CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5931 articles  ·  updated every 4 hours · grows forever

5931Total
4046Full Text
May 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40493 | HappySeaFox sail Field Header out-of-bounds write (GHSA-rcqx-gc76-r9mv)

A vulnerability classified as critical was found in HappySeaFox sail . This affects an unknown part of the component Field Handler . Executing a manipulation of the argument Header can lead to out-of-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40494 | HappySeaFox sail up to 496 RLE Decoder tga.c out-of-bounds write (GHSA-cp2j-rwh4-r46f)

A vulnerability, which was classified as critical , has been found in HappySeaFox sail up to 496 . This vulnerability affects unknown code of the file tga.c of the component RLE Decoder . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40337 | camelot-os sentry-kernel up to 0.4.6 unverified ownership (GHSA-5hgv-rg2f-79pg)

A vulnerability, which was classified as critical , was found in camelot-os sentry-kernel up to 0.4.6 . This issue affects some unknown processing. The manipulation results in unverified ownership. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40338 | gphoto libgphoto2 up to 2.5.33 camlibs/ptp2/ptp-pack.c ptp_unpack_Sony_DPD out-of-bounds (GHSA-2hwp-w84q-27hf)

A vulnerability has been found in gphoto libgphoto2 up to 2.5.33 and classified as critical . Impacted is the function ptp_unpack_Sony_DPD of the file camlibs/ptp2/ptp-pack.c . This manipulation cause…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40341 | gphoto libgphoto2 up to 2.5.33 ptp_unpack_EOS_FocusInfoEx buffer over-read (GHSA-vjx3-gjp6-r2g2)

A vulnerability was found in gphoto libgphoto2 up to 2.5.33 and classified as problematic . The affected element is the function ptp_unpack_EOS_FocusInfoEx . Such manipulation leads to buffer over-rea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40335 | gphoto libgphoto2 up to 2.5.33 camlibs/ptp2/ptp-pack.c ptp_unpack_DPV out-of-bounds (GHSA-g4g5-c2x9-cqfj)

A vulnerability was found in gphoto libgphoto2 up to 2.5.33 . It has been classified as critical . The impacted element is the function ptp_unpack_DPV of the file camlibs/ptp2/ptp-pack.c . Performing …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40336 | gphoto libgphoto2 up to 2.5.33 camlibs/ptp2/ptp-pack.c ptp_unpack_Sony_DPD memory leak (GHSA-g8xw-p5wj-mrxv)

A vulnerability was found in gphoto libgphoto2 up to 2.5.33 . It has been declared as problematic . This affects the function ptp_unpack_Sony_DPD of the file camlibs/ptp2/ptp-pack.c . Executing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-41253 | iTerm2 up to 3.6.9 File inclusion of functionality from untrusted control sphere

A vulnerability was found in iTerm2 up to 3.6.9 . It has been rated as problematic . This impacts an unknown function of the component File Handler . The manipulation leads to inclusion of functionali…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40323 | succinctlabs sp1 up to 6.0.x data authenticity (GHSA-63x8-x938-vx33)

A vulnerability categorized as problematic has been discovered in succinctlabs sp1 up to 6.0.x . Affected is an unknown function. The manipulation results in insufficient verification of data authenti…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40482 | ChurchCRM up to 7.1.x getMemberByScanString routeAndAccount sql injection (GHSA-hc37-vx3w-34fg)

A vulnerability identified as critical has been detected in ChurchCRM up to 7.1.x . Affected by this vulnerability is the function FinancialService::getMemberByScanString . This manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40582 | ChurchCRM up to 7.1.x API Endpoint /api/public/user/login authentication bypass (GHSA-8cwr-x83m-mh9x)

A vulnerability labeled as critical has been found in ChurchCRM up to 7.1.x . Affected by this issue is some unknown functionality of the file /api/public/user/login of the component API Endpoint . Su…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-35465 | freedomofpress securedrop-client up to 0.17.4 Archive Extraction file inclusion (GHSA-2jrc-x8fq-prvc)

A vulnerability marked as problematic has been reported in freedomofpress securedrop-client up to 0.17.4 . This affects an unknown part of the component Archive Extraction Handler . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-2434 | poporon Pz-LinkCard Plugin up to 2.5.8.1 on WordPress Shortcode blogcard cross site scripting

A vulnerability described as problematic has been identified in poporon Pz-LinkCard Plugin up to 2.5.8.1 on WordPress. This vulnerability affects the function blogcard of the component Shortcode Handl…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-1559 | Youzify Plugin up to 1.3.6 on WordPress checkin_place_id cross site scripting

A vulnerability classified as problematic has been found in Youzify Plugin up to 1.3.6 on WordPress. This issue affects some unknown processing. The manipulation of the argument checkin_place_id leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-1838 | prasunsen Hostel Plugin up to 1.1.6 on WordPress Shortcode shortcode_id cross site scripting

A vulnerability classified as problematic was found in prasunsen Hostel Plugin up to 1.1.6 on WordPress. Impacted is an unknown function of the component Shortcode Handler . The manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-4801 | godaddy Page Builder Gutenberg Blocks Plugin up to 3.1.16 on WordPress cross site scripting

A vulnerability, which was classified as problematic , has been found in godaddy Page Builder Gutenberg Blocks Plugin up to 3.1.16 on WordPress. The affected element is an unknown function. This manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-6048 | dragwyb Flipbox Addon for Elementor Plugin up to 2.0.8 on WordPress custom_attributes cross site scripting

A vulnerability, which was classified as problematic , was found in dragwyb Flipbox Addon for Elementor Plugin up to 2.0.8 on WordPress. The impacted element is an unknown function. Such manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40317 | MinecAnton209 NovumOS up to 0.23 privileges management (GHSA-xjx3-gjh9-45fm)

A vulnerability has been found in MinecAnton209 NovumOS up to 0.23 and classified as critical . This affects an unknown function. Performing a manipulation results in improper privilege management. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40572 | MinecAnton209 NovumOS up to 0.23 privileges management (GHSA-rg7m-6vh7-f4v2)

A vulnerability was found in MinecAnton209 NovumOS up to 0.23 and classified as critical . This impacts an unknown function. Executing a manipulation can lead to improper privilege management. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40479 | Kimai up to 2.52.x KimaiEscape.js escapeForHtml cross site scripting (GHSA-g82g-m9vx-vhjg)

A vulnerability was found in Kimai up to 2.52.x . It has been classified as problematic . Affected is the function escapeForHtml of the file KimaiEscape.js . The manipulation leads to cross site scrip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40489 | editorconfig editorconfig-core-c up to 0.12.10 EditorConfig Parser ec_glob stack-based overflow (GHSA-97xg-vrcq-254h)

A vulnerability was found in editorconfig editorconfig-core-c up to 0.12.10 . It has been declared as critical . Affected by this vulnerability is the function ec_glob of the component EditorConfig Pa…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40350 | leepeuker movary up to 0.71.0 Setting /settings/users authorization (GHSA-7r3f-9fwv-p43w)

A vulnerability was found in leepeuker movary up to 0.71.0 . It has been rated as critical . Affected by this issue is some unknown functionality of the file /settings/users of the component Setting H…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40348 | leepeuker movary up to 0.71.0 Endpoint server-url-verify server-side request forgery (GHSA-2m2v-v563-qqvj)

A vulnerability categorized as critical has been discovered in leepeuker movary up to 0.71.0 . This affects an unknown part of the file /settings/jellyfin/server-url-verify of the component Endpoint .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40483 | ChurchCRM up to 7.1.x Comment cross site scripting (GHSA-wjmf-w8gj-rx7g)

A vulnerability identified as problematic has been detected in ChurchCRM up to 7.1.x . This vulnerability affects unknown code. Performing a manipulation of the argument Comment results in cross site …

VulDB Read →
← Prev 85 / 248 Next →