CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  5962 articles  ·  updated every 4 hours · grows forever

5962Total
4047Full Text
May 20, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40302 | openziti zrok up to 2.0.0 ProxyUi Template Engine cross site scripting (GHSA-4fxq-2x3x-6xqx)

A vulnerability has been found in openziti zrok up to 2.0.0 and classified as problematic . The impacted element is an unknown function of the component ProxyUi Template Engine . This manipulation cau…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-33436 | Stirling-Tools Stirling-PDF up to 1.x PDF File information disclosure (GHSA-q5j3-4m5w-wp75)

A vulnerability was found in Stirling-Tools Stirling-PDF up to 1.x and classified as problematic . This affects an unknown function of the component PDF File Handler . Such manipulation leads to infor…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40304 | openziti zrok up to 2.0.0 controller/unaccess.go environment_id access control

A vulnerability was found in openziti zrok up to 2.0.0 . It has been classified as critical . This impacts an unknown function of the file controller/unaccess.go . Performing a manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40352 | labring FastGPT up to 4.14.9.5 Password Change Endpoint data query logic injection

A vulnerability was found in labring FastGPT up to 4.14.9.5 . It has been declared as critical . Affected is an unknown function of the component Password Change Endpoint . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40155 | auth0 nextjs-auth0 up to 4.17.x authorization (GHSA-xq8m-7c5p-c2r6)

A vulnerability was found in auth0 nextjs-auth0 up to 4.17.x . It has been rated as problematic . Affected by this vulnerability is an unknown functionality. The manipulation leads to incorrect author…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-29013 | libcoap up to 4.3.5a CBOR Parser src/oscore/oscore_cbor.c get_byte_inc out-of-bounds

A vulnerability categorized as problematic has been discovered in libcoap up to 4.3.5a . Affected by this issue is the function get_byte_inc of the file src/oscore/oscore_cbor.c of the component CBOR …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-35402 | neo4j-contrib mcp-neo4j up to 0.5.x APOC CALL read_only access control (GHSA-x3cv-r3g3-fpg9)

A vulnerability identified as critical has been detected in neo4j-contrib mcp-neo4j up to 0.5.x . This affects the function read_only of the component APOC CALL Handler . This manipulation causes impr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40353 | wger-project wger up to 2.4 attribution_link license_author cross site scripting

A vulnerability labeled as problematic has been found in wger-project wger up to 2.4 . This vulnerability affects the function attribution_link . Such manipulation of the argument license_author leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40293 | OpenFGA up to 1.13.x information disclosure (GHSA-68m9-983m-f3v5)

A vulnerability marked as problematic has been reported in OpenFGA up to 1.13.x . This issue affects some unknown processing. Performing a manipulation results in information disclosure. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-35603 | Anthropic claude-code up to 2.1.74 on Windows Configuration managed-settings.json untrusted search path (GHSA-5cwg-9f6j-9jvx)

A vulnerability described as problematic has been identified in Anthropic claude-code up to 2.1.74 on Windows. Impacted is an unknown function of the file C:\ProgramData\ClaudeCode\managed-settings.js…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40299 | amannn next-intl up to 4.9.0 WHATWG URL Parser redirect (GHSA-8f24-v5vv-gm5j)

A vulnerability classified as problematic has been found in amannn next-intl up to 4.9.0 . The affected element is an unknown function of the component WHATWG URL Parser . The manipulation leads to op…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40285 | LabRedesCefetRJ WeGIA up to 3.6.9 POST Parameter UsuarioDAO.php verificarDespacho cpf_usuario sql injection (GHSA-666r-v2m7-xgp9)

A vulnerability classified as critical was found in LabRedesCefetRJ WeGIA up to 3.6.9 . The impacted element is the function DespachoControle::verificarDespacho of the file dao/memorando/UsuarioDAO.ph…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-5720 | miniupnp project miniupnpd up to 2.3.9 HTTP Request ParseHttpHeaders integer underflow

A vulnerability, which was classified as critical , has been found in miniupnp project miniupnpd up to 2.3.9 . This affects the function ParseHttpHeaders of the component HTTP Request Handler . This m…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40474 | wger-project wger up to 2.4 Configuration config.change_gymconfig save access control

A vulnerability, which was classified as critical , was found in wger-project wger up to 2.4 . This impacts the function Save of the file config.change_gymconfig of the component Configuration Handler…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40527 | radareorg radare2 ELF DW_TAG_formal_parameter os command injection

A vulnerability has been found in radareorg radare2 and classified as critical . Affected is the function DW_TAG_formal_parameter of the component ELF Handler . Performing a manipulation results in os…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40284 | LabRedesCefetRJ WeGIA up to 3.6.9 Destinatário cross site scripting (GHSA-mccp-8446-phw5)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.9 and classified as problematic . Affected by this vulnerability is an unknown functionality. Executing a manipulation of the argument Dest…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-40286 | LabRedesCefetRJ WeGIA up to 3.6.9 Member Name cross site scripting (GHSA-42rc-rvrx-cmmw)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.6.9 . It has been classified as problematic . Affected by this issue is some unknown functionality. The manipulation of the argument Member N…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
Google Chrome Security Update Fixes 29 Vulnerabilities, Including Remote Code Execution Flaws - cyberpress.org

Google Chrome Security Update Fixes 29 Vulnerabilities, Including Remote Code Execution Flaws cyberpress.org

cyberpress.org Read →
⬡ Vulnerabilities & CVEs Apr 18, 2026
CVE-2026-33032 Enables Full Nginx Server Takeover Risk - The Cyber Express

CVE-2026-33032 Enables Full Nginx Server Takeover Risk The Cyber Express

The Cyber Express Read →
⬡ Vulnerabilities & CVEs Apr 17, 2026
CVE-2026-21709 | Veeam Backup and Replication/Software Appliance Windows Driver Signature Enforcement command injection (kb4830 / EUVD-2026-23438)

A vulnerability was found in Veeam Backup and Replication and Software Appliance and classified as critical . Affected is an unknown function of the component Windows Driver Signature Enforcement . Su…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 17, 2026
CVE-2026-3464 | aguilatechnologies WP Customer Area Plugin up to 8.3.4 on WordPress ajax_attach_file path traversal (EUVD-2026-23448)

A vulnerability was found in aguilatechnologies WP Customer Area Plugin up to 8.3.4 on WordPress. It has been classified as critical . Affected by this vulnerability is the function ajax_attach_file .…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 17, 2026
CVE-2026-40515 | HKUDS OpenHarness Path Normalization authorization (EUVD-2026-23450)

A vulnerability was found in HKUDS OpenHarness . It has been declared as problematic . Affected by this issue is some unknown functionality of the component Path Normalization Handler . Executing a ma…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 17, 2026
CVE-2026-21733 | Imagination Graphics DDK up to 25.3 RTM GPU insufficient permissions or privileges (EUVD-2026-23446)

A vulnerability was found in Imagination Graphics DDK up to 1.17 RTM/1.18 RTM/23.2 RTM/24.2 RTM/25.3 RTM . It has been rated as problematic . This affects an unknown part of the component GPU Handler …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 17, 2026
CVE-2026-40516 | HKUDS OpenHarness HTTP Service web_fetch/web_search server-side request forgery (EUVD-2026-23452)

A vulnerability categorized as critical has been discovered in HKUDS OpenHarness . This vulnerability affects the function web_fetch/web_search of the component HTTP Service . The manipulation results…

VulDB Read →
← Prev 88 / 249 Next →