CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5717 articles  ·  updated every 4 hours · grows forever

5717Total
4037Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41200 | NUWCDIVNPT stig-manager up to 1.6.7 src/init.js error/error_description cross site scripting (GHSA-wg33-j3rv-jq72)

A vulnerability labeled as problematic has been found in NUWCDIVNPT stig-manager up to 1.6.7 . Affected by this issue is some unknown functionality of the file src/init.js . Such manipulation of the a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41231 | Froxlor up to 2.3.5 Destination DataDump.add fixed_homedir link following (GHSA-75h4-c557-j89r)

A vulnerability marked as critical has been reported in Froxlor up to 2.3.5 . This affects the function DataDump.add of the component Destination Handler . Performing a manipulation of the argument fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-4917 | IBM Guardium Data Protection 12.1 URL path traversal

A vulnerability described as critical has been identified in IBM Guardium Data Protection 12.1 . This vulnerability affects unknown code of the component URL Handler . Executing a manipulation can lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-5926 | IBM Verify Identity Access Container up to 11.0.2 inadequate encryption

A vulnerability classified as problematic has been found in IBM Verify Identity Access Container, Security Verify Access Container, Verify Identity Access and Security Verify Access up to 11.0.2 . Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-5935 | IBM Total Storage Service Consol TS4500 IMC up to 9.6 os command injection

A vulnerability classified as critical was found in IBM Total Storage Service Consol TS4500 IMC 9.2/9.3/9.4/9.5/9.6 . Impacted is an unknown function. The manipulation results in os command injection.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-4918 | IBM Guardium Data Protection 12.1.0 Web UI cross site scripting

A vulnerability, which was classified as problematic , has been found in IBM Guardium Data Protection 12.1.0 . The affected element is an unknown function of the component Web UI . This manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-4919 | IBM Guardium Data Protection up to 26.0.0.4 Web UI cross site scripting

A vulnerability, which was classified as problematic , was found in IBM Guardium Data Protection up to 26.0.0.4 . The impacted element is an unknown function of the component Web UI . Such manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41230 | Froxlor up to 2.3.5 DomainZones::add crlf injection (GHSA-47hf-23pw-3m8c / WID-SEC-2026-1124)

A vulnerability has been found in Froxlor up to 2.3.5 and classified as problematic . This affects the function DomainZones::add . Performing a manipulation results in crlf injection. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41243 | siemvk OpenLearn access control (GHSA-4rv3-hfh6-vqvm)

A vulnerability was found in siemvk OpenLearn and classified as critical . This impacts an unknown function. Executing a manipulation can lead to improper access controls. The identification of this v…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41679 | paperclipai paperclip prior 2026.410.0 API Call improper authentication (GHSA-68qg-g8mg-6pr7)

A vulnerability was found in paperclipai paperclip . It has been classified as critical . Affected is an unknown function of the component API Call Handler . The manipulation leads to improper authent…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41211 | voidzero-dev vite-plus up to 0.1.16 downloadPackageManager path traversal (GHSA-33r3-4whc-44c2)

A vulnerability was found in voidzero-dev vite-plus up to 0.1.16 . It has been declared as critical . Affected by this vulnerability is the function downloadPackageManager . The manipulation results i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-40517 | radareorg radare2 up to 6.1.3 PDB Parser print_gvars os command injection (Bug 25730)

A vulnerability was found in radareorg radare2 up to 6.1.3 . It has been rated as critical . Affected by this issue is the function print_gvars of the component PDB Parser . This manipulation causes o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41233 | Froxlor up to 2.3.5 Domains.add adminid authorization

A vulnerability categorized as problematic has been discovered in Froxlor up to 2.3.5 . This affects the function Domains.add . Such manipulation of the argument adminid leads to incorrect authorizati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-3361 | tijmensmit WP Store Locator Plugin up to 2.2.261 on WordPress wpsl_address cross site scripting

A vulnerability identified as problematic has been detected in tijmensmit WP Store Locator Plugin up to 2.2.261 on WordPress. This vulnerability affects unknown code. Performing a manipulation of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41988 | uuidjs uuid up to 13.x control flow

A vulnerability labeled as problematic has been found in uuidjs uuid up to 13.x . This issue affects some unknown processing. Executing a manipulation can lead to incorrect control flow. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41172 | squidex up to 7.22.x server-side request forgery (GHSA-x7cq-4f4c-8qcv)

A vulnerability marked as critical has been reported in squidex up to 7.22.x . Impacted is an unknown function. The manipulation leads to server-side request forgery. This vulnerability is documented …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41175 | Statamic CMS up to 5.73.19/6.12.x REST API Endpoint externally-controlled input to select classes or code (GHSA-4jjr-vmv7-wh4w)

A vulnerability described as problematic has been identified in Statamic CMS up to 5.73.19/6.12.x . The affected element is an unknown function of the component REST API Endpoint . The manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-40529 | Kanata CMS ALAYA Administrative Interface sql injection

A vulnerability classified as critical has been found in Kanata CMS ALAYA . The impacted element is an unknown function of the component Administrative Interface . This manipulation causes sql injecti…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41232 | Froxlor up to 2.3.5 Email Address EmailSender::add authorization

A vulnerability classified as problematic was found in Froxlor up to 2.3.5 . This affects the function EmailSender::add of the component Email Address Handler . Such manipulation leads to incorrect au…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41177 | squidex up to 7.22.x Restore API Url file inclusion (GHSA-45fq-w37p-qfw5)

A vulnerability, which was classified as problematic , has been found in squidex up to 7.22.x . This impacts an unknown function of the component Restore API . Performing a manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-29198 | Rocket.Chat up to 8.2.x sql injection

A vulnerability, which was classified as critical , was found in Rocket.Chat up to 8.2.x . Affected is an unknown function. Executing a manipulation can lead to sql injection. This vulnerability is ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-3007 | Three Learning Koollab Learning Management System 5.3.2. cross site scripting

A vulnerability has been found in Three Learning Koollab Learning Management System 5.3.2. and classified as problematic . Affected by this vulnerability is an unknown functionality. The manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41989 | gnupg Libgcrypt up to 1.10.3/1.11.2/1.12.1 ECDH gcry_pk_decrypt out-of-bounds write

A vulnerability was found in gnupg Libgcrypt up to 1.10.3/1.11.2/1.12.1 and classified as critical . Affected by this issue is the function gcry_pk_decrypt of the component ECDH Handler . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 23, 2026
CVE-2026-41990 | gnupg Libgcrypt up to 1.12.1 out-of-bounds write

A vulnerability was found in gnupg Libgcrypt up to 1.12.1 . It has been classified as critical . This affects an unknown part. This manipulation causes out-of-bounds write. The identification of this …

VulDB Read →
← Prev 56 / 239 Next →