CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8555 articles  ·  updated every 4 hours · grows forever

8555Total
4176Full Text
Jun 13, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35394 | mobile-next mobile-mcp up to 0.0.49 mobile_open_url improper authorization in handler for custom url scheme (GHSA-5qhv-x9j4-c3vm)

A vulnerability, which was classified as critical , has been found in mobile-next mobile-mcp up to 0.0.49 . Affected by this vulnerability is an unknown functionality of the component mobile_open_url …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35441 | Directus up to 11.16.x GraphQL /graphql resource consumption

A vulnerability, which was classified as problematic , was found in Directus up to 11.16.x . Affected by this issue is some unknown functionality of the file /graphql of the component GraphQL . The ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35412 | Directus up to 11.16.0 /files/tus authorization

A vulnerability has been found in Directus up to 11.16.0 and classified as problematic . This affects an unknown part of the file /files/tus . This manipulation causes incorrect authorization. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35413 | Directus up to 11.16.0 /graphql/system information disclosure

A vulnerability was found in Directus up to 11.16.0 and classified as problematic . This vulnerability affects unknown code of the file /graphql/system . Such manipulation leads to information disclos…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-22675 | OCS Inventory NG Server up to 2.12.3 HTTP Header /ocsinventory User-Agent cross site scripting

A vulnerability was found in OCS Inventory NG Server up to 2.12.3 . It has been classified as problematic . This issue affects some unknown processing of the file /ocsinventory of the component HTTP H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35410 | Directus up to 11.16.0 isLoginRedirectAllowed incomplete blacklist

A vulnerability was found in Directus up to 11.16.0 . It has been declared as critical . Impacted is the function isLoginRedirectAllowed . Executing a manipulation can lead to incomplete blacklist. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35399 | LabRedesCefetRJ WeGIA up to 3.6.8 Backup Filename cross site scripting (GHSA-fmwv-62wf-2hgx)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.8 . It has been rated as problematic . The affected element is an unknown function of the component Backup Filename Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35442 | Directus up to 11.16.x directus_users information disclosure

A vulnerability categorized as problematic has been discovered in Directus up to 11.16.x . The impacted element is an unknown function of the component directus_users . The manipulation results in inf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35411 | Directus up to 11.16.0 /admin/tfa-setup redirect

A vulnerability identified as problematic has been detected in Directus up to 11.16.0 . This affects an unknown function of the file /admin/tfa-setup . This manipulation of the argument redirect cause…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35471 | patrickhener goshs up to 2.0.0-beta.2 tdeleteFile path traversal

A vulnerability labeled as critical has been found in patrickhener goshs up to 2.0.0-beta.2 . This impacts the function tdeleteFile . Such manipulation leads to path traversal. This vulnerability is t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35392 | patrickhener goshs up to 2.0.0-beta.2 httpserver/updown.go path traversal (GHSA-g8mv-vp7j-qp64)

A vulnerability marked as critical has been reported in patrickhener goshs up to 2.0.0-beta.2 . Affected is an unknown function of the file httpserver/updown.go . Performing a manipulation results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35393 | patrickhener goshs up to 2.0.0-beta.2 Multipart Upload path traversal (GHSA-jg56-wf8x-qrv5)

A vulnerability described as critical has been identified in patrickhener goshs up to 2.0.0-beta.2 . Affected by this vulnerability is an unknown functionality of the component Multipart Upload Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 07, 2026
CVE-2026-35409 | Directus up to 11.15.x server-side request forgery

A vulnerability classified as critical has been found in Directus up to 11.15.x . Affected by this issue is some unknown functionality. The manipulation leads to server-side request forgery. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35030 | BerriAI litellm up to 1.82.x JWT/OIDC enable_jwt_auth improper authentication (GHSA-jjhc-v7c2-5hh6)

A vulnerability labeled as critical has been found in BerriAI litellm up to 1.82.x . This affects the function enable_jwt_auth of the component JWT/OIDC . Such manipulation leads to improper authentic…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35039 | nearform fast-jwt up to 6.0.x data authenticity (GHSA-rp9m-7r4c-75qg)

A vulnerability marked as critical has been reported in nearform fast-jwt up to 6.0.x . This vulnerability affects unknown code. Performing a manipulation results in insufficient verification of data …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35036 | lin-snow Ech0 up to 4.2.7 Response Body /api/website/title server-side request forgery (GHSA-wc4h-2348-jc3p)

A vulnerability described as critical has been identified in lin-snow Ech0 up to 4.2.7 . This issue affects some unknown processing of the file /api/website/title of the component Response Body Handle…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35035 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0 Setting cross site scripting (GHSA-5ghq-42rg-769x)

A vulnerability classified as problematic has been found in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0 . Impacted is an unknown function of the component Setting Handler . The manipulation leads to cross sit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35037 | lin-snow Ech0 up to 4.2.7 Endpoint /api/website/title website_url server-side request forgery (GHSA-cqgf-f4x7-g6wc)

A vulnerability classified as critical was found in lin-snow Ech0 up to 4.2.7 . The affected element is an unknown function of the file /api/website/title of the component Endpoint . The manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35174 | xenocrat chyrp-lite prior 2026.01 Setting config.json.php path traversal (GHSA-p6pf-2grm-8257)

A vulnerability, which was classified as critical , has been found in xenocrat chyrp-lite . The impacted element is an unknown function of the file config.json.php of the component Setting Handler . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35470 | devcode-it openstamanager up to 2.10.1 Customer Information confronta_righe.php righe sql injection (GHSA-mmm5-3g4x-qw39)

A vulnerability, which was classified as critical , was found in devcode-it openstamanager up to 2.10.1 . This affects an unknown function of the file confronta_righe.php of the component Customer Inf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35164 | Ajax30 BraveCMS up to 2.0.5 CkEditorController.php unrestricted upload (GHSA-2j4q-6p52-4rhw)

A vulnerability has been found in Ajax30 BraveCMS up to 2.0.5 and classified as critical . This impacts an unknown function of the file app/Http/Controllers/Dashboard/CkEditorController.php . Performi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35044 | BentoML up to 1.4.37 generate.py generate_containerfile special elements used in a template engine (GHSA-v959-cwq9-7hr6)

A vulnerability was found in BentoML up to 1.4.37 and classified as critical . Affected is the function generate_containerfile of the file src/bentoml/_internal/container/generate.py . Executing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35050 | oobabooga text-generation-webui up to 4.1.0 Setting download-model.py path traversal (GHSA-jg96-p5p6-q3cv)

A vulnerability was found in oobabooga text-generation-webui up to 4.1.0 . It has been classified as critical . Affected by this vulnerability is an unknown functionality of the file download-model.py…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-35171 | kedro-org kedro up to 1.2.x dictConfig KEDRO_LOGGING_CONFIG code injection (GHSA-9cqf-439c-j96r)

A vulnerability was found in kedro-org kedro up to 1.2.x . It has been declared as critical . Affected by this issue is the function dictConfig . The manipulation of the argument KEDRO_LOGGING_CONFIG …

VulDB Read →
← Prev 247 / 357 Next →