CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5637 articles  ·  updated every 4 hours · grows forever

5637Total
4035Full Text
May 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43889 | Outline up to 1.6.x shares.create API authorization (GHSA-rg4j-pmch-w6pm)

A vulnerability categorized as problematic has been discovered in Outline up to 1.6.x . Affected by this issue is some unknown functionality of the component shares.create API . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-44695 | Outline up to 1.7.0 /auth/slack.post team_id/user_id cross-site request forgery (GHSA-mjgw-5j7q-gv8v)

A vulnerability identified as problematic has been detected in Outline up to 1.7.0 . This affects an unknown part of the file /auth/slack.post . The manipulation of the argument team_id/user_id leads …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43874 | WWBN AVideo up to 29.0 Outbound Message getWebSocket.json.php msgToResourceId json code injection (GHSA-ghcv-22jf-vfxm)

A vulnerability labeled as critical has been found in WWBN AVideo up to 29.0 . This vulnerability affects the function msgToResourceId of the file plugin/YPTSocket/getWebSocket.json.php of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43890 | Outline up to 1.7.0 API Endpoint subscriptions.create authorization (GHSA-gf8h-cv9v-q4fw)

A vulnerability marked as problematic has been reported in Outline up to 1.7.0 . This issue affects the function subscriptions.create of the component API Endpoint . This manipulation causes authoriza…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43888 | Outline up to 1.6.x fs.createWriteStream path traversal (GHSA-hw32-2v7j-mgqc)

A vulnerability described as critical has been identified in Outline up to 1.6.x . Impacted is the function fs.createWriteStream . Such manipulation leads to path traversal. This vulnerability is docu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-7010 | HAARG HTTP::Tiny up to 0.092 on Perl HTTP Request Host response splitting (EUVD-2026-29344)

A vulnerability classified as critical has been found in HAARG HTTP::Tiny up to 0.092 on Perl. The affected element is an unknown function of the component HTTP Request Handler . Performing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-34960 | barebox up to 2026.04.0 DHCP dhcp_message_type out-of-bounds

A vulnerability classified as problematic was found in barebox up to 2026.04.0 . The impacted element is the function dhcp_message_type of the component DHCP Handler . Executing a manipulation can lea…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42888 | advplyr audiobookshelf up to 2.33.1 Podcast Creation Endpoint PodcastController.js path traversal (GHSA-phch-9734-wrp3)

A vulnerability, which was classified as critical , has been found in advplyr audiobookshelf up to 2.33.1 . This affects an unknown function of the file server/controllers/PodcastController.js of the …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-41489 | Pi-hole up to 6.4.1 pihole-FTL-prestart.sh permission assignment (GHSA-6w8x-p785-6pm4)

A vulnerability, which was classified as problematic , was found in Pi-hole up to 6.4.1 . This impacts an unknown function of the file pihole-FTL-prestart.sh . The manipulation results in incorrect pe…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-37630 | QuickJS-NG 0.12.1 js_mapped_arguments_mark privilege escalation (Issue 1400)

A vulnerability has been found in QuickJS-NG 0.12.1 and classified as critical . Affected is the function js_mapped_arguments_mark . This manipulation causes privilege escalation. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks - CyberSecurityNews

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-41250 | taigaio taiga-front up to 6.9.0 cross site scripting (GHSA-fpm6-3pvx-3c46)

A vulnerability has been found in taigaio taiga-front up to 6.9.0 and classified as problematic . This issue affects some unknown processing. The manipulation leads to cross site scripting. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-42842 | getgrav grav/grav-plugin-form cross site scripting (GHSA-c2q3-p4jr-c55f)

A vulnerability was found in getgrav grav and grav-plugin-form and classified as problematic . Impacted is an unknown function. The manipulation results in cross site scripting. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-38569 | HireFlow 1.2 candidate_detail.html cross site scripting

A vulnerability was found in HireFlow 1.2 . It has been classified as problematic . The affected element is an unknown function of the file candidate_detail.html . This manipulation causes cross site …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45002 | OpenClaw up to 2026.4.19 authorization (GHSA-2xcp-x87w-q377)

A vulnerability was found in OpenClaw up to 2026.4.19 . It has been declared as problematic . The impacted element is an unknown function. Such manipulation leads to incorrect authorization. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-5266 | Wikimedia Echo up to 1.43.6/1.44.3/1.45.1 ApiEchoNotifications.Php information disclosure

A vulnerability was found in Wikimedia Echo up to 1.43.6/1.44.3/1.45.1 . It has been rated as problematic . This affects an unknown function of the file includes/Api/ApiEchoNotifications.Php . Perform…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-44999 | OpenClaw up to 2026.4.19 data authenticity (GHSA-57r2-h2wj-g887)

A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.4.19 . This impacts an unknown function. Executing a manipulation can lead to insufficient verification of data au…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-44997 | OpenClaw up to 2026.4.21 privileges assignment (GHSA-q3jj-46pq-826r)

A vulnerability identified as problematic has been detected in OpenClaw up to 2026.4.21 . Affected is an unknown function. The manipulation leads to incorrect privilege assignment. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45003 | OpenClaw up to 2026.4.21 Override Connector Endpoint confused deputy (GHSA-55cf-xx38-4p9p)

A vulnerability labeled as problematic has been found in OpenClaw up to 2026.4.21 . Affected by this vulnerability is an unknown functionality of the component Override Connector Endpoint . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45006 | OpenClaw up to 2026.4.22 Configuration config.apply incomplete blacklist (GHSA-cwj3-vqpp-pmxr)

A vulnerability marked as critical has been reported in OpenClaw up to 2026.4.22 . Affected by this issue is some unknown functionality of the file config.apply of the component Configuration Handler …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-5172 | dnsmasq 2.92rel2 DNS Response extract_addresses out-of-bounds write

A vulnerability described as critical has been identified in dnsmasq 2.92rel2 . This affects the function extract_addresses of the component DNS Response Handler . Such manipulation leads to out-of-bo…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45000 | OpenClaw up to 2026.4.19 server-side request forgery (GHSA-j4c5-89f5-f3pm)

A vulnerability classified as critical has been found in OpenClaw up to 2026.4.19 . This vulnerability affects unknown code. Performing a manipulation results in server-side request forgery. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45001 | OpenClaw up to 2026.4.19 Setting config.apply authorization (GHSA-7jm2-g593-4qrc)

A vulnerability classified as critical was found in OpenClaw up to 2026.4.19 . This issue affects some unknown processing of the file config.apply of the component Setting Handler . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45004 | OpenClaw up to 2026.4.22 setup-api.js process.cwd uncontrolled search path (GHSA-r39h-4c2p-3jxp)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.4.22 . Impacted is the function process.cwd of the file setup-api.js . The manipulation leads to uncontroll…

VulDB Read →
← Prev 24 / 235 Next →