CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5713 articles  ·  updated every 4 hours · grows forever

5713Total
4036Full Text
May 17, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7158 | dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6 server.py _validate_url_safe url server-side request forgery

A vulnerability described as critical has been identified in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6 . Affected by this issue is the function _validate_url_safe of…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7159 | douinc mkdocs-mcp-plugin up to 0.4.1 server.py read_document/list_documents docs_dir/file_path path traversal

A vulnerability classified as critical has been found in douinc mkdocs-mcp-plugin up to 0.4.1 . This affects the function read_document/list_documents of the file server.py . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7160 | Tenda HG3 2.0 /boaform/formTracert datasize command injection

A vulnerability classified as critical was found in Tenda HG3 2.0 . This vulnerability affects the function formTracert of the file /boaform/formTracert . Executing a manipulation of the argument data…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-3868 | Moxa EDR-8010/EDR-G9010 up to 3.23 HTTPS Management Interface length parameter

A vulnerability, which was classified as critical , has been found in Moxa EDR-8010 and EDR-G9010 up to 3.23 . This issue affects some unknown processing of the component HTTPS Management Interface . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-7106 | jgrodgers Highland Software Custom Role Manager Plugin up to 1.0.0 on WordPress Profile Page hscrm_save_user_roles privileges management

A vulnerability, which was classified as critical , was found in jgrodgers Highland Software Custom Role Manager Plugin up to 1.0.0 on WordPress. Impacted is the function hscrm_save_user_roles of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-42363 | GeoVision GV-IP Device Utility 9.0.5.0 Broadcast Message reliance on security through obscurity

A vulnerability has been found in GeoVision GV-IP Device Utility 9.0.5.0 and classified as critical . The affected element is an unknown function of the component Broadcast Message Handler . This mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-3867 | Moxa EDR-8010/EDR-G9010 up to 3.23 Configuration File improper ownership management

A vulnerability was found in Moxa EDR-8010 and EDR-G9010 up to 3.23 and classified as problematic . The impacted element is an unknown function of the component Configuration File Handler . Such manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-3006 | WinFSP up to 2.1.25156 Kernel heap-based overflow

A vulnerability was found in WinFSP up to 2.1.25156 . It has been classified as critical . This affects an unknown function of the component Kernel . Performing a manipulation results in heap-based bu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-33277 | JPCERT LogonTracer up to 1.x os command injection

A vulnerability was found in JPCERT LogonTracer up to 1.x . It has been declared as critical . This impacts an unknown function. Executing a manipulation can lead to os command injection. The identifi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-33566 | JPCERT LogonTracer up to 1.x Windows Event data query logic injection

A vulnerability was found in JPCERT LogonTracer up to 1.x . It has been rated as problematic . Affected is an unknown function of the component Windows Event Handler . The manipulation leads to improp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-27172 | Apache Camel up to 4.14.5/4.18.0 camel-consul ConsulRegistry malicious deserialization

A vulnerability categorized as critical has been discovered in Apache Camel up to 4.14.5/4.18.0 . Affected by this vulnerability is an unknown functionality of the component camel-consul ConsulRegistr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-33453 | Apache Camel up to 4.14.4/4.18.0 CoAP URI Query Parameter injection

A vulnerability identified as critical has been detected in Apache Camel up to 4.14.4/4.18.0 . Affected by this issue is some unknown functionality of the component CoAP URI Query Parameter Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-33454 | Apache Camel up to 4.14.5/4.18.0 Inbound Header Filter injection

A vulnerability labeled as critical has been found in Apache Camel up to 4.14.5/4.18.0 . This affects an unknown part of the component Inbound Header Filter . Such manipulation leads to injection. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-40022 | Apache Camel up to 4.14.5/4.18.1 Camel-Platform-HTTP-Main improper authentication

A vulnerability marked as critical has been reported in Apache Camel up to 4.14.5/4.18.1 . This vulnerability affects unknown code of the component Camel-Platform-HTTP-Main . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-40048 | Apache Camel up to 4.18.1/4.19.x Camel-PQC deserialization

A vulnerability described as critical has been identified in Apache Camel up to 4.18.1/4.19.x . This issue affects some unknown processing of the component Camel-PQC . Executing a manipulation can lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-40453 | Apache Camel up to 4.14.5/4.18.1/4.19.x Incomplete Fix CVE-2025-27636 injection

A vulnerability classified as critical has been found in Apache Camel up to 4.14.5/4.18.1/4.19.x . Impacted is an unknown function of the component Incomplete Fix CVE-2025-27636 . The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-40473 | Apache Camel up to 4.14.5/4.18.1/4.19.x Camel-Mina MinaConverter.toObjectInput deserialization

A vulnerability classified as critical was found in Apache Camel up to 4.14.5/4.18.1/4.19.x . The affected element is the function MinaConverter.toObjectInput of the component Camel-Mina . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-40858 | Apache Camel up to 4.14.6/4.18.1/4.19.x Camel-Infinispan deserialization

A vulnerability, which was classified as critical , has been found in Apache Camel up to 4.14.6/4.18.1/4.19.x . The impacted element is an unknown function of the component Camel-Infinispan . This man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-40860 | Apache Camel up to 4.14.6/4.18.1/4.19.x camel-jms deserialization

A vulnerability, which was classified as critical , was found in Apache Camel up to 4.14.6/4.18.1/4.19.x . This affects an unknown function of the component camel-jms . Such manipulation leads to dese…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-22077 | OPPO Wallet App Trusted Domain access control

A vulnerability has been found in OPPO Wallet App and classified as critical . This impacts an unknown function of the component Trusted Domain Handler . Performing a manipulation results in improper …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-3008 | Notepad++ 8.9.3 injection (Alert 17960)

A vulnerability was found in Notepad++ 8.9.3 and classified as critical . Affected is an unknown function. Executing a manipulation can lead to injection. This vulnerability is handled as CVE-2026-300…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
CVE-2026-42371 | uriparser up to 1.0.0 URI numeric truncation error

A vulnerability was found in uriparser up to 1.0.0 . It has been classified as problematic . Affected by this vulnerability is an unknown functionality of the component URI Handler . The manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
Critical Vulnerability Exposes Linux Systems To Root-Level Takeover - LinkedIn

Critical Vulnerability Exposes Linux Systems To Root-Level Takeover LinkedIn

LinkedIn Read →
⬡ Vulnerabilities & CVEs Apr 27, 2026
Dell 0-Day Vulnerability Exploited by Chinese Hackers Since mid-2024 to Deploy Malware - CyberSecurityNews

Dell 0-Day Vulnerability Exploited by Chinese Hackers Since mid-2024 to Deploy Malware CyberSecurityNews

CyberSecurityNews Read →
← Prev 45 / 239 Next →