CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5895 articles  ·  updated every 4 hours · grows forever

5895Total
4042Full Text
May 19, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6553 | TYPO3 CMS up to 14.2.x User Settings user_settings cleartext storage

A vulnerability, which was classified as problematic , has been found in TYPO3 CMS up to 14.2.x . Impacted is an unknown function of the component User Settings Module . This manipulation of the argum…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-39467 | MetaSlider Responsive Slider Plugin up to 3.106.0 on WordPress deserialization

A vulnerability, which was classified as problematic , was found in MetaSlider Responsive Slider Plugin up to 3.106.0 on WordPress. The affected element is an unknown function. Such manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41039 | Quantum Router QN-I-470 6.1.1.B1 API Endpoint missing authentication (CIVN-2026-0200)

A vulnerability has been found in Quantum Router QN-I-470 6.1.1.B1 and classified as critical . The impacted element is an unknown function of the component API Endpoint . Performing a manipulation re…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-3317 | Navigate CMS up to 2.9.5 /blog cross site scripting

A vulnerability was found in Navigate CMS up to 2.9.5 and classified as problematic . This affects an unknown function of the file /blog . Executing a manipulation can lead to cross site scripting. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
Attackers Weaponize CVE-2026-39987 to Spread Blockchain-Based Backdoor Via Hugging Face - CyberSecurityNews

Attackers Weaponize CVE-2026-39987 to Spread Blockchain-Based Backdoor Via Hugging Face CyberSecurityNews

CyberSecurityNews Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
6,000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online - cyberpress.org

6,000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-39946 | OpenBao up to 2.5.2 PostgreSQL Database Secrets Engine sql injection (GHSA-6vgr-cp5c-ffx3)

A vulnerability has been found in OpenBao up to 2.5.2 and classified as critical . This impacts an unknown function of the component PostgreSQL Database Secrets Engine . Performing a manipulation resu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-39386 | m1k1o neko up to 3.0.10/3.1.1 /api/profile access control (GHSA-2gw9-c2r2-f5qf)

A vulnerability was found in m1k1o neko up to 3.0.10/3.1.1 and classified as critical . Affected is an unknown function of the file /api/profile . Executing a manipulation can lead to improper access …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-39388 | OpenBao up to 2.5.2 certificate validation (GHSA-7ccv-rp6m-rffr)

A vulnerability was found in OpenBao up to 2.5.2 . It has been classified as critical . Affected by this vulnerability is an unknown functionality. The manipulation leads to improper certificate valid…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40264 | OpenBao up to 2.5.2 improper restriction of security token assignment (GHSA-p49j-v9wc-wg57)

A vulnerability was found in OpenBao up to 2.5.2 . It has been declared as problematic . Affected by this issue is some unknown functionality. The manipulation results in improper restriction of secur…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-34839 | nicolargo glances up to 4.5.3 REST API /api/4/ information disclosure (GHSA-gfc2-9qmw-w7vh)

A vulnerability was found in nicolargo glances up to 4.5.3 . It has been rated as problematic . This affects an unknown part of the file /api/4/ of the component REST API . This manipulation causes in…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-35588 | nicolargo glances up to 4.5.3 Cassandra Export __init__.py sql injection (GHSA-grp3-h8m8-45p7)

A vulnerability categorized as critical has been discovered in nicolargo glances up to 4.5.3 . This vulnerability affects unknown code of the file glances/exports/glances_cassandra/__init__.py of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-35570 | Gitlawb openclaude up to 0.5.0 Command Line Interface Parser bashPermissions.ts path traversal (GHSA-m6rx-7pvw-2f73)

A vulnerability identified as critical has been detected in Gitlawb openclaude up to 0.5.0 . This issue affects some unknown processing of the file src/tools/BashTool/bashPermissions.ts of the compone…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-39396 | OpenBao up to 2.5.2 OCI Plugin ExtractPluginFromImage resource consumption (GHSA-r65v-xgwc-g56j)

A vulnerability labeled as problematic has been found in OpenBao up to 2.5.2 . Impacted is the function ExtractPluginFromImage of the component OCI Plugin . Executing a manipulation can lead to resour…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-35587 | nicolargo glances up to 4.5.3 Configuration Parameter public_api server-side request forgery (GHSA-g5pq-48mj-jvw8)

A vulnerability marked as critical has been reported in nicolargo glances up to 4.5.3 . The affected element is the function public_api of the component Configuration Parameter Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-39861 | Anthropic claude-code up to 2.1.63 Symlink path traversal (GHSA-vp62-r36r-9xqp)

A vulnerability described as critical has been identified in Anthropic claude-code up to 2.1.63 . The impacted element is an unknown function of the component Symlink Handler . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41285 | OpenBSD up to 7.8 ICMPv6 Neighbor Discovery Option nd_opt_len improper validation of specified quantity in input

A vulnerability classified as problematic has been found in OpenBSD up to 7.8 . This affects an unknown function of the component ICMPv6 Neighbor Discovery Option Handler . This manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6675 | cyberchimps Responsive Blocks Plugin up to 2.2.0 on WordPress Public REST API Route input validation

A vulnerability classified as critical was found in cyberchimps Responsive Blocks Plugin up to 2.2.0 on WordPress. This impacts an unknown function of the component Public REST API Route . Such manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40045 | OpenClaw up to 2026.4.1 ws Gateway Endpoint cleartext transmission (GHSA-83f3-hh45-vfw9)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.4.1 . Affected is an unknown function of the component ws Gateway Endpoint Handler . Performing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6674 | tholstkabelbwde CMS für Motorrad Werkstätten Plugin up to 1.0.0 on WordPress arttype sql injection

A vulnerability, which was classified as critical , was found in tholstkabelbwde CMS für Motorrad Werkstätten Plugin up to 1.0.0 on WordPress. Affected by this vulnerability is an unknown functionalit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41294 | OpenClaw up to 2026.3.27 Environment Variable external control of setting (GHSA-8rh7-6779-cjqq)

A vulnerability has been found in OpenClaw up to 2026.3.27 and classified as problematic . Affected by this issue is some unknown functionality of the component Environment Variable Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41295 | OpenClaw up to 2026.4.1 Workspace Channel inclusion of functionality from untrusted control sphere (GHSA-2qrv-rc5x-2g2h)

A vulnerability was found in OpenClaw up to 2026.4.1 and classified as problematic . This affects an unknown part of the component Workspace Channel Handler . The manipulation results in inclusion of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40497 | freescout-help-desk freescout up to 1.8.212 Mailbox Signature Field /mailbox/settings/ stripDangerousTags cross site scripting (GHSA-fh99-wr77-pxq3)

A vulnerability was found in freescout-help-desk freescout up to 1.8.212 . It has been classified as problematic . This vulnerability affects the function Helper::stripDangerousTags of the file /mailb…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-5965 | NewSoft NewSoftOA prior 10.1.8.3 os command injection

A vulnerability was found in NewSoft NewSoftOA . It has been declared as critical . This issue affects some unknown processing. Such manipulation leads to os command injection. This vulnerability is d…

VulDB Read →
← Prev 75 / 246 Next →