows forever

5637Total
4035Full Text
May 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-0804 | Axis Communications AB AXIS OS up to 12.10.3 ACAP Configuration File path traversal

A vulnerability classified as critical has been found in Axis Communications AB AXIS OS up to 12.10.3 . Affected by this issue is some unknown functionality of the component ACAP Configuration File Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-1185 | Axis Communications AB AXIS OS up to 12.10.35 Configuration File permission assignment

A vulnerability classified as problematic was found in Axis Communications AB AXIS OS up to 12.10.35 . This affects an unknown part of the component Configuration File Handler . Such manipulation lead…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-1681 | zephyrproject-rtos Zephyr up to 4.3 IPv4 Address recursion

A vulnerability, which was classified as critical , has been found in zephyrproject-rtos Zephyr up to 4.3 . This vulnerability affects unknown code of the component IPv4 Address Handler . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
Adobe Patches Acrobat Reader 0-Day Vulnerability Exploited in the Wild - CyberSecurityNews

Adobe Patches Acrobat Reader 0-Day Vulnerability Exploited in the Wild CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43913 | dani-garcia vaultwarden up to 1.35.4 /api/ciphers/purge authorization (GHSA-937x-3j8m-7w7p)

A vulnerability, which was classified as problematic , was found in dani-garcia vaultwarden up to 1.35.4 . This vulnerability affects unknown code of the file /api/ciphers/purge . Such manipulation le…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-34961 | barebox up to 2026.04.0 ext4 /fs/ext4/ext4_common.c eh_entries out-of-bounds

A vulnerability has been found in barebox up to 2026.04.0 and classified as problematic . This issue affects some unknown processing of the file /fs/ext4/ext4_common.c of the component ext4 Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42188 | GeyserMC Geyser up to 2.9.2 Bedrock /give server-side request forgery (GHSA-xcfg-fcr5-gw9r)

A vulnerability was found in GeyserMC Geyser up to 2.9.2 and classified as critical . Impacted is an unknown function of the file /give of the component Bedrock Handler . Executing a manipulation can …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42564 | fccview jotty up to 1.21.x /api/app-icons/ filename path traversal (GHSA-7843-gwq8-g96f)

A vulnerability was found in fccview jotty up to 1.21.x . It has been classified as critical . The affected element is an unknown function of the file /api/app-icons/ . The manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-45362 | Sangoma Switchvox up to 8.3 cleartext storage (GHSA-mfm3-g35x-c9w8 / EUVD-2026-29354)

A vulnerability was found in Sangoma Switchvox up to 8.3 . It has been declared as problematic . The impacted element is an unknown function. The manipulation results in cleartext storage of sensitive…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43881 | WWBN AVideo up to 29.0 objects/users.json.php User::getAllUsers ignoreAdmin missing authentication (GHSA-6rvw-7p8v-mjfq)

A vulnerability was found in WWBN AVideo up to 29.0 . It has been rated as critical . This affects the function User::getAllUsers of the file objects/users.json.php . This manipulation of the argument…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43885 | WWBN AVideo up to 29.0 API Endpoint objects/plugins.json.php users_list information disclosure (GHSA-xr49-f4rh-qcjf)

A vulnerability categorized as problematic has been discovered in WWBN AVideo up to 29.0 . This impacts the function users_list of the file objects/plugins.json.php of the component API Endpoint . Suc…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43876 | WWBN AVideo up to 29.0 Raw Message notifySubscribers.json.php sendSiteEmail cross site scripting (GHSA-g9cm-rxp7-6gv5)

A vulnerability identified as problematic has been detected in WWBN AVideo up to 29.0 . Affected is the function sendSiteEmail of the file objects/notifySubscribers.json.php of the component Raw Messa…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43884 | WWBN AVideo up to 29.0 objects/EpgParser.php isSSRFSafeURL server-side request forgery (GHSA-2hch-c97c-g99x)

A vulnerability labeled as critical has been found in WWBN AVideo up to 29.0 . Affected by this vulnerability is the function isSSRFSafeURL of the file objects/EpgParser.php . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43879 | WWBN AVideo up to 29.0 metadata isValidURL server-side request forgery (GHSA-wp38-whx3-xffh)

A vulnerability marked as critical has been reported in WWBN AVideo up to 29.0 . Affected by this issue is the function isValidURL of the file /internal/loopback/metadata . The manipulation leads to s…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43873 | WWBN AVideo up to 29.0 Rejection Message cloneClient.json.php die objClone information exposure (GHSA-qm9p-p5pw-jrx2)

A vulnerability described as problematic has been identified in WWBN AVideo up to 29.0 . This affects the function die of the file plugin/CloneSite/cloneClient.json.php of the component Rejection Mess…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43875 | WWBN AVideo up to 29.0 Password Hash oauth2.php get request method with sensitive query strings (GHSA-5w8w-26ch-v5cw)

A vulnerability classified as problematic has been found in WWBN AVideo up to 29.0 . This vulnerability affects unknown code of the file plugin/MobileManager/oauth2.php of the component Password Hash …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43877 | WWBN AVideo up to 29.0 userSavePhoto.php User::isLogged cross-site request forgery (GHSA-jw8g-5j46-44rp)

A vulnerability classified as problematic was found in WWBN AVideo up to 29.0 . This issue affects the function User::isLogged of the file objects/userSavePhoto.php . Such manipulation leads to cross-…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43878 | WWBN AVideo up to 29.0 URL plugin/Meet/iframe.php cross site scripting (GHSA-mm5f-8q57-4fc4)

A vulnerability, which was classified as problematic , has been found in WWBN AVideo up to 29.0 . Impacted is an unknown function of the file plugin/Meet/iframe.php of the component URL Handler . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43880 | WWBN AVideo up to 29.0 Endpoint sendEmail.json.php sendTo verification of source (GHSA-5hgj-7gm9-cff5)

A vulnerability, which was classified as problematic , was found in WWBN AVideo up to 29.0 . The affected element is an unknown function of the file objects/sendEmail.json.php of the component Endpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43882 | WWBN AVideo up to 29.0 downloadICS.php Scheduler::downloadICS joinURL crlf injection (GHSA-mwgh-92m2-wvhv)

A vulnerability has been found in WWBN AVideo up to 29.0 and classified as problematic . The impacted element is the function Scheduler::downloadICS of the file plugin/Scheduler/downloadICS.php . The …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43883 | WWBN AVideo up to 29.0 Subscription agreementCancel.json.php authorization (GHSA-958h-qp3x-q4gj)

A vulnerability was found in WWBN AVideo up to 29.0 and classified as problematic . This affects an unknown function of the file plugin/PayPalYPT/agreementCancel.json.php of the component Subscription…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43887 | Outline up to 1.6.x cross site scripting (GHSA-rqrg-f3qc-xvgh)

A vulnerability was found in Outline up to 1.6.x . It has been classified as problematic . This impacts an unknown function. This manipulation causes cross site scripting. The identification of this v…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43897 | OP-Engineering link-preview-js up to 4.0.0 Link Preview server-side request forgery (GHSA-4gp8-rjrq-ch6q)

A vulnerability was found in OP-Engineering link-preview-js up to 4.0.0 . It has been declared as critical . Affected is an unknown function of the component Link Preview Handler . Such manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43893 | photostructure exiftool-vendored.js up to 35.18.x argument injection (GHSA-cw26-7653-2rp5)

A vulnerability was found in photostructure exiftool-vendored.js up to 35.18.x . It has been rated as critical . Affected by this vulnerability is an unknown functionality. Performing a manipulation r…

VulDB Read →
← Prev 23 / 235 Next →