CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5768 articles  ·  updated every 4 hours · grows forever

5768Total
4039Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41190 | freescout-help-desk freescout up to 1.8.214 Conversation authorization (GHSA-vj2p-2789-3747)

A vulnerability, which was classified as critical , has been found in freescout-help-desk freescout up to 1.8.214 . The impacted element is an unknown function of the component Conversation Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41191 | freescout-help-desk freescout up to 1.8.214 updateSave authorization (GHSA-wpv9-c2gv-2j82)

A vulnerability, which was classified as critical , was found in freescout-help-desk freescout up to 1.8.214 . This affects the function MailboxesController::updateSave . The manipulation results in i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40706 | tuxera ntfs-3g 2022.10.3 NTFS Image acls.c ntfs_build_permissions_posix buffer overflow

A vulnerability has been found in tuxera ntfs-3g 2022.10.3 and classified as critical . This impacts the function ntfs_build_permissions_posix of the file acls.c of the component NTFS Image Handler . …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40599 | craigjbass clearancekit up to 5.0.4 authorization (GHSA-w253-42qp-5f2x / EUVD-2026-24209)

A vulnerability was found in craigjbass clearancekit up to 5.0.4 and classified as problematic . Affected is an unknown function. Such manipulation leads to incorrect authorization. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40594 | pyLoad up to 0.5.0b3.dev97 __init__.py set_session_cookie_secure origin validation (GHSA-mp82-fmj6-f22v)

A vulnerability was found in pyLoad up to 0.5.0b3.dev97 . It has been classified as problematic . Affected by this vulnerability is the function set_session_cookie_secure of the file src/pyload/webui/…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40602 | home-assistant-ecosystem home-assistant-cli up to 0.x code injection (GHSA-33qf-q99x-wpm8)

A vulnerability was found in home-assistant-ecosystem home-assistant-cli up to 0.x . It has been declared as critical . Affected by this issue is some unknown functionality. Executing a manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40604 | craigjbass clearancekit up to 5.0.5 AUTH Endpoint protection mechanism (GHSA-5r9w-9fg6-266q / EUVD-2026-24213)

A vulnerability was found in craigjbass clearancekit up to 5.0.5 . It has been rated as problematic . This affects an unknown part of the component AUTH Endpoint . The manipulation leads to protection…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40606 | mitmproxy up to 12.2.1 ldap injection (GHSA-527g-3w9m-29hv)

A vulnerability categorized as problematic has been discovered in mitmproxy up to 12.2.1 . This vulnerability affects unknown code. The manipulation results in ldap injection. This vulnerability was n…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40587 | blueprintue blueprintue-self-hosted-edition up to 4.1.x Password Change session expiration (GHSA-gqpq-x62g-p4mg)

A vulnerability identified as problematic has been detected in blueprintue blueprintue-self-hosted-edition up to 4.1.x . This issue affects some unknown processing of the component Password Change Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40613 | Coturn up to 4.9.x type conversion

A vulnerability labeled as problematic has been found in Coturn up to 4.9.x . Impacted is an unknown function. Such manipulation leads to incorrect type conversion. This vulnerability is referenced as…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40608 | DayuanJiang next-ai-draw-io up to 0.4.14 POST allocation of resources (GHSA-9q7h-wgfw-p378 / EUVD-2026-24217)

A vulnerability marked as problematic has been reported in DayuanJiang next-ai-draw-io up to 0.4.14 . The affected element is an unknown function of the component POST Handler . Performing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40611 | go-acme lego up to 4.33.x path traversal (GHSA-qqx8-2xmm-jrv8)

A vulnerability described as critical has been identified in go-acme lego up to 4.33.x . The impacted element is an unknown function. Executing a manipulation can lead to path traversal. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41192 | freescout-help-desk freescout up to 1.8.214 Attachment::deleteByIds attachments_all[] authorization (GHSA-cv36-2j23-x6g3)

A vulnerability classified as problematic has been found in freescout-help-desk freescout up to 1.8.214 . This affects the function Attachment::deleteByIds . The manipulation of the argument attachmen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40614 | pjsip pjproject up to 2.16 codec_parse dec_frame[].buf heap-based overflow

A vulnerability classified as critical was found in pjsip pjproject up to 2.16 . This impacts the function codec_parse . The manipulation of the argument dec_frame[].buf results in heap-based buffer o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40865 | horilla-opensource horilla 1.5.0 HR File access control

A vulnerability, which was classified as critical , has been found in horilla-opensource horilla 1.5.0 . Affected is an unknown function of the component HR File Handler . This manipulation causes imp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40866 | horilla-opensource horilla 1.5.0 Employee Document Upload Endpoint access control

A vulnerability, which was classified as critical , was found in horilla-opensource horilla 1.5.0 . Affected by this vulnerability is an unknown functionality of the component Employee Document Upload…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40867 | horilla-opensource horilla 1.5.0 Attachments access control

A vulnerability has been found in horilla-opensource horilla 1.5.0 and classified as critical . Affected by this issue is some unknown functionality of the component Attachments Handler . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41193 | freescout-help-desk freescout up to 1.8.214 ZIP Archive path traversal (GHSA-r85m-5mc9-cc9w)

A vulnerability was found in freescout-help-desk freescout up to 1.8.214 and classified as critical . This affects an unknown part of the component ZIP Archive Handler . Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-22751 | Vmware Spring Security up to 6.4.15/6.5.9/7.0.4 One-Time Token Login toctou

A vulnerability was found in Vmware Spring Security up to 6.4.15/6.5.9/7.0.4 . It has been classified as problematic . This vulnerability affects unknown code of the component One-Time Token Login . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40868 | Kyverno up to 1.16.3 API Call sensitive information

A vulnerability was found in Kyverno up to 1.16.3 . It has been declared as critical . This issue affects some unknown processing of the component API Call Handler . The manipulation results in insecu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41194 | freescout-help-desk freescout up to 1.8.214 oauth-disconnect cross-site request forgery (GHSA-6rvw-fhqx-cfv5)

A vulnerability was found in freescout-help-desk freescout up to 1.8.214 . It has been rated as problematic . Impacted is an unknown function of the file /mailbox/oauth-disconnect/ . This manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40588 | blueprintue blueprintue-self-hosted-edition up to 4.1.x Password Change /profile/{slug}/edit/ current_password unverified password change (GHSA-73f2-p9jr-m44x)

A vulnerability categorized as critical has been discovered in blueprintue blueprintue-self-hosted-edition up to 4.1.x . The affected element is an unknown function of the file /profile/{slug}/edit/ o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41456 | Bludit up to 3.20 URL cross site scripting (6732dde)

A vulnerability identified as problematic has been detected in Bludit up to 3.20 . The impacted element is an unknown function of the component URL Handler . Performing a manipulation results in cross…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6771 | Mozilla Firefox up to 149 Security

A vulnerability was found in Mozilla Firefox up to 149 . It has been declared as problematic . Impacted is an unknown function of the component Security Component . Executing a manipulation can lead t…

VulDB Read →
← Prev 67 / 241 Next →