CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5667 articles  ·  updated every 4 hours · grows forever

5667Total
4035Full Text
May 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43880 | WWBN AVideo up to 29.0 Endpoint sendEmail.json.php sendTo verification of source (GHSA-5hgj-7gm9-cff5)

A vulnerability, which was classified as problematic , was found in WWBN AVideo up to 29.0 . The affected element is an unknown function of the file objects/sendEmail.json.php of the component Endpoin…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43882 | WWBN AVideo up to 29.0 downloadICS.php Scheduler::downloadICS joinURL crlf injection (GHSA-mwgh-92m2-wvhv)

A vulnerability has been found in WWBN AVideo up to 29.0 and classified as problematic . The impacted element is the function Scheduler::downloadICS of the file plugin/Scheduler/downloadICS.php . The …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43883 | WWBN AVideo up to 29.0 Subscription agreementCancel.json.php authorization (GHSA-958h-qp3x-q4gj)

A vulnerability was found in WWBN AVideo up to 29.0 and classified as problematic . This affects an unknown function of the file plugin/PayPalYPT/agreementCancel.json.php of the component Subscription…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43887 | Outline up to 1.6.x cross site scripting (GHSA-rqrg-f3qc-xvgh)

A vulnerability was found in Outline up to 1.6.x . It has been classified as problematic . This impacts an unknown function. This manipulation causes cross site scripting. The identification of this v…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43897 | OP-Engineering link-preview-js up to 4.0.0 Link Preview server-side request forgery (GHSA-4gp8-rjrq-ch6q)

A vulnerability was found in OP-Engineering link-preview-js up to 4.0.0 . It has been declared as critical . Affected is an unknown function of the component Link Preview Handler . Such manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43893 | photostructure exiftool-vendored.js up to 35.18.x argument injection (GHSA-cw26-7653-2rp5)

A vulnerability was found in photostructure exiftool-vendored.js up to 35.18.x . It has been rated as critical . Affected by this vulnerability is an unknown functionality. Performing a manipulation r…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43889 | Outline up to 1.6.x shares.create API authorization (GHSA-rg4j-pmch-w6pm)

A vulnerability categorized as problematic has been discovered in Outline up to 1.6.x . Affected by this issue is some unknown functionality of the component shares.create API . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-44695 | Outline up to 1.7.0 /auth/slack.post team_id/user_id cross-site request forgery (GHSA-mjgw-5j7q-gv8v)

A vulnerability identified as problematic has been detected in Outline up to 1.7.0 . This affects an unknown part of the file /auth/slack.post . The manipulation of the argument team_id/user_id leads …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43874 | WWBN AVideo up to 29.0 Outbound Message getWebSocket.json.php msgToResourceId json code injection (GHSA-ghcv-22jf-vfxm)

A vulnerability labeled as critical has been found in WWBN AVideo up to 29.0 . This vulnerability affects the function msgToResourceId of the file plugin/YPTSocket/getWebSocket.json.php of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43890 | Outline up to 1.7.0 API Endpoint subscriptions.create authorization (GHSA-gf8h-cv9v-q4fw)

A vulnerability marked as problematic has been reported in Outline up to 1.7.0 . This issue affects the function subscriptions.create of the component API Endpoint . This manipulation causes authoriza…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43888 | Outline up to 1.6.x fs.createWriteStream path traversal (GHSA-hw32-2v7j-mgqc)

A vulnerability described as critical has been identified in Outline up to 1.6.x . Impacted is the function fs.createWriteStream . Such manipulation leads to path traversal. This vulnerability is docu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-7010 | HAARG HTTP::Tiny up to 0.092 on Perl HTTP Request Host response splitting (EUVD-2026-29344)

A vulnerability classified as critical has been found in HAARG HTTP::Tiny up to 0.092 on Perl. The affected element is an unknown function of the component HTTP Request Handler . Performing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-34960 | barebox up to 2026.04.0 DHCP dhcp_message_type out-of-bounds

A vulnerability classified as problematic was found in barebox up to 2026.04.0 . The impacted element is the function dhcp_message_type of the component DHCP Handler . Executing a manipulation can lea…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42888 | advplyr audiobookshelf up to 2.33.1 Podcast Creation Endpoint PodcastController.js path traversal (GHSA-phch-9734-wrp3)

A vulnerability, which was classified as critical , has been found in advplyr audiobookshelf up to 2.33.1 . This affects an unknown function of the file server/controllers/PodcastController.js of the …

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-41489 | Pi-hole up to 6.4.1 pihole-FTL-prestart.sh permission assignment (GHSA-6w8x-p785-6pm4)

A vulnerability, which was classified as problematic , was found in Pi-hole up to 6.4.1 . This impacts an unknown function of the file pihole-FTL-prestart.sh . The manipulation results in incorrect pe…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-37630 | QuickJS-NG 0.12.1 js_mapped_arguments_mark privilege escalation (Issue 1400)

A vulnerability has been found in QuickJS-NG 0.12.1 and classified as critical . Affected is the function js_mapped_arguments_mark . This manipulation causes privilege escalation. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks - CyberSecurityNews

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-41250 | taigaio taiga-front up to 6.9.0 cross site scripting (GHSA-fpm6-3pvx-3c46)

A vulnerability has been found in taigaio taiga-front up to 6.9.0 and classified as problematic . This issue affects some unknown processing. The manipulation leads to cross site scripting. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-42842 | getgrav grav/grav-plugin-form cross site scripting (GHSA-c2q3-p4jr-c55f)

A vulnerability was found in getgrav grav and grav-plugin-form and classified as problematic . Impacted is an unknown function. The manipulation results in cross site scripting. This vulnerability is …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-38569 | HireFlow 1.2 candidate_detail.html cross site scripting

A vulnerability was found in HireFlow 1.2 . It has been classified as problematic . The affected element is an unknown function of the file candidate_detail.html . This manipulation causes cross site …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45002 | OpenClaw up to 2026.4.19 authorization (GHSA-2xcp-x87w-q377)

A vulnerability was found in OpenClaw up to 2026.4.19 . It has been declared as problematic . The impacted element is an unknown function. Such manipulation leads to incorrect authorization. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-5266 | Wikimedia Echo up to 1.43.6/1.44.3/1.45.1 ApiEchoNotifications.Php information disclosure

A vulnerability was found in Wikimedia Echo up to 1.43.6/1.44.3/1.45.1 . It has been rated as problematic . This affects an unknown function of the file includes/Api/ApiEchoNotifications.Php . Perform…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-44999 | OpenClaw up to 2026.4.19 data authenticity (GHSA-57r2-h2wj-g887)

A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.4.19 . This impacts an unknown function. Executing a manipulation can lead to insufficient verification of data au…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-44997 | OpenClaw up to 2026.4.21 privileges assignment (GHSA-q3jj-46pq-826r)

A vulnerability identified as problematic has been detected in OpenClaw up to 2026.4.21 . Affected is an unknown function. The manipulation leads to incorrect privilege assignment. This vulnerability …

VulDB Read →
← Prev 25 / 237 Next →