Skip to content
COOEY
LIVE FEED
3560 events · 4 sources · newest first
2026-08-25 NVD CVE
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn...
adminercode-executioncve-2026-56705nvd-cveodbcpdophpremote-code-execution
2026-08-25 NVD CVE
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to...
nvd-cve
2026-08-25 NVD CVE
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout...
accounts-securitiesadmin-super-accountapi-user-writeauthenticationbrute-force-protectioncve-2026-56710gravgrav-login-plugin
2026-08-25 NVD CVE
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML...
nvd-cve
2026-08-25 NVD CVE
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a...
arbitrary-command-executioncgicommand-injectioncooeys-clubcve-2026-63586http-basic-authenticationnvd-cveroot-privileges-escalation
2026-08-25 NVD CVE
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like...
nvd-cve
2026-08-25 NVD CVE
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
cve-2026-78568database-securitydatum-exfiltrationinsufficient-escapingnvd-cveplugins-vulnerabilitiesquery-preparationsql-injection
2026-08-25 NVD CVE
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the...
arbitrary-code-executioncve-2026-78683deserializations-attacknltknvd-cvepickle-deserializationpickle-gadgetpython
2026-08-25 NVD CVE
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config...
arbitrary-code-executioncode-injectionconfigs-corruptionscve-2026-78676directivegitgit-configgitpython
2026-08-25 NVD CVE
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of...
cve-2026-78570nvd-cveplugins-securityplugins-vulnerabilitiesprivileges-escalationsecurity-vulnerabilitytotals-donationsunauthenticated-attacks
2026-08-25 NVD CVE
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
administrator-privilegescve-2026-78477jawn-themenvd-cveprivileges-escalationsecurity-bulletinthemes-vulnerabilityunauthenticated-attacks
2026-08-25 CISA advisory
<h2><strong>Advisory at a Glance</strong></h2> <table> <tbody> <tr> <th>Title</th> <td>A Tale of Two SOCs: Insights From Two Red Team Assessments</td> </tr> <tr> <th>Original Publication&nbsp;</th> <td><strong>August...
cisa-advisory
2026-08-25 CISA KEV
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the...
cisa-kev
2026-08-25 NVD CVE
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies...
nvd-cve
2026-08-24 NVD CVE
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is...
api-tokenapp-codeapp-idauthentication-bypasscaches-keyingcve-2026-67602databases-rows-identifiersinsecure-cache
2026-08-24 NVD CVE
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper...
attackcve-2026-78167efmhttpcon-check-session-urlimproper-authenticationiptimenvd-cvepublic-exploit
2026-08-24 NVD CVE
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command...
nvd-cve
2026-08-24 NVD CVE
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded...
base64-decoderbin-netis-cgiboa-web-servercgicve-2026-76070firmwarelogin-handlernc63
2026-08-24 NVD CVE
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to...
boa-web-serverbuffer-overflowcgicve-2026-76071firmwareipfilterlistnc63netis
2026-08-24 NVD CVE
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these...
nvd-cve
2026-08-24 NVD CVE
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes()...
administrator-privilegesapi-token-issuanceauthentication-bypasscve-2026-77915nvd-cverconfigregistration-controllerroles-default
2026-08-24 CISA KEV
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as...
cisa-kev
2026-08-24 NVD CVE
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper...
cve-2026-78168efmhttpcon-check-session-urlimproper-authenticationiptimenvd-cveremote-attackssecurities-disclosures
2026-08-24 NVD CVE
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed...
cell-notecve-2026-78207deepmergeexcelj-hardenedexcelj-vulnerabilityjson-parsingmalicious-codenvd-cve
2026-08-24 NVD CVE
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a...
1250gwaspremotepapconftempsendcve-2026-78169goformhiperhttps-request-handlernvd-cvepublic-exploit
2026-08-24 NVD CVE
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter,...
4mosan4mosan-security-technologyadodbarbitrary-command-executioncve-2026-78211gcbs-doctormalicious-command-injectionnvd-cve
2026-08-23 NVD CVE
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The...
cross-site-scriptingcve-2026-7808dom-manipulationsforeign-contents-bypasshtml-sanitizationjusthtmlmathml-injectionsnamespaces-mislabeling
2026-08-23 NVD CVE
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom...
active-htmlcustoms-sanitizationcve-2026-5388encoded-urlshtml-commenthtml-serializationjavascript-injectionjusthtml
2026-08-23 NVD CVE
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set...
code-executioncross-site-scriptingcve-2026-8445html-escapinginput-validationjusthtmlmarkdownnvd-cve
2026-08-23 NVD CVE
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation...
cf-n1-scgi-bincomfastcve-2026-78050ntp-timezonenvd-cveremote-exploitsecurity-bulletin
2026-08-22 NVD CVE
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler....
apply-timecgibuffer-overflowcgi-bincve-2026-77946exploitnetwork-trafficntpnvd-cve
2026-08-22 NVD CVE
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the...
administrator-accounts-takeoverapi-keycve-2026-78003email-forwardinginput-validationmailgunnvd-cvepassword-reset
2026-08-22 NVD CVE
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission...
code-executioncve-2026-4703deserializationfile-deletionnvd-cvephp-object-injectionsecurity-bulletinsensitive-data-exposure
2026-08-21 NVD CVE
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers...
arbitrary-file-writeauthenticate-administratorauthenticates-accessesbazaarcode-executioncve-2026-77086directories-deletiondirectories-traversal
2026-08-21 CISA KEV
Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
code-executioncve-2026-69836deserializationentra-ididentity-managementmicrosoftmicrosofts-entrasnetworks-attacks
2026-08-21 NVD CVE
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr...
argumentcf-n1-scgi-bincomfastcommand-injectioncve-2026-77683exploitfile-system
2026-08-21 CISA KEV
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary...
arbitrary-command-executioncisa-kevcollaboration-suitecve-2026-73570email-serveros-command-injectionsecurity-vulnerabilitysmtp
2026-08-21 NVD CVE
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and...
allowlistauthenticationauthorizationcve-2026-77776datum-planedocker-composesheaders-injectionidentity-management
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
aixarbitrary-code-executioncve-2026-17160ibminteger-overflownvd-cvepowervmremote-attackers
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
aixarbitrary-code-executioncve-2026-17157ibmnvd-cvepowervmremote-attackerssecurity-bulletin
◀ PREV PAGE 01 / 89 NEXT ▶