CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5717 articles  ·  updated every 4 hours · grows forever

5717Total
4037Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41271 | FlowiseAI Flowise/flowise-components up to 3.0.x API Chain server-side request forgery (GHSA-6r77-hqx7-7vw8 / EUVD-2026-25288)

A vulnerability classified as critical has been found in FlowiseAI Flowise and flowise-components up to 3.0.x . The affected element is an unknown function of the component API Chain Component . Perfo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41272 | FlowiseAI Flowise/flowise-components up to 3.0.x secureAxiosRequest/secureFetch server-side request forgery (GHSA-2x8m-83vc-6wv4 / EUVD-2026-25289)

A vulnerability classified as critical was found in FlowiseAI Flowise and flowise-components up to 3.0.x . The impacted element is an unknown function of the component secureAxiosRequest/secureFetch .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41264 | FlowiseAI Flowise up to 3.0.x CSV_Agents incomplete blacklist (GHSA-3hjv-c53m-58jj)

A vulnerability, which was classified as critical , has been found in FlowiseAI Flowise up to 3.0.x . This affects the function CSV_Agents . The manipulation leads to incomplete blacklist. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41265 | FlowiseAI Flowise up to 3.0.x Airtable_Agents command injection (GHSA-v38x-c887-992f)

A vulnerability, which was classified as critical , was found in FlowiseAI Flowise up to 3.0.x . This impacts the function Airtable_Agents . The manipulation results in command injection. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41276 | FlowiseAI Flowise up to 3.0.x Password Reset Token reset-password resetPassword improper authentication (GHSA-f6hc-c5jr-878p)

A vulnerability has been found in FlowiseAI Flowise up to 3.0.x and classified as critical . Affected is the function resetPassword of the file /api/v1/account/reset-password of the component Password…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41275 | FlowiseAI Flowise up to 3.0.x cleartext transmission (GHSA-x5w6-38gp-mrqh / EUVD-2026-25291)

A vulnerability was found in FlowiseAI Flowise up to 3.0.x and classified as problematic . Affected by this vulnerability is an unknown functionality. Such manipulation leads to cleartext transmission…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6941 | radareorg radare2 up to 6.1.3 zrp Archive link following

A vulnerability was found in radareorg radare2 up to 6.1.3 . It has been classified as critical . Affected by this issue is some unknown functionality of the component zrp Archive Handler . Performing…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-25874 | Hugging Face LeRobot up to 0.5.1 Pickle pickle.loads deserialization (ID 3047)

A vulnerability was found in Hugging Face LeRobot up to 0.5.1 . It has been declared as critical . This affects the function pickle.loads of the component Pickle Handler . Executing a manipulation can…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41277 | FlowiseAI Flowise up to 3.0.x DocumentStore Creation Endpoint repository.save access control (GHSA-3prp-9gf7-4rxx)

A vulnerability was found in FlowiseAI Flowise up to 3.0.x . It has been rated as critical . This vulnerability affects the function repository.save of the component DocumentStore Creation Endpoint . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6376 | SpiceJet Online Booking System missing authentication (icsa-26-113-04 / EUVD-2026-25300)

A vulnerability categorized as critical has been discovered in SpiceJet Online Booking System . This issue affects some unknown processing. The manipulation results in missing authentication. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41278 | FlowiseAI Flowise up to 3.0.x :id sanitizeFlowDataForPublicEndpoint information disclosure (GHSA-w47f-j8rh-wx87)

A vulnerability identified as problematic has been detected in FlowiseAI Flowise up to 3.0.x . Impacted is the function sanitizeFlowDataForPublicEndpoint of the file /api/v1/public-chatflows/:id . Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41279 | FlowiseAI Flowise up to 3.0.x generate authorization (GHSA-5fw2-mwhh-9947)

A vulnerability labeled as problematic has been found in FlowiseAI Flowise up to 3.0.x . The affected element is an unknown function of the file /api/v1/text-to-speech/generate . Such manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6375 | SpiceJet Online Booking System authorization (icsa-26-113-04)

A vulnerability marked as problematic has been reported in SpiceJet Online Booking System . The impacted element is an unknown function. Performing a manipulation results in authorization bypass. This…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6940 | radareorg radare2 up to 6.1.3 path traversal

A vulnerability described as critical has been identified in radareorg radare2 up to 6.1.3 . This affects an unknown function. Executing a manipulation can lead to path traversal. The identification o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-28525 | sbabic swupdate up to 2025.12 mongoose_multipart.c mg_http_multipart_continue_wait_for_chunk integer underflow

A vulnerability classified as problematic has been found in sbabic swupdate up to 2025.12 . This impacts the function mg_http_multipart_continue_wait_for_chunk of the file mongoose_multipart.c . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6942 | radareorg radare2 up to 1.5.x Jsonrpc Interface r2_cmd_str os command injection (Issue 45)

A vulnerability classified as critical was found in radareorg radare2 up to 1.5.x . Affected is the function r2_cmd_str of the component Jsonrpc Interface . The manipulation results in os command inje…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2025-62373 | pipecat-ai pipecat up to 0.0.93 Pickle livekit.py deserialize deserialization (EUVD-2025-209570)

A vulnerability was found in pipecat-ai pipecat up to 0.0.93 and classified as critical . The impacted element is the function deserialize of the file src/pipecat/serializers/livekit.py of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-23751 | Tungsten Automation Kofax Capture 6.0.0.0 Ascent Capture Service missing authentication (EUVD-2026-25228)

A vulnerability was found in Tungsten Automation Kofax Capture 6.0.0.0 . It has been classified as critical . This affects an unknown function of the component Ascent Capture Service . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-34001 | X.org X Server miSyncTriggerFence expired pointer dereference (EUVD-2026-25230)

A vulnerability was found in X.org X Server . It has been declared as critical . This impacts the function miSyncTriggerFence . The manipulation results in expired pointer dereference. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-33999 | X.org X Server XKB Compatibility Map integer underflow (EUVD-2026-25229)

A vulnerability was found in X.org X Server . It has been rated as critical . Affected is an unknown function of the component XKB Compatibility Map Handler . This manipulation causes integer underflo…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-34003 | X.org X Server XKB Key Types Request out-of-bounds (EUVD-2026-25231)

A vulnerability categorized as critical has been discovered in X.org X Server . Affected by this vulnerability is an unknown functionality of the component XKB Key Types Request Handler . Such manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-40470 | hackage-server/hackage.haskell.org up to 0.5 cross site scripting (HSEC-2024-0004 / EUVD-2026-25233)

A vulnerability identified as problematic has been detected in hackage-server and hackage.haskell.org up to 0.5 . Affected by this issue is some unknown functionality. Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41240 | cure53 DOMPurify up to 3.3.x permissive list of allowed inputs

A vulnerability labeled as problematic has been found in cure53 DOMPurify up to 3.3.x . This affects an unknown part. Executing a manipulation can lead to permissive list of allowed inputs. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-39087 | Via Code up to 2.20 ntfy.sh parseActions privilege escalation (EUVD-2026-25232)

A vulnerability marked as critical has been reported in Via Code up to 2.20 . This vulnerability affects the function parseActions of the file ntfy.sh . The manipulation leads to privilege escalation.…

VulDB Read →
← Prev 53 / 239 Next →