CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  10243 articles  ·  updated every 4 hours · grows forever

10243Total
4232Full Text
Jun 30, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58054 | MyBB up to 1.8.40 User verify_usergroup privileges management

A vulnerability was found in MyBB up to 1.8.40 and classified as critical . This impacts the function verify_usergroup of the component User Module . Such manipulation leads to improper privilege mana…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58058 | Nmap up to 7.99 libnetutil/netutil.cc integer underflow

A vulnerability was found in Nmap up to 7.99 . It has been classified as critical . Affected is an unknown function of the file libnetutil/netutil.cc . Performing a manipulation results in integer und…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58050 | libssh2 up to 1.11.1 SSH integer overflow

A vulnerability was found in libssh2 up to 1.11.1 . It has been declared as problematic . Affected by this vulnerability is an unknown functionality of the component SSH Handler . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58052 | 7-Zip up to 26.02 on Windows File Content protection mechanism

A vulnerability was found in 7-Zip up to 26.02 on Windows. It has been rated as problematic . Affected by this issue is some unknown functionality of the component File Content Handler . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58055 | nghttp2 up to 1.69.0 HTTP Request request smuggling

A vulnerability categorized as problematic has been discovered in nghttp2 up to 1.69.0 . This affects an unknown part of the component HTTP Request Handler . The manipulation results in http request s…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58056 | RustDesk Control Message authorization

A vulnerability identified as critical has been detected in RustDesk . This vulnerability affects unknown code of the component Control Message Handler . This manipulation causes incorrect authorizati…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-58057 | Flowise up to 3.1.2 on Windows Environment Variable case sensitivity

A vulnerability labeled as problematic has been found in Flowise up to 3.1.2 on Windows. This issue affects some unknown processing of the component Environment Variable Handler . Such manipulation le…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-10643 | zephyrproject zephyr up to 4.4.x Supervisor Mode sockets_inet.c recvmsg out-of-bounds write

A vulnerability marked as critical has been reported in zephyrproject zephyr up to 4.4.x . Impacted is the function recvmsg of the file subsys/net/lib/sockets/sockets_inet.c of the component Superviso…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-10593 | zephyrproject zephyr up to 4.4.x bap_unicast_client.c unicast_client_ep_qos_state null pointer dereference (GHSA-22q8-m94g-2pwh)

A vulnerability described as problematic has been identified in zephyrproject zephyr up to 4.4.x . The affected element is the function unicast_client_ep_qos_state of the file subsys/bluetooth/audio/b…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-10646 | zephyrproject zephyr up to 4.4.x getaddrinfo.c getaddrinfo ai_arr[] use after free (GHSA-h752-vhmf-29w6)

A vulnerability classified as critical has been found in zephyrproject zephyr up to 4.4.x . The impacted element is the function getaddrinfo of the file subsys/net/lib/sockets/getaddrinfo.c . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13507 | volcengine OpenViking up to 0.3.21 Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 ID data authenticity (Issue 2263)

A vulnerability classified as problematic was found in volcengine OpenViking up to 0.3.21 . This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of th…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13508 | khoj-ai khoj up to 2.0.0-beta.28 Conversation Sharing api_chat.py conversation.agent authorization (Issue 1327)

A vulnerability, which was classified as critical , has been found in khoj-ai khoj up to 2.0.0-beta.28 . This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conv…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13509 | RAGapp up to 0.1.5 Knowledge File files.py FileHandler.upload_file/FileHandler.remove_file path traversal (Issue 293)

A vulnerability, which was classified as critical , was found in RAGapp up to 0.1.5 . Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controller…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13510 | SimStudioAI sim up to 0.6.92 Password Protection deployment.ts weak hash (Issue 4759)

A vulnerability has been found in SimStudioAI sim up to 0.6.92 and classified as problematic . Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/depl…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13511 | VoltAgent up to 2.1.17 Memory REST API memory.handlers.ts handleGetMemoryConversation conversationId improper authorization (Issue 1315)

A vulnerability was found in VoltAgent up to 2.1.17 and classified as problematic . Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/mem…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13512 | Databend up to 1.2.881 on HTTP Tenant client_session_manager.rs state_key authorization (Issue 19930)

A vulnerability was found in Databend up to 1.2.881 on HTTP. It has been classified as problematic . This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13513 | MyScale MyScaleDB up to 1.8.0 SegmentId.h SegmentId::getCacheKey data authenticity (Issue 54)

A vulnerability was found in MyScale MyScaleDB up to 1.8.0 . It has been declared as problematic . This vulnerability affects the function SegmentId::getCacheKey in the library src/VectorIndex/Common/…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13514 | Chess Play and Learn App up to 4.9.42 on Android com.chess AndroidManifest.xml backup

A vulnerability was found in Chess Play and Learn App up to 4.9.42 on Android. It has been rated as problematic . This issue affects some unknown processing of the file AndroidManifest.xml of the comp…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13515 | Tenda JD12L 16.03.53.23 /goform/SetPptpServerCfg formSetPPTPServer startIp stack-based overflow

A vulnerability categorized as critical has been discovered in Tenda JD12L 16.03.53.23 . Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg . Such manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13516 | Tenda JD12L 16.03.53.23 /goform/WifiGuestSet fromSetWifiGusetBasic shareSpeed stack-based overflow

A vulnerability identified as critical has been detected in Tenda JD12L 16.03.53.23 . The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet . Performing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13517 | Tenda JD12L 16.03.53.23 /goform/WifiBasicSet formWifiBasicSet security_5g stack-based overflow

A vulnerability labeled as critical has been found in Tenda JD12L 16.03.53.23 . The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet . Executing a manipulation of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13518 | Tenda JD12L 16.03.53.23 /goform/addressNat fromAddressNat page stack-based overflow

A vulnerability marked as critical has been reported in Tenda JD12L 16.03.53.23 . This affects the function fromAddressNat of the file /goform/addressNat . The manipulation of the argument page leads …

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13519 | Tenda JD12L 16.03.53.23 /goform/NatStaticSetting fromNatStaticSetting page stack-based overflow

A vulnerability described as critical has been identified in Tenda JD12L 16.03.53.23 . This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting . The manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Jun 28, 2026
CVE-2026-13520 | itsourcecode Hospital Management System 1.0 Appointment /appointmentapproval.php editid sql injection

A vulnerability classified as critical has been found in itsourcecode Hospital Management System 1.0 . Affected is an unknown function of the file /appointmentapproval.php of the component Appointment…

VulDB Read →
← Prev 9 / 427 Next →