CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9140 articles  ·  updated every 4 hours · grows forever

9140Total
4195Full Text
Jun 19, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-34935 | MervinPraison PraisonAI up to 4.5.68 anyio.open_process mcp os command injection (GHSA-9gm9-c8mq-vq7m)

A vulnerability was found in MervinPraison PraisonAI up to 4.5.68 . It has been classified as critical . This affects the function anyio.open_process . Performing a manipulation of the argument mcp re…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2017-20238 | Belden Hirschmann Industrial HiVision up to 06.0.05/06.0.5/07.00 Web Interface improper authorization

A vulnerability was found in Belden Hirschmann Industrial HiVision up to 06.0.05/06.0.5/07.00 . It has been declared as critical . This vulnerability affects unknown code of the component Web Interfac…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-34052 | jupyterhub ltiauthenticator up to 1.6.2 memory leak (GHSA-8mxq-7xr7-2fxj)

A vulnerability was found in jupyterhub ltiauthenticator up to 1.6.2 . It has been rated as problematic . This issue affects some unknown processing. The manipulation leads to memory leak. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-33175 | jupyterhub oauthenticator up to 17.3.x usrname_claim improper authentication (GHSA-rrvg-cxh4-qhrv)

A vulnerability categorized as critical has been discovered in jupyterhub oauthenticator up to 17.3.x . Impacted is an unknown function. The manipulation of the argument usrname_claim results in impro…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-33709 | Jupyter Notbook up to 5.4.3 Jupyterhub redirect (GHSA-3vff-hjqv-m7h8)

A vulnerability identified as problematic has been detected in Jupyter Notbook up to 5.4.3 . The affected element is an unknown function of the component Jupyterhub . This manipulation causes open red…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2016-15058 | Belden Hirschmann HiLCOS Classic Platform up to 05.3.06/05.3.6/09.0.05/09.0.5 SNMP password recoverable

A vulnerability labeled as critical has been found in Belden Hirschmann HiLCOS Classic Platform up to 05.3.06/05.3.6/09.0.05/09.0.5 . The impacted element is an unknown function of the component SNMP …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-35043 | BentoML up to 1.4.37 command injection

A vulnerability marked as critical has been reported in BentoML up to 1.4.37 . This affects an unknown function. Performing a manipulation results in command injection. This vulnerability is known as …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-35042 | nearform fast-jwt crit Header Extension data authenticity

A vulnerability described as problematic has been identified in nearform fast-jwt . This impacts an unknown function of the component crit Header Extension . Executing a manipulation can lead to insuf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-33752 | curl_cffi prior 0.15.0 redirect

A vulnerability classified as problematic has been found in curl_cffi . Affected is an unknown function. The manipulation leads to open redirect. This vulnerability is uniquely identified as CVE-2026-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5526 | Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1 /bin/httpd access control

A vulnerability classified as critical was found in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1 . Affected by this vulnerability is an unknown functionality of the file /bin/httpd . The manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5527 | Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53 ECDSA P-256 Private Key /etc/www/pem/server.key hard-coded key

A vulnerability, which was classified as problematic , has been found in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53 . Affected by this issue is some unknown functionality of the file /etc/www/pem/ser…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5528 | MoussaabBadla code-screenshot-mcp up to 0.1.0 HTTP Interface os command injection

A vulnerability, which was classified as critical , was found in MoussaabBadla code-screenshot-mcp up to 0.1.0 . This affects an unknown part of the component HTTP Interface . Such manipulation leads …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5529 | Dromara lamp-cloud up to 5.8.1 DefUserController /defUser/pageUser improper authorization (Issue 403)

A vulnerability has been found in Dromara lamp-cloud up to 5.8.1 and classified as critical . This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserCon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5530 | Ollama up to 18.1 Model Pull API server/download.go server-side request forgery

A vulnerability was found in Ollama up to 18.1 and classified as critical . This issue affects some unknown processing of the file server/download.go of the component Model Pull API . Executing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5531 | SourceCodester Student Result Management System 1.0 HTTP GET Request /login_credentials.txt cleartext storage in file

A vulnerability was found in SourceCodester Student Result Management System 1.0 . It has been classified as problematic . Impacted is an unknown function of the file /login_credentials.txt of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5532 | ScrapeGraphAI scrapegraph-ai up to 1.74.0 GenerateCodeNode generate_code_node.py create_sandbox_and_execute os command injection

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0 . It has been declared as critical . The affected element is the function create_sandbox_and_execute of the file scrapegraphai/no…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5533 | badlogic pi-mono 0.58.4 SVG Artifact SvgArtifact.ts cross site scripting

A vulnerability was found in badlogic pi-mono 0.58.4 . It has been rated as problematic . The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5534 | itsourcecode Online Enrollment System 1.0 Parameter index.php?view=edit&id=10 USERID sql injection

A vulnerability categorized as critical has been discovered in itsourcecode Online Enrollment System 1.0 . This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the compo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5535 | FedML-AI FedML up to 0.8.9 MQTT Message FileUtils.java dataSet path traversal

A vulnerability identified as critical has been detected in FedML-AI FedML up to 0.8.9 . This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler . Performing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5536 | FedML-AI FedML up to 0.8.9 gRPC server grpc_server.py sendMessage deserialization

A vulnerability labeled as critical has been found in FedML-AI FedML up to 0.8.9 . Affected is the function sendMessage of the file grpc_server.py of the component gRPC server . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5537 | halex CourseSEL up to 1.1.0 HTTP GET Parameter IndexController.class.php check_sel seid sql injection

A vulnerability marked as critical has been reported in halex CourseSEL up to 1.1.0 . Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.p…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5538 | QingdaoU OnlineJudge up to 1.6.1 judge_server_heartbeat Endpoint JudgeServer.service_url server-side request forgery

A vulnerability described as critical has been identified in QingdaoU OnlineJudge up to 1.6.1 . Affected by this issue is the function service_url of the file JudgeServer.service_url of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5539 | code-projects Simple Laundry System 1.0 Parameter /modifymember.php firstName cross site scripting

A vulnerability classified as problematic has been found in code-projects Simple Laundry System 1.0 . This affects an unknown part of the file /modifymember.php of the component Parameter Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 04, 2026
CVE-2026-5540 | code-projects Simple Laundry System 1.0 Parameter /modifymember.php firstName sql injection

A vulnerability classified as critical was found in code-projects Simple Laundry System 1.0 . This vulnerability affects unknown code of the file /modifymember.php of the component Parameter Handler .…

VulDB Read →
← Prev 282 / 381 Next →