LIVE FEED
1767 events · 4 sources · newest first
Events in view
1767
all sources
Critical
1492
severity
Active sources
4
collectors
Last sync
2026-08-26 00:01
UTC
2026-08-05
NVD CVE
CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operat
CRITICAL
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM...
advanced-cluster-managementapplication-subscription-controllercluster-adminscluster-role-bindingcve-2026-10090helmkubernetenamespaces-scoped-privilege
2026-08-05
NVD CVE
CVE-2026-20310: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software...
catalyst-sd-wanciscocve-2026-20310cwes-59files-accesslink-resolutionnvd-cvesecurity-review
2026-08-05
NVD CVE
CVE-2026-20304: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software...
catalyst-sd-wanciscocve-2026-20304cwe-284improper-access-controlnvd-cvesecurity-reviewsoftwares-hardening
2026-08-05
NVD CVE
CVE-2026-20303: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20303cwes-20input-validationnvd-cvesoftwares-hardeningvulnerability
2026-08-05
NVD CVE
CVE-2026-20267: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20267cwes-pillar-cwe-284improper-access-controlnvd-cveproduct-qualitysecurity-reviewsoftwares-hardening
2026-08-05
NVD CVE
CVE-2026-20272: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20272cwes-74nvd-cvesoftwares-hardeningvulnerability
2026-08-05
NVD CVE
CVE-2026-70615: boringproxy through 0.10.0 contains a newline injection vulnerability that allow
CRITICAL
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH...
authenticate-userboringproxycleartext-credentiallow-privilegednewline-injectionnvd-cvepersistent-shell-accessssh-authorized-key
2026-08-05
NVD CVE
CVE-2026-66747: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS,
CRITICAL
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package...
c2cleartext-communicationscommands-and-controlcve-2026-66747endlessdoorfirmwareimplantnvd-cve
2026-08-05
NVD CVE
CVE-2026-17556: A path traversal vulnerability was identified in GitHub Enterprise Server that a
CRITICAL
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage...
2026-08-05
NVD CVE
CVE-2026-16442: A flaw was found in the SAML broker component of Keycloak, which is used to mana
HIGH
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a...
access-controlaccounts-linkingauthenticationcve-2026-16442identity-federationidentity-managementkeycloaklogins-restrictions
2026-08-05
NVD CVE
CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00
HIGH
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event...
authenticationcve-2026-10025event-processingibminjectioninterim-fixesnvd-cveport-514
2026-08-05
NVD CVE
CVE-2026-16443: A flaw was found in the SAML metadata import functionality of the keycloak-servi
HIGH
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata...
authenticationcve-2026-16443forgeryidentity-brokeridentity-providerkeycloakmetadata-importnvd-cve
2026-08-05
NVD CVE
CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv
HIGH
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server...
application-serverarbitrary-code-executionclass-loadingcve-2026-8400ibmibm-sdkiiopjava
2026-08-05
NVD CVE
CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side
HIGH
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
applications-gateways-operatorscustom-resourcecve-2026-17617ibmnvd-cvesecurityservers-sides-requests-forgeryssrf
2026-08-04
NVD CVE
CVE-2026-70554: MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti
CRITICAL
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to...
arbitrary-code-executionmaxsite-cmnvd-cvephp-object-injectionunauthenticated-attacksvulnerability
2026-08-04
NVD CVE
CVE-2026-70552: MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in
CRITICAL
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and...
admins-gated-endpointajax-dispatcherajax-phpauthentication-bypassbase64-encoded-pathscve-2026-70552dangerous-operationheader
2026-08-04
NVD CVE
CVE-2026-70553: MaxSite CMS contains a remote code execution vulnerability that allows unauthent
CRITICAL
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install...
cve-2026-70553nvd-cvephpremote-code-executionvulnerability
2026-08-04
NVD CVE
CVE-2026-69098: kotaemon through 0.12.0 contains an insecure deserialization vulnerability in th
CRITICAL
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON...
application-privilegescve-2026-69098cybersecuritydata-protectionendpointinsecure-deserializationjsonkotaemon
2026-08-04
NVD CVE
CVE-2026-61515: Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated c
CRITICAL
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON...
binary-protocolcommand-injectiondevices-compromisefirmwareip-camerasjson-payloadnetworks-devicesnvd-cve
2026-08-04
NVD CVE
CVE-2026-14175: Unrestricted upload of file with dangerous type vulnerability in Bilin Software
CRITICAL
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue affects...
bilin-softwarecve-2026-14175cybersecurityfiles-uploadhumanists-digital-human-resourcesincident-responseinformatics-consultancynist-800-171
2026-08-04
NVD CVE
CVE-2026-14804: Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat
CRITICAL
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST...
bilin-softwarecryptographic-keyscve-2026-14804cybersecuritydata-encryptiondfar-252-204-7012executablehard-coded-keys
2026-08-04
NVD CVE
CVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge
HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
chromiumcve-2026-66321cybersecuritydefense-industrial-basedfar-252-204-7012information-securitymicrosoftmicrosoft-edge
2026-08-04
NVD CVE
CVE-2026-18685: A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Imp
CRITICAL
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It...
command-injectioncve-2026-18685cybersecurityfirmware-vulnerabilitiesgl-inetgl-mt3000incident-responsemodem-so
2026-08-04
NVD CVE
CVE-2026-18686: A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem
CRITICAL
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in...
command-injectioncve-2026-18686cybersecuritygl-inetgl-mt3000information-securitynas-websnetworks-devices
2026-08-04
NVD CVE
CVE-2026-15721: Cleartext storage of sensitive information vulnerability in Bilin Software and I
CRITICAL
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital Human Resources:...
bilin-softwarecleartext-storagescve-2026-15721data-securityhumanists-digital-human-resourcesinformatics-consultancyinformation-securitynvd-cve
2026-08-04
NVD CVE
CVE-2026-10050: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-
CRITICAL
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.
This was done because the initial specification for HTTP did not specify explicitly a charset, and...
authenticationauthorization-headercve-2026-10050cybersecuritydata-integrityeclipse-jettyinformation-securityiso-8859-1
2026-08-03
NVD CVE
CVE-2026-48333: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation...
accaccess-controladobeadobe-campaign-classiccve-2026-48333cybersecurityincorrect-authorizationinformation-security
2026-08-03
NVD CVE
CVE-2026-48331: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)
CRITICAL
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
adobeadobe-campaign-classiccve-2026-48331cyber-attacksinformation-securitynvd-cveprivileges-escalationsecurities-risks
2026-08-03
NVD CVE
CVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the...
accadobeadobe-campaign-classicapplications-securityarbitrary-code-executioncontrolcve-2026-48330cybersecurity
2026-08-03
NVD CVE
CVE-2026-48326: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the...
accadobeadobe-campaign-classicarbitrary-code-executioncve-2026-48326cybersecuritydata-securityimproper-neutralization
2026-08-03
NVD CVE
CVE-2026-48323: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An...
accadobe-campaign-classicarbitrary-code-executioncode-executioncve-2026-48323cybersecurityimproper-neutralizationnvd-cve
2026-08-03
NVD CVE
CVE-2026-18684: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affe
CRITICAL
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is...
command-injectioncve-2026-18684cybersecuritygl-inetgl-mt3000internetiots-securitymodem-so
2026-08-03
NVD CVE
CVE-2026-48317: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Direct
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the...
adobe-campaign-classicarbitrary-code-executioncode-executioncve-2026-48317cybersecuritydirectivedynamic-code-evaluationeval-injection
2026-08-03
NVD CVE
CVE-2026-18602: A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the
CRITICAL
A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a...
command-injectioncybersecuritygl-inetgl-mt3000native-pluginnetworks-devicesnvd-cveovpn-client
2026-08-03
NVD CVE
CVE-2026-69084: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, whic
CRITICAL
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin...
authenticationcleartext-datumcve-2026-69084cybersecuritydata-exposuredata-modificationencryptionendpoint
2026-08-03
NVD CVE
CVE-2026-39932: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the docu
CRITICAL
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating...
authenticate-administratorcommand-executioncve-2026-39932cybersecuritydatabase-securitydocuments-categories-treeevallibrary-class-tree-class-php
2026-08-03
NVD CVE
CVE-2026-41452: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installe
CRITICAL
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST...
administrator-accountarbitrary-valuesauthenticationcrmcve-2026-41452data-breachesendpointhttp-post
2026-08-03
NVD CVE
CVE-2026-18614: A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func
CRITICAL
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument...
command-injectioncybersecuritygl-inetgl-mt3000networks-devicesnvd-cvepublic-disclosureremote-attacks
2026-08-03
NVD CVE
CVE-2026-18601: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun
CRITICAL
A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the...
command-injectioncve-2026-18601cybersecurityfirmwaregl-inetgl-mt3000native-pluginnetworks-devices
2026-08-03
NVD CVE
CVE-2026-18588: A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affect
CRITICAL
A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote...
buffer-overflowcve-2026-18588cybersecurityfirmwareincident-responsemt7628nas-cginetworks-devices