CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5717 articles  ·  updated every 4 hours · grows forever

5717Total
4037Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-40471 | hackage-server cross-site request forgery (HSEC-2026-0002 / EUVD-2026-25234)

A vulnerability described as problematic has been identified in hackage-server . This issue affects some unknown processing. The manipulation results in cross-site request forgery. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41239 | cure53 DOMPurify up to 3.3.x cross site scripting

A vulnerability classified as problematic has been found in cure53 DOMPurify up to 3.3.x . Impacted is an unknown function. This manipulation causes cross site scripting. This vulnerability is registe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2025-50229 | Jizhicms 2.5.4 Product Editing sql injection (EUVD-2025-209568)

A vulnerability classified as critical was found in Jizhicms 2.5.4 . The affected element is an unknown function of the component Product Editing Module . Such manipulation leads to sql injection. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-40472 | hackage-server cabal File cross site scripting (HSEC-2026-0004 / EUVD-2026-25235)

A vulnerability, which was classified as problematic , has been found in hackage-server . The impacted element is an unknown function of the component cabal File Handler . Performing a manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-6920 | Google Chrome up to 147.0.7727.101 on Android GPU out-of-bounds

A vulnerability, which was classified as critical , was found in Google Chrome on Android. This affects an unknown function of the component GPU . Executing a manipulation can lead to out-of-bounds re…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31159 | Totolink A3300R 17.0.0cu.557_B20221024 Parameter /cgi-bin/cstecgi.cgi Password command injection

A vulnerability has been found in Totolink A3300R 17.0.0cu.557_B20221024 and classified as critical . This impacts an unknown function of the file /cgi-bin/cstecgi.cgi of the component Parameter Handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31177 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi stunMinAlive privilege escalation

A vulnerability was found in Totolink A3300R 17.0.0cu.557_B20221024 and classified as critical . Affected is an unknown function of the file /cgi-bin/cstecgi.cgi . The manipulation of the argument stu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31533 | Linux Kernel up to 6.19.12 tls tls_do_encryption use after free

A vulnerability was found in Linux Kernel up to 6.19.12 . It has been classified as critical . Affected by this vulnerability is the function tls_do_encryption of the component tls . This manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-5039 | TP-Link TL-WL841N v13 TDDPv2 Debug default key

A vulnerability was found in TP-Link TL-WL841N v13 . It has been declared as problematic . Affected by this issue is some unknown functionality of the component TDDPv2 Debug Handler . Such manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31181 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi stunServerAddr command injection

A vulnerability was found in Totolink A3300R 17.0.0cu.557_B20221024 . It has been rated as critical . This affects an unknown part of the file /cgi-bin/cstecgi.cgi . Performing a manipulation of the a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31179 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi stun-port os command injection

A vulnerability categorized as critical has been discovered in Totolink A3300R 17.0.0cu.557_B20221024 . This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi . Executing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-6919 | Google Chrome up to 147.0.7727.101 DevTools use after free

A vulnerability identified as critical has been detected in Google Chrome . This issue affects some unknown processing of the component DevTools . The manipulation leads to use after free. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31176 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi stun-user command injection

A vulnerability labeled as critical has been found in Totolink A3300R 17.0.0cu.557_B20221024 . Impacted is an unknown function of the file /cgi-bin/cstecgi.cgi . The manipulation of the argument stun-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31178 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi stunMaxAlive command injection

A vulnerability marked as critical has been reported in Totolink A3300R 17.0.0cu.557_B20221024 . The affected element is an unknown function of the file /cgi-bin/cstecgi.cgi . This manipulation of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-6921 | Google Chrome up to 147.0.7727.101 on Windows GPU race condition

A vulnerability described as problematic has been identified in Google Chrome on Windows. The impacted element is an unknown function of the component GPU . Such manipulation leads to race condition. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31160 | Totolink A3300R 17.0.0cu.557 /cgi-bin/cstecgi.cgi provider command injection

A vulnerability classified as critical has been found in Totolink A3300R 17.0.0cu.557 . This affects an unknown function of the file /cgi-bin/cstecgi.cgi . Performing a manipulation of the argument pr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31165 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi pppoeServiceName command injection

A vulnerability classified as critical was found in Totolink A3300R 17.0.0cu.557_B20221024 . This impacts an unknown function of the file /cgi-bin/cstecgi.cgi . Executing a manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-31164 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi pppoeMtu command injection

A vulnerability, which was classified as critical , has been found in Totolink A3300R 17.0.0cu.557_B20221024 . Affected is an unknown function of the file /cgi-bin/cstecgi.cgi . The manipulation of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-22020 | libpng privilege escalation

A vulnerability, which was classified as problematic , was found in libpng . Affected by this vulnerability is an unknown functionality. The manipulation results in privilege escalation. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-40466 | Apache ActiveMQ up to 5.19.5/6.2.4

A vulnerability has been found in Apache ActiveMQ up to 5.19.5/6.2.4 and classified as problematic . Affected by this issue is some unknown functionality. This manipulation causes an unknown weakness.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41043 | Apache ActiveMQ up to 5.19.5/6.2.4 cross site scripting

A vulnerability was found in Apache ActiveMQ up to 5.19.5/6.2.4 and classified as problematic . This affects an unknown part. Such manipulation leads to cross site scripting. This vulnerability is tra…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41044 | Jolokia ActiveMQ up to 5.19.5/6.2.4 DestinationView MBean privilege escalation

A vulnerability was found in Jolokia ActiveMQ up to 5.19.5/6.2.4 . It has been classified as problematic . This vulnerability affects unknown code of the component DestinationView MBean . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CISA Warns of FIRESTARTER Malware Targeting Cisco ASA including Firepower and Secure Firewall Products
CISA Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-3960 | h2oai h2o-3 up to 3.46.0.9/3.46.0.10 REST API Endpoint /99/ImportSQLTable jdbc:postgresql code injection

A vulnerability classified as critical has been found in h2oai h2o-3 up to 3.46.0.9/3.46.0.10 . Affected is the function jdbc:postgresql of the file /99/ImportSQLTable of the component REST API Endpoi…

VulDB Read →
← Prev 54 / 239 Next →