CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5713 articles  ·  updated every 4 hours · grows forever

5713Total
4036Full Text
May 17, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-41398 | OpenClaw up to 2026.4.1 origin validation (GHSA-4p4f-fc8q-84m3)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.4.1 . Affected by this issue is some unknown functionality. The manipulation leads to origin validation err…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-41911 | OpenClaw up to 2026.4.7 upload_file path traversal (GHSA-5fc7-f62m-8983)

A vulnerability, which was classified as critical , was found in OpenClaw up to 2026.4.7 . This affects the function upload_file . The manipulation results in path traversal. This vulnerability is cat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42424 | OpenClaw up to 2026.4.7 file inclusion (GHSA-qqq7-4hxc-x63c)

A vulnerability has been found in OpenClaw up to 2026.4.7 and classified as problematic . This vulnerability affects unknown code. This manipulation causes file inclusion. This vulnerability is regist…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42430 | OpenClaw up to 2026.4.7 server-side request forgery (GHSA-w8g9-x8gx-crmm / EUVD-2026-26132)

A vulnerability was found in OpenClaw up to 2026.4.7 and classified as critical . This issue affects some unknown processing. Such manipulation leads to server-side request forgery. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-42428 | OpenClaw up to 2026.4.7 integrity check (GHSA-3vvq-q2qc-7rmp / EUVD-2026-26130)

A vulnerability was found in OpenClaw up to 2026.4.7 . It has been classified as problematic . Impacted is an unknown function. Performing a manipulation results in missing support for integrity check…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 28, 2026
Microsoft’s March Security Update of High-Risk Vulnerability Notice for Multiple Products - Security Boulevard

Microsoft’s March Security Update of High-Risk Vulnerability Notice for Multiple Products Security Boulevard

Security Boulevard Read →
⬡ Vulnerabilities & CVEs Apr 28, 2026
Microsoft .NET 0-Day Flaw Opens Doors for Denial of Service Attacks - gbhackers.com

Microsoft .NET 0-Day Flaw Opens Doors for Denial of Service Attacks gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 28, 2026
Microsoft Defender 0-Day Vulnerability “RedSun” Enables Full SYSTEM Access - CyberSecurityNews

Microsoft Defender 0-Day Vulnerability “RedSun” Enables Full SYSTEM Access CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Apr 28, 2026
Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities - SecurityWeek

Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities SecurityWeek

SecurityWeek Read →
⬡ Vulnerabilities & CVEs Apr 28, 2026
Microsoft SharePoint Server 0-Day Vulnerability Actively Exploited in Attacks - CyberSecurityNews

Microsoft SharePoint Server 0-Day Vulnerability Actively Exploited in Attacks CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-40514 | SmarterTools SmarterMail up to 100.0.9609 Attachment Download Endpoint weak prng

A vulnerability identified as problematic has been detected in SmarterTools SmarterMail up to 100.0.9609 . Affected is an unknown function of the component Attachment Download Endpoint . This manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-6357 | pip up to 26.0 Self-update Check Local Privilege Escalation

A vulnerability labeled as problematic has been found in pip up to 26.0 . Affected by this vulnerability is an unknown functionality of the component Self-update Check . Such manipulation leads to Loc…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-32688 | elixir-plug plug_cowboy up to 2.8.0 lib/plug/cowboy/conn.ex allocation of resources (GHSA-q8x4-x7mp-5vg2)

A vulnerability marked as problematic has been reported in elixir-plug plug_cowboy up to 2.8.0 . Affected by this issue is some unknown functionality in the library lib/plug/cowboy/conn.ex . Performin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-30350 | aegra Agent Protocol Server /store/items/search denial of service

A vulnerability described as problematic has been identified in aegra . This affects an unknown part of the file /store/items/search of the component Agent Protocol Server . Executing a manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7214 | eghuzefa engineer-your-data up to 0.1.3 src/server.py read_file/write_file/list_files/file_inf WORKSPACE_PATH path traversal

A vulnerability classified as critical has been found in eghuzefa engineer-your-data up to 0.1.3 . This vulnerability affects the function read_file/write_file/list_files/file_inf of the file src/serv…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7215 | egtai gmx-vmd-mcp up to 0.1.0 VMD Launch mcp_server.py launch_vmd_gui_tool structure_file/trajectory_file command injection

A vulnerability classified as critical was found in egtai gmx-vmd-mcp up to 0.1.0 . This issue affects the function launch_vmd_gui_tool of the file mcp_server.py of the component VMD Launch Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7216 | donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd create_sketch Tool processing_server.py sketch_name path traversal

A vulnerability, which was classified as critical , has been found in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd . Impacted is an unknown function of the file…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7217 | Deepractice PromptX up to 2.4.0 Document File index.ts path absolute path traversal (Issue 571)

A vulnerability, which was classified as critical , was found in Deepractice PromptX up to 2.4.0 . The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the f…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7218 | Totolink N300RT 3.4.0-B20250430 libapmib.so /boafrm/formWsc is_cmd_string_valid localPin buffer overflow

A vulnerability has been found in Totolink N300RT 3.4.0-B20250430 and classified as critical . The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component lib…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7219 | Totolink N300RT 3.4.0-B20250430 /boafrm/formIpQoS entry_name buffer overflow

A vulnerability was found in Totolink N300RT 3.4.0-B20250430 and classified as critical . This affects an unknown function of the file /boafrm/formIpQoS . Executing a manipulation of the argument entr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7220 | jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620 fastly_cli Tool fastly-mcp.mjs command os command injection

A vulnerability was found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620 . It has been classified as critical . This impacts an unknown function of the file fastly-mcp.mjs o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7221 | TencentCloudBase CloudBase-MCP up to 2.17.0 open-url API Endpoint interactive-server.ts openUrl req.body.url server-side request forgery (Issue 509)

A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0 . It has been declared as critical . Affected is the function openUrl of the file mcp/src/interactive-server.ts of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7222 | code-projects Coaching Management System 1.0 Complaint Form Page complaint.php cross site scripting

A vulnerability was found in code-projects Coaching Management System 1.0 . It has been rated as problematic . Affected by this vulnerability is an unknown functionality of the file /cims/modules/stud…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7223 | BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63 AI Proxy Middleware aiProxyMiddleware.mts fetch baseurl server-side request forgery (Issue 142)

A vulnerability categorized as critical has been discovered in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63 . Affected by this issue is the function fetch of the file packages/core/src/http/aiP…

VulDB Read →
← Prev 43 / 239 Next →