CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5784 articles  ·  updated every 4 hours · grows forever

5784Total
4039Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40587 | blueprintue blueprintue-self-hosted-edition up to 4.1.x Password Change session expiration (GHSA-gqpq-x62g-p4mg)

A vulnerability identified as problematic has been detected in blueprintue blueprintue-self-hosted-edition up to 4.1.x . This issue affects some unknown processing of the component Password Change Han…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40613 | Coturn up to 4.9.x type conversion

A vulnerability labeled as problematic has been found in Coturn up to 4.9.x . Impacted is an unknown function. Such manipulation leads to incorrect type conversion. This vulnerability is referenced as…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40608 | DayuanJiang next-ai-draw-io up to 0.4.14 POST allocation of resources (GHSA-9q7h-wgfw-p378 / EUVD-2026-24217)

A vulnerability marked as problematic has been reported in DayuanJiang next-ai-draw-io up to 0.4.14 . The affected element is an unknown function of the component POST Handler . Performing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40611 | go-acme lego up to 4.33.x path traversal (GHSA-qqx8-2xmm-jrv8)

A vulnerability described as critical has been identified in go-acme lego up to 4.33.x . The impacted element is an unknown function. Executing a manipulation can lead to path traversal. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41192 | freescout-help-desk freescout up to 1.8.214 Attachment::deleteByIds attachments_all[] authorization (GHSA-cv36-2j23-x6g3)

A vulnerability classified as problematic has been found in freescout-help-desk freescout up to 1.8.214 . This affects the function Attachment::deleteByIds . The manipulation of the argument attachmen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40614 | pjsip pjproject up to 2.16 codec_parse dec_frame[].buf heap-based overflow

A vulnerability classified as critical was found in pjsip pjproject up to 2.16 . This impacts the function codec_parse . The manipulation of the argument dec_frame[].buf results in heap-based buffer o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40865 | horilla-opensource horilla 1.5.0 HR File access control

A vulnerability, which was classified as critical , has been found in horilla-opensource horilla 1.5.0 . Affected is an unknown function of the component HR File Handler . This manipulation causes imp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40866 | horilla-opensource horilla 1.5.0 Employee Document Upload Endpoint access control

A vulnerability, which was classified as critical , was found in horilla-opensource horilla 1.5.0 . Affected by this vulnerability is an unknown functionality of the component Employee Document Upload…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40867 | horilla-opensource horilla 1.5.0 Attachments access control

A vulnerability has been found in horilla-opensource horilla 1.5.0 and classified as critical . Affected by this issue is some unknown functionality of the component Attachments Handler . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41193 | freescout-help-desk freescout up to 1.8.214 ZIP Archive path traversal (GHSA-r85m-5mc9-cc9w)

A vulnerability was found in freescout-help-desk freescout up to 1.8.214 and classified as critical . This affects an unknown part of the component ZIP Archive Handler . Executing a manipulation can l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-22751 | Vmware Spring Security up to 6.4.15/6.5.9/7.0.4 One-Time Token Login toctou

A vulnerability was found in Vmware Spring Security up to 6.4.15/6.5.9/7.0.4 . It has been classified as problematic . This vulnerability affects unknown code of the component One-Time Token Login . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40868 | Kyverno up to 1.16.3 API Call sensitive information

A vulnerability was found in Kyverno up to 1.16.3 . It has been declared as critical . This issue affects some unknown processing of the component API Call Handler . The manipulation results in insecu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41194 | freescout-help-desk freescout up to 1.8.214 oauth-disconnect cross-site request forgery (GHSA-6rvw-fhqx-cfv5)

A vulnerability was found in freescout-help-desk freescout up to 1.8.214 . It has been rated as problematic . Impacted is an unknown function of the file /mailbox/oauth-disconnect/ . This manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40588 | blueprintue blueprintue-self-hosted-edition up to 4.1.x Password Change /profile/{slug}/edit/ current_password unverified password change (GHSA-73f2-p9jr-m44x)

A vulnerability categorized as critical has been discovered in blueprintue blueprintue-self-hosted-edition up to 4.1.x . The affected element is an unknown function of the file /profile/{slug}/edit/ o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41456 | Bludit up to 3.20 URL cross site scripting (6732dde)

A vulnerability identified as problematic has been detected in Bludit up to 3.20 . The impacted element is an unknown function of the component URL Handler . Performing a manipulation results in cross…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6771 | Mozilla Firefox up to 149 Security

A vulnerability was found in Mozilla Firefox up to 149 . It has been declared as problematic . Impacted is an unknown function of the component Security Component . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6774 | Mozilla Firefox up to 149 Security

A vulnerability was found in Mozilla Firefox up to 149 . It has been rated as problematic . The affected element is an unknown function of the component Security Component . The manipulation leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6782 | Mozilla Firefox up to 149 IP Protection information disclosure

A vulnerability categorized as problematic has been discovered in Mozilla Firefox up to 149 . The impacted element is an unknown function of the component IP Protection . The manipulation results in i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6766 | Mozilla Firefox up to 149 NSS memory corruption

A vulnerability identified as critical has been detected in Mozilla Firefox up to 149 . This affects an unknown function of the component NSS . This manipulation causes memory corruption. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6767 | Mozilla Firefox up to 149 NSS Remote Code Execution

A vulnerability labeled as critical has been found in Mozilla Firefox up to 149 . This impacts an unknown function of the component NSS . Such manipulation leads to Remote Code Execution. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6769 | Mozilla Firefox up to 149 Debugger Remote Code Execution

A vulnerability marked as critical has been reported in Mozilla Firefox up to 149 . Affected is an unknown function of the component Debugger . Performing a manipulation results in Remote Code Executi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6772 | Mozilla Firefox up to 149 NSS memory corruption

A vulnerability described as critical has been identified in Mozilla Firefox up to 149 . Affected by this vulnerability is an unknown functionality of the component NSS . Executing a manipulation can …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6770 | Mozilla Firefox up to 149 IndexedDB Remote Code Execution

A vulnerability classified as critical has been found in Mozilla Firefox up to 149 . Affected by this issue is some unknown functionality of the component IndexedDB . The manipulation leads to Remote …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6773 | Mozilla Firefox up to 149 WebGPU integer overflow

A vulnerability classified as problematic was found in Mozilla Firefox up to 149 . This affects an unknown part of the component WebGPU . The manipulation results in integer overflow. This vulnerabili…

VulDB Read →
← Prev 68 / 241 Next →