CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5768 articles  ·  updated every 4 hours · grows forever

5768Total
4039Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40450 | Samsung Open Source ONE up to 1.29.x integer overflow

A vulnerability was found in Samsung Open Source ONE up to 1.29.x . It has been rated as problematic . The affected element is an unknown function. This manipulation causes integer overflow. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-41665 | Samsung Open Source ONE up to 1.29.x integer overflow

A vulnerability categorized as problematic has been discovered in Samsung Open Source ONE up to 1.29.x . The impacted element is an unknown function. Such manipulation leads to integer overflow. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-41666 | Samsung Open Source ONE up to 1.29.x integer overflow

A vulnerability identified as problematic has been detected in Samsung Open Source ONE up to 1.29.x . This affects an unknown function. Performing a manipulation results in integer overflow. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-41667 | Samsung Open Source ONE up to 1.29.x integer overflow

A vulnerability labeled as problematic has been found in Samsung Open Source ONE up to 1.29.x . This impacts an unknown function. Executing a manipulation can lead to integer overflow. The identificat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-6839 | Samsung Open Source ONE up to 1.29.x improper validation of specified quantity in input

A vulnerability marked as problematic has been reported in Samsung Open Source ONE up to 1.29.x . Affected is an unknown function. The manipulation leads to improper validation of specified quantity i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-22754 | Vmware Spring Security up to 7.0.4 Authorization Rule authorization

A vulnerability described as problematic has been identified in Vmware Spring Security up to 7.0.4 . Affected by this vulnerability is an unknown functionality of the component Authorization Rule Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-22746 | Vmware Spring Security up to 7.0.4 DaoAuthenticationProvider UserDetails information disclosure

A vulnerability classified as problematic has been found in Vmware Spring Security up to 7.0.4 . Affected by this issue is some unknown functionality of the component DaoAuthenticationProvider . This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-22747 | Vmware Spring Security up to 7.0.4 x.509 Certificate certificate validation

A vulnerability classified as critical was found in Vmware Spring Security up to 7.0.4 . This affects an unknown part of the component x.509 Certificate Handler . Such manipulation leads to improper c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-22748 | Vmware Spring Security up to 6.3.14/6.4.14/6.5.9/7.0.4 JWT Decoding NimbusJwtDecoder/NimbusReactiveJwtDecoder

A vulnerability, which was classified as problematic , has been found in Vmware Spring Security up to 6.3.14/6.4.14/6.5.9/7.0.4 . This vulnerability affects the function NimbusJwtDecoder/NimbusReactiv…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-6840 | Samsung Open Source ONE up to 1.29.x Model Loading array index

A vulnerability, which was classified as problematic , was found in Samsung Open Source ONE up to 1.29.x . This issue affects some unknown processing of the component Model Loading . Executing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
Amazon AWS-LC Vulnerability Allows Attackers to Bypass Certificate Chain Verification - cyberpress.org

Amazon AWS-LC Vulnerability Allows Attackers to Bypass Certificate Chain Verification cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40889 | frappe hrms up to 15.58.1/16.4.1 API Endpoint access control (GHSA-6cg5-4q6m-vrgm)

A vulnerability classified as critical has been found in frappe hrms up to 15.58.1/16.4.1 . Affected by this vulnerability is an unknown functionality of the component API Endpoint . This manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40876 | patrickhener goshs up to 2.0.0-beta.5 sftpserver/sftpserver.go DefaultHandler.GetHandler path traversal (GHSA-5h6h-7rc9-3824)

A vulnerability classified as critical was found in patrickhener goshs up to 2.0.0-beta.5 . Affected by this issue is the function DefaultHandler.GetHandler of the file sftpserver/sftpserver.go . Such…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40890 | gomarkdown out-of-bounds (GHSA-77fj-vx54-gvh7)

A vulnerability, which was classified as problematic , has been found in gomarkdown markdown . This affects an unknown part. Performing a manipulation results in out-of-bounds read. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40885 | patrickhener goshs 2.0.0-beta.4/2.0.0-beta.5 Request Header information disclosure (GHSA-7h3j-592v-jcrp)

A vulnerability, which was classified as problematic , was found in patrickhener goshs 2.0.0-beta.4/2.0.0-beta.5 . This vulnerability affects unknown code of the component Request Header Handler . Exe…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40903 | patrickhener goshs up to 2.0.0-beta.5 GITHUB_TOKEN inclusion of functionality from untrusted control sphere

A vulnerability has been found in patrickhener goshs up to 2.0.0-beta.5 and classified as critical . This issue affects some unknown processing. The manipulation of the argument GITHUB_TOKEN leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40884 | patrickhener goshs up to 2.0.0-beta.5 SFTP Service missing authentication (GHSA-c29w-qq4m-2gcv)

A vulnerability was found in patrickhener goshs up to 2.0.0-beta.5 and classified as critical . Impacted is an unknown function of the component SFTP Service . The manipulation results in missing auth…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40883 | patrickhener goshs 2.0.0-beta.4/2.0.0-beta.5 cross-site request forgery (GHSA-jrq5-hg6x-j6g3)

A vulnerability was found in patrickhener goshs 2.0.0-beta.4/2.0.0-beta.5 . It has been classified as problematic . The affected element is an unknown function. This manipulation causes cross-site req…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40925 | WWBN AVideo up to 29.0 configurationUpdate.json.php User::isAdmin cross-site request forgery (EUVD-2026-24485)

A vulnerability was found in WWBN AVideo up to 29.0 . It has been declared as problematic . The impacted element is the function User::isAdmin of the file objects/configurationUpdate.json.php . Such m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40906 | electric-sql electric up to 1.4.x ORDER /v1/shape order_by sql injection

A vulnerability was found in electric-sql electric up to 1.4.x . It has been rated as critical . This affects an unknown function of the file /v1/shape of the component ORDER Handler . Performing a ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-41320 | Frappe hrms up to 14.38.0/15.53.x Request sql injection (GHSA-745c-5q8r-vgj2)

A vulnerability categorized as critical has been discovered in Frappe hrms up to 14.38.0/15.53.x . This impacts an unknown function of the component Request Handler . Executing a manipulation can lead…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40870 | decidim up to 0.30.4/0.31.0 Setting /api Decidim::Apiauth commentable authorization (GHSA-ghmh-q25g-gxxx)

A vulnerability identified as problematic has been detected in decidim up to 0.30.4/0.31.0 . Affected is the function Decidim::Apiauth of the file /api of the component Setting Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40872 | mailcow mailcow-dockerized prior 2026-03b EMailAddress cross site scripting (GHSA-f9xf-vc72-rcgm)

A vulnerability labeled as problematic has been found in mailcow mailcow-dockerized . Affected by this vulnerability is an unknown functionality. The manipulation of the argument EMailAddress results …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40905 | Kovah LinkAce up to 2.5.3 redirect (EUVD-2026-24473)

A vulnerability marked as problematic has been reported in Kovah LinkAce up to 2.5.3 . Affected by this issue is some unknown functionality. This manipulation causes open redirect. The identification …

VulDB Read →
← Prev 65 / 241 Next →