CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5768 articles  ·  updated every 4 hours · grows forever

5768Total
4039Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40887 | vendurehq vendure up to 2.3.3/3.5.6/3.6.1 Vendure Shop API sql injection

A vulnerability described as critical has been identified in vendurehq vendure up to 2.3.3/3.5.6/3.6.1 . This affects an unknown part of the component Vendure Shop API . Such manipulation leads to sql…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40869 | Decidim up to 0.30.4/0.31.0 privileges assignment (GHSA-w5xj-99cg-rccm)

A vulnerability classified as problematic has been found in Decidim up to 0.30.4/0.31.0 . This vulnerability affects unknown code. Performing a manipulation results in incorrect privilege assignment. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40892 | pjsip pjproject up to 2.16 pjsip_auth_create_digest2 stack-based overflow

A vulnerability classified as critical was found in pjsip pjproject up to 2.16 . This issue affects the function pjsip_auth_create_digest2 . Executing a manipulation can lead to stack-based buffer ove…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40895 | follow-redirects up to 1.15.x information disclosure

A vulnerability, which was classified as problematic , has been found in follow-redirects up to 1.15.x . Impacted is an unknown function. The manipulation leads to information disclosure. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40871 | mailcow mailcow-dockerized prior 2026-03b API quarantine_category input validation (GHSA-r8fq-wrfm-cj2q)

A vulnerability, which was classified as problematic , was found in mailcow mailcow-dockerized . The affected element is an unknown function of the component API . The manipulation of the argument qua…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40878 | mailcow mailcow-dockerized prior 2026-03b Web Interface setLang REQUEST_URI cross site scripting (GHSA-xv9r-j862-5hqf)

A vulnerability has been found in mailcow mailcow-dockerized and classified as problematic . The impacted element is the function setLang of the component Web Interface . This manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40873 | mailcow mailcow-dockerized prior 2026-03b Attachment cross site scripting (GHSA-2xjc-rg88-jvpp)

A vulnerability was found in mailcow mailcow-dockerized and classified as problematic . This affects an unknown function of the component Attachment Handler . Such manipulation leads to cross site scr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40910 | fatedier frp up to 0.68.0 Authorization Header improper authentication

A vulnerability was found in fatedier frp up to 0.68.0 . It has been classified as critical . This impacts an unknown function of the component Authorization Header Handler . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40874 | mailcow mailcow-dockerized prior 2026-03b Mail Service access control (GHSA-jjxh-rm7p-hjc3)

A vulnerability was found in mailcow mailcow-dockerized . It has been declared as critical . Affected is an unknown function of the component Mail Service . Executing a manipulation can lead to improp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40888 | Frappe hrms up to 15.58.0/16.4.0 API Endpoint access control (GHSA-4375-7rxj-9hfx)

A vulnerability was found in Frappe hrms up to 15.58.0/16.4.0 . It has been rated as critical . Affected by this vulnerability is an unknown functionality of the component API Endpoint . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40879 | nestjs nest up to 11.1.18 JSON Message handleData recursion (GHSA-hpwf-8g29-85qm)

A vulnerability categorized as problematic has been discovered in nestjs nest up to 11.1.18 . Affected by this issue is the function handleData of the component JSON Message Handler . The manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40911 | WWBN AVideo up to 29.0 JSON Message script.js eval msg/callback code injection

A vulnerability identified as critical has been detected in WWBN AVideo up to 29.0 . This affects the function eval of the file plugin/YPTSocket/script.js of the component JSON Message Handler . This …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-6819 | HKUDS OpenHarness up to 155 Plugin Installation /plugin default permission

A vulnerability labeled as critical has been found in HKUDS OpenHarness up to 155 . This vulnerability affects unknown code of the file /plugin of the component Plugin Installation Handler . Such mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40875 | mailcow mailcow-dockerized prior 2026-03b Login History cross site scripting (GHSA-jprq-w83q-q62h)

A vulnerability marked as problematic has been reported in mailcow mailcow-dockerized . This issue affects some unknown processing of the component Login History . Performing a manipulation results in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-33812 | x-image font sfnt up to 0.38.x Font File Parser memory allocation

A vulnerability described as problematic has been identified in x-image font sfnt up to 0.38.x . Impacted is an unknown function of the component Font File Parser . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-33813 | x-image up to 0.38.x on 32-bit WEBP Image Parser integer overflow

A vulnerability classified as problematic has been found in x-image up to 0.38.x on 32-bit. The affected element is an unknown function of the component WEBP Image Parser . The manipulation leads to i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 22, 2026
CVE-2026-40372 | Microsoft ASP.NET Core up to 10.0.6 signature verification

A vulnerability classified as problematic was found in Microsoft ASP.NET Core up to 10.0.6 . The impacted element is an unknown function. The manipulation results in improper verification of cryptogra…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40585 | blueprintue blueprintue-self-hosted-edition up to 4.1.x Password Reset findUserIDFromEmailAndToken password recovery (GHSA-qr65-6vp8-whjf)

A vulnerability categorized as problematic has been discovered in blueprintue blueprintue-self-hosted-edition up to 4.1.x . Affected by this vulnerability is the function findUserIDFromEmailAndToken o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40589 | freescout-help-desk freescout up to 1.8.213 Email Address authorization (GHSA-mv55-3mgv-fxwr)

A vulnerability identified as critical has been detected in freescout-help-desk freescout up to 1.8.213 . Affected by this issue is some unknown functionality of the component Email Address Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40591 | freescout-help-desk freescout up to 1.8.213 Conversation customer_id/name/to_email/phone authorization (GHSA-9ff4-mmhv-x6jp)

A vulnerability labeled as critical has been found in freescout-help-desk freescout up to 1.8.213 . This affects an unknown part of the component Conversation Handler . The manipulation of the argumen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40590 | freescout-help-desk freescout up to 1.8.213 Email Validation /customers/ajax Customer::create authorization (GHSA-wjw4-8xg6-342m)

A vulnerability marked as problematic has been reported in freescout-help-desk freescout up to 1.8.213 . This vulnerability affects the function Customer::create of the file /customers/ajax of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41183 | freescout-help-desk freescout up to 1.8.214 information disclosure (GHSA-7rh8-9rgv-g35r)

A vulnerability described as problematic has been identified in freescout-help-desk freescout up to 1.8.214 . This issue affects some unknown processing. Such manipulation leads to information disclos…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41189 | freescout-help-desk freescout up to 1.8.214 ThreadPolicy::edit authorization (GHSA-4h5p-7f5c-q7gj)

A vulnerability classified as critical has been found in freescout-help-desk freescout up to 1.8.214 . Impacted is the function ThreadPolicy::edit . Performing a manipulation results in incorrect auth…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40592 | freescout-help-desk freescout up to 1.8.213 Conversation undo-reply authorization (GHSA-674v-r6xp-mvp6)

A vulnerability classified as problematic was found in freescout-help-desk freescout up to 1.8.213 . The affected element is an unknown function of the file /conversation/undo-reply/ of the component …

VulDB Read →
← Prev 66 / 241 Next →