CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8487 articles  ·  updated every 4 hours · grows forever

8487Total
4176Full Text
Jun 12, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-4065 | nextendweb Smart Slider 3 Plugin up to 3.5.1.33 on WordPress display_admin_ajax authorization

A vulnerability has been found in nextendweb Smart Slider 3 Plugin up to 3.5.1.33 on WordPress and classified as critical . This issue affects the function display_admin_ajax . Performing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39369 | WWBN AVideo up to 26.0 aVideoEncoderReceiveImage.json.php path traversal (GHSA-f4f9-627c-jh33)

A vulnerability was found in WWBN AVideo up to 26.0 and classified as critical . Impacted is an unknown function of the file objects/aVideoEncoderReceiveImage.json.php . Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34765 | Electron up to 39.8.4/40.8.4/41.0.x window.open exposure of resource

A vulnerability was found in Electron up to 39.8.4/40.8.4/41.0.x . It has been classified as problematic . The affected element is the function window.open . The manipulation leads to exposure of reso…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34580 | randombit botan up to 3.11.0 Path Validation certificate_known certificate validation

A vulnerability was found in randombit botan up to 3.11.0 . It has been declared as critical . The impacted element is the function Certificate_Store::certificate_known of the component Path Validatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34582 | randombit botan up to 3.11.0 behavioral workflow

A vulnerability was found in randombit botan up to 3.11.0 . It has been rated as problematic . This affects an unknown function. This manipulation causes enforcement of behavioral workflow. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34781 | Electron up to 39.8.4/40.8.4/41.0.x clipboard.readImage null pointer dereference

A vulnerability categorized as problematic has been discovered in Electron up to 39.8.4/40.8.4/41.0.x . This impacts the function clipboard.readImage . Such manipulation leads to null pointer derefere…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39371 | redwoodjs sdk up to 1.0.5 GET Request serverAction cross-site request forgery (GHSA-x8rx-789c-2pxq)

A vulnerability identified as problematic has been detected in redwoodjs sdk up to 1.0.5 . Affected is the function serverAction of the component GET Request Handler . Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-34371 | danny-avila LibreChat up to 0.8.3 writeFileSync path traversal

A vulnerability labeled as critical has been found in danny-avila LibreChat up to 0.8.3 . Affected by this vulnerability is the function writeFileSync . Executing a manipulation can lead to path trave…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-35568 | modelcontextprotocol java-sdk up to 0.x Model Context Protocol origin validation

A vulnerability marked as critical has been reported in modelcontextprotocol java-sdk up to 0.x . Affected by this issue is some unknown functionality of the component Model Context Protocol . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39839 | Wikimedia Cargo Extension up to 3.8.6 on Mediawiki cross site scripting

A vulnerability described as problematic has been identified in Wikimedia Cargo Extension up to 3.8.6 on Mediawiki. This affects an unknown part. The manipulation results in basic cross site scripting…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
CVE-2026-39838 | Wikimedia ProofreadPage Extension up to 1.43.6/1.44.3/1.45.1 on MediaWiki cross site scripting

A vulnerability classified as problematic has been found in Wikimedia ProofreadPage Extension up to 1.43.6/1.44.3/1.45.1 on MediaWiki. This vulnerability affects unknown code. This manipulation causes…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 08, 2026
Windows Shell Zero-Day Vulnerability Allows Attackers to Bypass Authentication - cyberpress.org

Windows Shell Zero-Day Vulnerability Allows Attackers to Bypass Authentication cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-22682 | HKUDS OpenHarness Configuration read_file/write_file/edit_file/notebook_edit authorization

A vulnerability was found in HKUDS OpenHarness and classified as problematic . Affected by this issue is the function read_file/write_file/edit_file/notebook_edit of the component Configuration Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35615 | MervinPraison PraisonAI up to 4.5.112 _validate_path path traversal (GHSA-693f-pf34-72c5)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.112 . It has been classified as critical . This affects the function _validate_path . This manipulation causes path traversal. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-24146 | NVIDIA Triton Inference Server memory allocation

A vulnerability was found in NVIDIA Triton Inference Server . It has been declared as problematic . This vulnerability affects unknown code. Such manipulation leads to uncontrolled memory allocation. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39305 | MervinPraison PraisonAI up to 4.5.112 Action Orchestrator Feature path traversal (GHSA-jfxc-v5g9-38xr)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.112 . It has been rated as critical . This issue affects some unknown processing of the component Action Orchestrator Feature . Performin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-24174 | NVIDIA Triton Inference Server numeric conversion (EUVD-2026-19757)

A vulnerability categorized as critical has been discovered in NVIDIA Triton Inference Server . Impacted is an unknown function. Executing a manipulation can lead to incorrect conversion between numer…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39335 | ChurchCRM up to 7.1.0 entity cross site scripting (GHSA-44j4-jjw2-wcr6)

A vulnerability identified as problematic has been detected in ChurchCRM up to 7.1.0 . The affected element is an unknown function. The manipulation of the argument entity leads to cross site scriptin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35608 | RoastSlav quickdrop up to 1.5.2 File Preview Endpoint /api/file/upload-chunk cross site scripting (GHSA-f577-ffvv-w6rr)

A vulnerability labeled as problematic has been found in RoastSlav quickdrop up to 1.5.2 . The impacted element is an unknown function of the file /api/file/upload-chunk of the component File Preview …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-31272 | MRCMS 3.1.2 UserController.java save access control (EUVD-2026-19767)

A vulnerability marked as critical has been reported in MRCMS 3.1.2 . This affects the function Save of the file src/main/java/org/marker/mushroom/controller/UserController.java . This manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35574 | ChurchCRM up to 6.5.2 cross site scripting (GHSA-cx82-8xrh-7f5c)

A vulnerability described as problematic has been identified in ChurchCRM up to 6.5.2 . This impacts an unknown function. Such manipulation leads to cross site scripting. This vulnerability is uniquel…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-39336 | ChurchCRM up to 7.0.x Directory Reports Form cross site scripting (GHSA-r8cp-gg58-2r2r)

A vulnerability classified as problematic has been found in ChurchCRM up to 7.0.x . Affected is an unknown function of the component Directory Reports Form . Performing a manipulation results in cross…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35575 | ChurchCRM up to 6.5.2 cross site scripting (GHSA-gc8q-2gw7-qj7w)

A vulnerability classified as problematic was found in ChurchCRM up to 6.5.2 . Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2025-70844 | kantorge yaffa 2.0.0 Add Account Group cross site scripting

A vulnerability, which was classified as problematic , has been found in kantorge yaffa 2.0.0 . Affected by this issue is some unknown functionality of the component Add Account Group . The manipulati…

VulDB Read →
← Prev 239 / 354 Next →