CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5931 articles  ·  updated every 4 hours · grows forever

5931Total
4046Full Text
May 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40346 | nocobase up to 2.0.36 server-side request forgery (GHSA-mvvv-v22x-xqwp)

A vulnerability labeled as critical has been found in nocobase up to 2.0.36 . This issue affects some unknown processing. Executing a manipulation can lead to server-side request forgery. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40487 | gitroomhq postiz-app up to 2.21.5 cross site scripting (GHSA-44wg-r34q-hvfx)

A vulnerability marked as problematic has been reported in gitroomhq postiz-app up to 2.21.5 . Impacted is an unknown function. The manipulation leads to cross site scripting. This vulnerability is un…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40349 | leepeuker movary up to 0.71.0 Endpoint /settings/users/ authorization (GHSA-mcfq-8rx7-w25v)

A vulnerability described as critical has been identified in leepeuker movary up to 0.71.0 . The affected element is an unknown function of the file /settings/users/ of the component Endpoint . The ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-41254 | Little CMS up to 2.18 CubeSize cmslut.c incorrect behavior order

A vulnerability classified as problematic has been found in Little CMS up to 2.18 . The impacted element is an unknown function of the file cmslut.c of the component CubeSize . This manipulation cause…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-32624 | neutrinolabs xrdp up to 0.10.5 Domain Name xrdp.ini domain_user_separator heap-based overflow (GHSA-7q2g-6fjr-h6pp)

A vulnerability was found in neutrinolabs xrdp up to 0.10.5 and classified as critical . Impacted is the function domain_user_separator of the file xrdp.ini of the component Domain Name Handler . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40282 | LabRedesCefetRJ WeGIA up to 3.6.9 Notifications cross site scripting

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.9 . It has been classified as problematic . The affected element is an unknown function of the component Notifications Handler . This manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40283 | LabRedesCefetRJ WeGIA up to 3.6.9 Informações Pacientes Page Nome cross site scripting (GHSA-x74c-gwj9-6cwr)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.9 . It has been declared as problematic . The impacted element is an unknown function of the component Informações Pacientes Page . Such ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40948 | Apache Airflow Keycloak Provider up to 0.6.x OAuth Login cross-site request forgery

A vulnerability was found in Apache Airflow Keycloak Provider up to 0.6.x . It has been rated as problematic . This affects an unknown function of the component OAuth Login . Performing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40196 | sysadminsmedia homebox up to 0.24.x Web Interface incorrect ownership assignment (GHSA-6pvm-v73p-p6m9)

A vulnerability categorized as critical has been discovered in sysadminsmedia homebox up to 0.24.x . This impacts an unknown function of the component Web Interface . Executing a manipulation can lead…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40305 | dnnsoftware Dnn.Platform up to 10.2.1 improper authorization

A vulnerability identified as critical has been detected in dnnsoftware Dnn.Platform up to 10.2.1 . Affected is an unknown function. The manipulation leads to improper authorization. This vulnerabilit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-23500 | Dolibarr up to 22.x Software Package odf.php exec os command injection (GHSA-w5j3-8fcr-h87w)

A vulnerability labeled as critical has been found in Dolibarr up to 22.x . Affected by this vulnerability is the function exec of the file odf.php of the component Software Package Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40301 | rhukster dom-sanitizer up to 1.0.9 DOM/SVG/MathML DOMSanitizer::sanitize cross site scripting (GHSA-93vf-569f-22cq)

A vulnerability marked as problematic has been reported in rhukster dom-sanitizer up to 1.0.9 . Affected by this issue is the function DOMSanitizer::sanitize of the component DOM/SVG/MathML . This man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40306 | dnnsoftware Dnn.Platform up to 10.2.1 random values

A vulnerability described as problematic has been identified in dnnsoftware Dnn.Platform up to 10.2.1 . This affects an unknown part. Such manipulation leads to insufficiently random values. This vuln…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40321 | dnnsoftware Dnn.Platform up to 10.2.1 SVG File cross site scripting

A vulnerability classified as problematic has been found in dnnsoftware Dnn.Platform up to 10.2.1 . This vulnerability affects unknown code of the component SVG File Handler . Performing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40258 | gramps-project gramps-web-api up to 3.11.0 Gramps Web API path traversal

A vulnerability classified as critical was found in gramps-project gramps-web-api up to 3.11.0 . This issue affects some unknown processing of the component Gramps Web API . Executing a manipulation c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40303 | openziti zrok up to 2.0.0 endpoints.GetSessionCookie resource consumption (GHSA-cpf9-ph2j-ccr9)

A vulnerability, which was classified as problematic , has been found in openziti zrok up to 2.0.0 . Impacted is the function endpoints.GetSessionCookie . The manipulation leads to resource consumptio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40351 | labring FastGPT up to 4.14.9.5 Password Field data query logic injection

A vulnerability, which was classified as critical , was found in labring FastGPT up to 4.14.9.5 . The affected element is an unknown function of the component Password Field Handler . The manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40302 | openziti zrok up to 2.0.0 ProxyUi Template Engine cross site scripting (GHSA-4fxq-2x3x-6xqx)

A vulnerability has been found in openziti zrok up to 2.0.0 and classified as problematic . The impacted element is an unknown function of the component ProxyUi Template Engine . This manipulation cau…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-33436 | Stirling-Tools Stirling-PDF up to 1.x PDF File information disclosure (GHSA-q5j3-4m5w-wp75)

A vulnerability was found in Stirling-Tools Stirling-PDF up to 1.x and classified as problematic . This affects an unknown function of the component PDF File Handler . Such manipulation leads to infor…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40304 | openziti zrok up to 2.0.0 controller/unaccess.go environment_id access control

A vulnerability was found in openziti zrok up to 2.0.0 . It has been classified as critical . This impacts an unknown function of the file controller/unaccess.go . Performing a manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40352 | labring FastGPT up to 4.14.9.5 Password Change Endpoint data query logic injection

A vulnerability was found in labring FastGPT up to 4.14.9.5 . It has been declared as critical . Affected is an unknown function of the component Password Change Endpoint . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40155 | auth0 nextjs-auth0 up to 4.17.x authorization (GHSA-xq8m-7c5p-c2r6)

A vulnerability was found in auth0 nextjs-auth0 up to 4.17.x . It has been rated as problematic . Affected by this vulnerability is an unknown functionality. The manipulation leads to incorrect author…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-29013 | libcoap up to 4.3.5a CBOR Parser src/oscore/oscore_cbor.c get_byte_inc out-of-bounds

A vulnerability categorized as problematic has been discovered in libcoap up to 4.3.5a . Affected by this issue is the function get_byte_inc of the file src/oscore/oscore_cbor.c of the component CBOR …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-35402 | neo4j-contrib mcp-neo4j up to 0.5.x APOC CALL read_only access control (GHSA-x3cv-r3g3-fpg9)

A vulnerability identified as critical has been detected in neo4j-contrib mcp-neo4j up to 0.5.x . This affects the function read_only of the component APOC CALL Handler . This manipulation causes impr…

VulDB Read →
← Prev 86 / 248 Next →