CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  9235 articles  ·  updated every 4 hours · grows forever

9235Total
4198Full Text
Jun 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5360 | Free5GC 4.2.0 aper type confusion (Issue 831)

A vulnerability, which was classified as problematic , was found in Free5GC 4.2.0 . The affected element is an unknown function of the component aper . Such manipulation leads to type confusion. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34236 | auth0 auth0-PHP up to 8.18.x entropy (GHSA-w3wc-44p4-m4j7)

A vulnerability has been found in auth0 auth0-PHP up to 8.18.x and classified as problematic . The impacted element is an unknown function. Performing a manipulation results in insufficient entropy. T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34397 | himmelblau-idm himmelblau up to 2.3.8/3.1.0 NSS Module privileges management (GHSA-v7xx-7mqc-g835)

A vulnerability was found in himmelblau-idm himmelblau up to 2.3.8/3.1.0 and classified as critical . This affects an unknown function of the component NSS Module . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34222 | open-webui Open WebUI up to 0.8.10 improper authorization (GHSA-7429-hxcv-268m)

A vulnerability was found in open-webui Open WebUI up to 0.8.10 . It has been classified as critical . This impacts an unknown function. The manipulation leads to improper authorization. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34445 | onnx up to 1.20.x Model setattr input validation (GHSA-538c-55jv-c5g9)

A vulnerability was found in onnx up to 1.20.x . It has been declared as critical . Affected is the function setattr of the component Model Handler . The manipulation results in improper input validat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34159 | ggml-org llama.cpp up to 55abc39/up to 55d4206c8/b7824 GRAPH_COMPUTE Message deserialize_tensor memory corruption (GHSA-j8rj-fmpv-wcxw)

A vulnerability was found in ggml-org llama.cpp up to 55abc39/up to 55d4206c8/b7824 . It has been rated as critical . Affected by this vulnerability is the function deserialize_tensor of the file llam…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-27489 | onnx up to 1.20.x path traversal (GHSA-3r9x-f23j-gc73)

A vulnerability categorized as problematic has been discovered in onnx up to 1.20.x . Affected by this issue is some unknown functionality. Such manipulation leads to relative path traversal. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34446 | onnx up to 1.20.x path traversal (GHSA-cmw6-hcpp-c6jp)

A vulnerability identified as critical has been detected in onnx up to 1.20.x . This affects an unknown part. Performing a manipulation results in path traversal. This vulnerability is identified as C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34447 | onnx up to 1.20.x symlink (GHSA-p433-9wv8-28xj)

A vulnerability labeled as critical has been found in onnx up to 1.20.x . This vulnerability affects unknown code. Executing a manipulation can lead to symlink following. This vulnerability is tracked…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5199 | temporal up to 1.29.4/1.30.2 authorization

A vulnerability marked as problematic has been reported in temporal up to 1.29.4/1.30.2 . This issue affects some unknown processing. The manipulation leads to authorization bypass. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34874 | mbed TLS up to 3.6.5/4.0.0 null pointer dereference

A vulnerability described as problematic has been identified in mbed TLS up to 3.6.5/4.0.0 . Impacted is an unknown function. The manipulation results in null pointer dereference. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5368 | projectworlds Car Rental Project 1.0 Parameter /login.php uname sql injection

A vulnerability classified as critical has been found in projectworlds Car Rental Project 1.0 . The affected element is an unknown function of the file /login.php of the component Parameter Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34376 | mrmn2 PdfDing up to 1.6.x authorization (GHSA-42x7-vvj4-4cj3)

A vulnerability classified as problematic was found in mrmn2 PdfDing up to 1.6.x . The impacted element is an unknown function. Such manipulation leads to incorrect authorization. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34072 | fccview cronmaster up to 2.1.x improper authentication (GHSA-9whh-mffv-xvh6)

A vulnerability, which was classified as critical , has been found in fccview cronmaster up to 2.1.x . This affects an unknown function. Performing a manipulation results in improper authentication. T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34751 | payloadcms payload up to 3.79.0 Password Reset external control of assumed-immutable web parameter (GHSA-hp5w-3hxx-vmwf)

A vulnerability, which was classified as critical , was found in payloadcms payload up to 3.79.0 . This impacts an unknown function of the component Password Reset Handler . Executing a manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-35000 | dgtlmoon changedetection.io up to 0.54.6 SafeXPath3Parser json-doc incomplete blacklist

A vulnerability has been found in dgtlmoon changedetection.io up to 0.54.6 and classified as critical . Affected is the function json-doc of the component SafeXPath3Parser . The manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34076 | clerk javascript clerkFrontendApiProxy server-side request forgery (GHSA-gjxx-92w9-8v8f)

A vulnerability was found in clerk javascript and classified as critical . Affected by this vulnerability is the function clerkFrontendApiProxy . The manipulation results in server-side request forger…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34875 | mbed TLS up to 1.0.0/3.6.5 FFDH Key Export buffer overflow

A vulnerability was found in mbed TLS up to 1.0.0/3.6.5 . It has been classified as critical . Affected by this issue is some unknown functionality of the component FFDH Key Export Handler . This mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-25835 | mbed TLS up to 3.6.5 entropy

A vulnerability was found in mbed TLS up to 3.6.5 . It has been declared as problematic . This affects an unknown part. Such manipulation leads to insufficient entropy in prng. This vulnerability is u…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-25834 | mbed TLS up to 3.6.5/4.0.0 downgrade

A vulnerability was found in mbed TLS up to 3.6.5/4.0.0 . It has been rated as problematic . This vulnerability affects unknown code. Performing a manipulation results in algorithm downgrade. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-25833 | mbed TLS up to 3.6.5 x509_inet_pton_ipv6 buffer overflow

A vulnerability categorized as critical has been discovered in mbed TLS up to 3.6.5 . This issue affects the function x509_inet_pton_ipv6 . Executing a manipulation can lead to buffer overflow. The id…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-5370 | krayin laravel-crm up to 2.2 Activities Module/Notes inbox.spec.ts composeMail cross site scripting (Issue 2419)

A vulnerability identified as problematic has been detected in krayin laravel-crm up to 2.2 . Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34872 | mbed TLS up to 3.6.5 FFDH entropy

A vulnerability labeled as problematic has been found in mbed TLS up to 3.6.5 . The affected element is an unknown function of the component FFDH Handler . The manipulation results in insufficient ent…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 01, 2026
CVE-2026-34871 | mbed TLS up to 3.6.5/4.0.x entropy

A vulnerability marked as problematic has been reported in mbed TLS up to 3.6.5/4.0.x . The impacted element is an unknown function. This manipulation causes insufficient entropy in prng. This vulnera…

VulDB Read →
← Prev 299 / 385 Next →