CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5713 articles  ·  updated every 4 hours · grows forever

5713Total
4036Full Text
May 17, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6981 | IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e Endpoint AiraHub.py connect_stream_endpoint/sync_agents server-side request forgery

A vulnerability has been found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e and classified as critical . Affected is the function connect_stream_endpoint/sync_age…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6982 | star7th ShowDoc up to 2.10.10/3.6.2/3.8.0 API Page Sort Endpoint PageController.class.PHP pages sql injection

A vulnerability was found in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0 and classified as critical . Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Contro…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6983 | pagekit up to 1.0.18 download url server-side request forgery

A vulnerability was found in pagekit up to 1.0.18 . It has been classified as critical . Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6984 | AstrBotDevs AstrBot up to 4.22.1 Dashboard API t2i.py create_template special elements used in a template engine (Issue 7330)

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1 . It has been declared as critical . This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6985 | Cesanta Mongoose up to 7.20 TCP Option /src/net_builtin.c handle_opt optlen infinite loop

A vulnerability was found in Cesanta Mongoose up to 7.20 . It has been rated as problematic . This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Opt…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6986 | Cesanta Mongoose up to 7.20 GCM Authentication Tag /src/tls_aes128.c mg_aes_gcm_decrypt signature verification

A vulnerability categorized as problematic has been discovered in Cesanta Mongoose up to 7.20 . This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Au…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6987 | PicoClaw up to 0.2.4 Web Launcher Management Plane /api/gateway/restart command injection (Issue 2307)

A vulnerability identified as critical has been detected in PicoClaw up to 0.2.4 . Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane . Per…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41894 | SiYuan up to 3.6.4 url.PathUnescape path traversal

A vulnerability labeled as critical has been found in SiYuan up to 3.6.4 . The affected element is the function url.PathUnescape . Executing a manipulation can lead to path traversal. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41327 | dgraph-io dgraph up to 25.3.2 DQL Parser /mutate?commitNow=true cond data query logic injection

A vulnerability marked as critical has been reported in dgraph-io dgraph up to 25.3.2 . The impacted element is an unknown function of the file /mutate?commitNow=true of the component DQL Parser . The…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41326 | kata-containers Kata Containers up to 3.28.x CopyFile symlink (GHSA-q49m-57vm-c8cc)

A vulnerability described as critical has been identified in kata-containers Kata Containers up to 3.28.x . This affects an unknown function of the component CopyFile Handler . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41418 | RARgames 4gaBoards up to 3.3.4 Login Endpoint /api/access-tokens bcrypt.compareSync timing discrepancy (GHSA-8mj9-p99h-jhxp)

A vulnerability classified as problematic has been found in RARgames 4gaBoards up to 3.3.4 . This impacts the function bcrypt.compareSync of the file /api/access-tokens of the component Login Endpoint…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41414 | skim-rs skim github/workflows/pr.yml code injection (GHSA-9g93-rxr5-xhqw)

A vulnerability classified as critical was found in skim-rs skim . Affected is an unknown function of the file github/workflows/pr.yml . Such manipulation leads to code injection. This vulnerability i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41415 | pjsip pjproject up to 2.16 Multipart Message out-of-bounds (GHSA-935m-fmf5-j4pm)

A vulnerability, which was classified as problematic , has been found in pjsip pjproject up to 2.16 . Affected by this vulnerability is an unknown functionality of the component Multipart Message Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41416 | pjsip pjproject up to 2.16 integer overflow (GHSA-f33g-8hjq-62xr)

A vulnerability, which was classified as critical , was found in pjsip pjproject up to 2.16 . Affected by this issue is some unknown functionality. Executing a manipulation can lead to integer overflo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41421 | SiYuan up to 3.6.4 Notification Message pushMsg msg os command injection (GHSA-grjj-6f6g-cq8q)

A vulnerability has been found in SiYuan up to 3.6.4 and classified as critical . This affects an unknown part of the file /api/notification/pushMsg of the component Notification Message Handler . The…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41419 | RARgames 4gaBoards up to 3.3.4 Application Interface path traversal (GHSA-rrjq-7x8g-cmgm)

A vulnerability was found in RARgames 4gaBoards up to 3.3.4 and classified as critical . This vulnerability affects unknown code of the component Application Interface . The manipulation results in pa…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6988 | Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon Boa Service /boaform/formRouting formRoute nextHop buffer overflow

A vulnerability was found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon . It has been classified as critical . This issue affects the function formRoute of the file /boaform/formRouting of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6989 | Tenda F453 up to 1.0.0.3 Telnet Service /goform/telnet TendaTelnet command injection

A vulnerability was found in Tenda F453 up to 1.0.0.3 . It has been declared as critical . Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service . Such manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6990 | projeto-siga 11.0.3.18 novo Nome/Descrição cross site scripting (Issue 2491)

A vulnerability was found in projeto-siga siga 11.0.3.18 . It has been rated as problematic . The affected element is an unknown function of the file /sigawf/app/responsavel/novo . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6991 | colinhacks Zod up to 4.3.6 CUID Data Type regexes.ts sql injection

A vulnerability categorized as critical has been discovered in colinhacks Zod up to 4.3.6 . The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6992 | Linksys MR9600 2.0.6.206937 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus pin os command injection

A vulnerability identified as critical has been detected in Linksys MR9600 2.0.6.206937 . This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6993 | go-kratos up to 2.9.2 http.DefaultServeMux Fallback transport/http/server.go NewServer confused deputy (Issue 3810)

A vulnerability labeled as problematic has been found in go-kratos kratos up to 2.9.2 . This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux F…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6994 | Envoy up to 1.33.0 Query Parameter header_mutation.cc params.add injection (ID 43502)

A vulnerability marked as critical has been reported in Envoy up to 1.33.0 . Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41425 | Authlib up to 1.6.10 authlib.integrations.starlette_client.OAuth cross-site request forgery

A vulnerability described as problematic has been identified in Authlib up to 1.6.10 . Affected by this vulnerability is the function authlib.integrations.starlette_client.OAuth . Such manipulation le…

VulDB Read →
← Prev 48 / 239 Next →