CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5898 articles  ·  updated every 4 hours · grows forever

5898Total
4045Full Text
May 19, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-26951 | Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6 stack-based overflow (dsa-2026-060)

A vulnerability identified as critical has been detected in Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6 . This vulnerability affects unknown code. This manipulation causes stack-based b…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-35154 | Dell PowerProtect Data Domain appliances up to 7.13.1.60/8.3.1.20/8.7.0.0 privileges management (dsa-2026-060)

A vulnerability labeled as critical has been found in Dell PowerProtect Data Domain appliances up to 7.13.1.60/8.3.1.20/8.7.0.0 . This issue affects some unknown processing. Such manipulation leads to…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23756 | GFI HelpDesk up to 4.99.8 Troubleshooter Controller_Step.InsertSubmit subject cross site scripting

A vulnerability marked as problematic has been reported in GFI HelpDesk up to 4.99.8 . Impacted is the function Controller_Step.InsertSubmit of the component Troubleshooter Module . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-25883 | Vexa-ai vexa prior 0.10.0-260419-1910 HTTP POST Request server-side request forgery (GHSA-fhr6-8hff-cvg4)

A vulnerability described as critical has been identified in Vexa-ai vexa . The affected element is an unknown function of the component HTTP POST Request Handler . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23758 | GFI HelpDesk up to 4.99.8 POST Parameter Controller_Ticket.EditSubmit editsubject cross site scripting

A vulnerability classified as problematic has been found in GFI HelpDesk up to 4.99.8 . The impacted element is the function Controller_Ticket.EditSubmit of the component POST Parameter Handler . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-30266 | DeepCool DeepCreative up to 1.2.7 File permission

A vulnerability classified as critical was found in DeepCool DeepCreative up to 1.2.7 . This affects an unknown function of the component File Handler . The manipulation results in permission issues. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-41389 | OpenClaw up to 2026.4.14 UNC File file inclusion

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.4.14 . This impacts an unknown function of the component UNC File Handler . This manipulation causes file i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23752 | GFI HelpDesk up to 4.99.8 Groups Page companyname cross site scripting

A vulnerability, which was classified as problematic , was found in GFI HelpDesk up to 4.99.8 . Affected is an unknown function of the component Groups Page . Such manipulation of the argument company…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23753 | GFI HelpDesk up to 4.99.8 Languages Page SWIFT_Language::Create charset cross site scripting

A vulnerability has been found in GFI HelpDesk up to 4.99.8 and classified as problematic . Affected by this vulnerability is the function SWIFT_Language::Create of the component Languages Page . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23757 | GFI HelpDesk up to 4.99.9 Reports SWIFT_Report::Create report title cross site scripting

A vulnerability was found in GFI HelpDesk up to 4.99.9 and classified as problematic . Affected by this issue is the function SWIFT_Report::Create of the component Reports Module . Executing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-6654 | Mozilla thin-vec up to 0.2.15 clear use after free (GHSA-xphw-cqx3-667j / EUVD-2026-23832)

A vulnerability labeled as critical has been found in Mozilla thin-vec up to 0.2.15 . The affected element is the function IntoIter::drop/ThinVec::clear . Such manipulation leads to use after free. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-6662 | ericc-ch copilot-api up to 0.7.0 Token Endpoint src/server.ts cors cross-domain policy

A vulnerability marked as critical has been reported in ericc-ch copilot-api up to 0.7.0 . The impacted element is the function cors of the file src/server.ts of the component Token Endpoint . Perform…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-5958 | GNU sed up to 4.9 open_next_file toctou (EUVD-2026-23834)

A vulnerability described as problematic has been identified in GNU sed up to 4.9 . This affects the function open_next_file . Executing a manipulation can lead to time-of-check time-of-use. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-5760 | sglang 0.59 Reranking Endpoint /v1/rerank jinja2.Environment special elements used in a template engine

A vulnerability classified as critical has been found in sglang 0.59 . This impacts the function jinja2.Environment of the file /v1/rerank of the component Reranking Endpoint . The manipulation leads …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-3517 | Progress LoadMaster prior 7.2.63.0 API command injection

A vulnerability classified as critical was found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF . Affected is an unknown function of the component API …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-3518 | Progress LoadMaster prior 7.2.63.0 API command injection

A vulnerability, which was classified as critical , has been found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF . Affected by this vulnerability is a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-3519 | Progress LoadMaster prior 7.2.63.0 API command injection

A vulnerability, which was classified as critical , was found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF . Affected by this issue is some unknown f…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-4048 | Progress LoadMaster prior 7.2.63.0 UI command injection

A vulnerability has been found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF and classified as critical . This affects an unknown part of the componen…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-34427 | givanz Vvveb up to 1.0.8.0 Plugin Upload dynamically-determined object attributes

A vulnerability was found in givanz Vvveb up to 1.0.8.0 and classified as critical . This vulnerability affects unknown code of the component Plugin Upload Handler . Executing a manipulation can lead …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-6369 | Canonical canonical-livepatch up to 10.14.x Livepatch Service livepatchd.sock missing authentication

A vulnerability was found in Canonical canonical-livepatch up to 10.14.x . It has been classified as critical . This issue affects some unknown processing of the file livepatchd.sock of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-34428 | givanz Vvveb up to 1.0.8.0 file URL getUrl server-side request forgery

A vulnerability was found in givanz Vvveb up to 1.0.8.0 . It has been declared as critical . Impacted is the function getUrl of the component file URL Handler . The manipulation results in server-side…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-34429 | givanz Vvveb up to 1.0.8.0 Media Upload cross site scripting

A vulnerability was found in givanz Vvveb up to 1.0.8.0 . It has been rated as problematic . The affected element is an unknown function of the component Media Upload Handler . This manipulation cause…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure - The Hacker News

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure The Hacker News

The Hacker News Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-5967 | TeamT5 ThreatSonar Anti-Ransomware up to 4.0.0 os command injection (EUVD-2026-23800)

A vulnerability, which was classified as critical , has been found in TeamT5 ThreatSonar Anti-Ransomware up to 4.0.0 . This affects an unknown function. The manipulation leads to os command injection.…

VulDB Read →
← Prev 78 / 246 Next →