CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5667 articles  ·  updated every 4 hours · grows forever

5667Total
4035Full Text
May 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45003 | OpenClaw up to 2026.4.21 Override Connector Endpoint confused deputy (GHSA-55cf-xx38-4p9p)

A vulnerability labeled as problematic has been found in OpenClaw up to 2026.4.21 . Affected by this vulnerability is an unknown functionality of the component Override Connector Endpoint . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45006 | OpenClaw up to 2026.4.22 Configuration config.apply incomplete blacklist (GHSA-cwj3-vqpp-pmxr)

A vulnerability marked as critical has been reported in OpenClaw up to 2026.4.22 . Affected by this issue is some unknown functionality of the file config.apply of the component Configuration Handler …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-5172 | dnsmasq 2.92rel2 DNS Response extract_addresses out-of-bounds write

A vulnerability described as critical has been identified in dnsmasq 2.92rel2 . This affects the function extract_addresses of the component DNS Response Handler . Such manipulation leads to out-of-bo…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45000 | OpenClaw up to 2026.4.19 server-side request forgery (GHSA-j4c5-89f5-f3pm)

A vulnerability classified as critical has been found in OpenClaw up to 2026.4.19 . This vulnerability affects unknown code. Performing a manipulation results in server-side request forgery. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45001 | OpenClaw up to 2026.4.19 Setting config.apply authorization (GHSA-7jm2-g593-4qrc)

A vulnerability classified as critical was found in OpenClaw up to 2026.4.19 . This issue affects some unknown processing of the file config.apply of the component Setting Handler . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45004 | OpenClaw up to 2026.4.22 setup-api.js process.cwd uncontrolled search path (GHSA-r39h-4c2p-3jxp)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.4.22 . Impacted is the function process.cwd of the file setup-api.js . The manipulation leads to uncontroll…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-4893 | dnsmasq 2.92rel2 RFC 7871 Client Subnet Information information disclosure

A vulnerability, which was classified as problematic , was found in dnsmasq 2.92rel2 . The affected element is an unknown function of the component RFC 7871 Client Subnet Information Handler . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-44998 | OpenClaw up to 2026.4.19 authorization (GHSA-qrp5-gfw2-gxv4)

A vulnerability has been found in OpenClaw up to 2026.4.19 and classified as critical . The impacted element is an unknown function. This manipulation causes incorrect authorization. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45005 | OpenClaw up to 2026.4.22 SecretRef operation after expiration (GHSA-q8ff-7ffm-m3r9)

A vulnerability was found in OpenClaw up to 2026.4.22 and classified as problematic . This affects an unknown function. Such manipulation of the argument SecretRef leads to operation on a resource aft…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-4890 | dnsmasq 2.92rel2 DNSSEC Validation infinite loop

A vulnerability was found in dnsmasq 2.92rel2 . It has been classified as problematic . This impacts an unknown function of the component DNSSEC Validation . Performing a manipulation results in infin…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-4891 | dnsmasq 2.92rel2 DNSSEC Validation out-of-bounds

A vulnerability was found in dnsmasq 2.92rel2 . It has been declared as problematic . Affected is an unknown function of the component DNSSEC Validation . Executing a manipulation can lead to out-of-b…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-4892 | dnsmasq 2.92rel2 DHCPv6 heap-based overflow

A vulnerability was found in dnsmasq 2.92rel2 . It has been rated as critical . Affected by this vulnerability is an unknown functionality of the component DHCPv6 Handler . The manipulation leads to h…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-44931 | malcontent 0.14.0 D-Bus API resource consumption

A vulnerability categorized as problematic has been discovered in malcontent 0.14.0 . Affected by this issue is some unknown functionality of the component D-Bus API . The manipulation results in reso…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45109 | next.js App Router Application authentication bypass

A vulnerability identified as critical has been detected in next.js . This affects an unknown part of the component App Router Application . This manipulation causes authentication bypass using altern…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-7790 | ninenines cowlib up to 2.16.0 chunk-size resource consumption

A vulnerability labeled as problematic has been found in ninenines cowlib up to 2.16.0 . This vulnerability affects unknown code. Such manipulation of the argument chunk-size leads to resource consump…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-42871 | LabRedesCefetRJ WeGIA up to 3.6.x familiar_docfamiliar.php information disclosure

A vulnerability marked as problematic has been reported in LabRedesCefetRJ WeGIA up to 3.6.x . This issue affects some unknown processing of the file atendido/familiar_docfamiliar.php . Performing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45223 | openclaw crabbox up to 0.8.x verifyUserToken authentication spoofing

A vulnerability described as critical has been identified in openclaw crabbox up to 0.8.x . Impacted is the function verifyUserToken . Executing a manipulation can lead to authentication bypass by spo…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-42864 | ManoManoTech firefighter-incident up to 0.0.53 jira_bot httpx.get missing authentication

A vulnerability classified as critical has been found in ManoManoTech firefighter-incident up to 0.0.53 . The affected element is the function httpx.get of the file /api/v2/firefighter/raid/jira_bot .…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45224 | openclaw crabbox up to 0.8.x /workspace path traversal

A vulnerability classified as critical was found in openclaw crabbox up to 0.8.x . The impacted element is an unknown function of the file /workspace . The manipulation results in path traversal. This…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-42866 | Alfredredbird tookie-osint up to 4.1fix modules/modules.py write_txt/write_csv/write_json/scan_file path traversal

A vulnerability, which was classified as critical , has been found in Alfredredbird tookie-osint up to 4.1fix . This affects the function write_txt/write_csv/write_json/scan_file of the file modules/m…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-43969 | ninenines cowlib 2.9.0 crlf injection

A vulnerability, which was classified as problematic , was found in ninenines cowlib 2.9.0 . This impacts an unknown function. Such manipulation leads to crlf injection. This vulnerability is document…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-43968 | ninenines cowlib 2.6.0 crlf injection

A vulnerability has been found in ninenines cowlib 2.6.0 and classified as problematic . Affected is an unknown function. Performing a manipulation results in crlf injection. This vulnerability is rep…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-45222 | steipete summarize up to 0.14.1 ~/.summarize/daemon.json permission assignment

A vulnerability was found in steipete summarize up to 0.14.1 and classified as problematic . Affected by this vulnerability is an unknown functionality of the file ~/.summarize/daemon.json . Executing…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-6433 | Custom css-js-php Plugin up to 2.0.7 on WordPress eval code injection (EUVD-2026-29034)

A vulnerability categorized as critical has been discovered in Custom css-js-php Plugin up to 2.0.7 on WordPress. This impacts the function eval . The manipulation results in code injection. This vuln…

VulDB Read →
← Prev 26 / 237 Next →