Skip to content
COOEY
LIVE FEED
1821 events · 4 sources · newest first
2026-07-30 NVD CVE
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
authentication-bypasscisacmmc-level-2compliancecve-2026-28323defense-industrial-basedodfedramp-authorization
2026-07-30 NVD CVE
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request...
compliance-riskcve-2026-15435directories-traversalfile-writeibm-apps-connect-enterprisenvd-cveremote-code-executionsecurity-patch
2026-07-30 NVD CVE
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is...
api-enumerationapi-vulnerabilitiesauthentication-bypasscapiauth-middlewarecommit-e1cdf8ccve-2026-67594database-user-creationfile-write
2026-07-30 NVD CVE
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user...
adobe-campaign-classicarbitrary-code-executioncisacode-executioncve-2026-48449defense-industrial-basedodincorrect-authorization
2026-07-30 NVD CVE
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed...
audit-logsauthentication-bypassconfiguration-changescontents-security-policycross-site-scriptingcve-2026-66418endpoint-accessesfailed-login
2026-07-30 NVD CVE
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup...
admins-endpointsagents-transcriptscooeycross-site-scriptingcve-2026-66421html-injectionjavascript-executionnvd-cve
2026-07-29 NVD CVE
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes...
admin-account-creationcve-2025-10656cve-disclosurese-commercelights-pluginmissing-authorizationnvd-cveplugins-vulnerabilities
2026-07-29 NVD CVE
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.
administrator-credentialscisacmmc-level-2compliance-riskcve-2026-18191devices-vulnerabilitiesdfar-252-204-7012dod
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative...
2026-07-29 NVD CVE
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
2026-07-29 NVD CVE
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15...
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding...
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
2026-07-29 NVD CVE
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by...
ammo-instrument-toolkitarbitrary-command-executionauthentication-bypasscommand-buscommand-injectioncve-2026-60112defensives-mitigationsmissing-authentication
2026-07-29 NVD CVE
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network...
ammoapi-exposureauthentication-vulnerabilitycisacve-2026-60113deep-space-networkdefense-industrial-basehttps-requests
2026-07-29 NVD CVE
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the...
arbitrary-deletionauthorization-bypasscisaciscocve-2026-14488frontend-submissionmeta-boxmissing-authorization
2026-07-29 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature...
applications-securitycve-2026-14529cybersecuritydefense-industrial-basedfar-252-204-7012ibmnist-800-171nvd-cve
2026-07-29 NVD CVE
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the...
authentication-bypasscode-injectioncve-2026-14900eval-exploitnonce-checksnvd-cvephp-evalplugins-vulnerabilities
2026-07-29 NVD CVE
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by...
administrative-accesscares-everywhere-gatewayscmmccompliance-riskcve-2026-41939defense-industrial-basedeployment-interfacesend
2026-07-29 NVD CVE
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists...
administrator-privilegesadvanced-responsive-video-embedderauthentication-bypasscve-2026-18072cybersecuritydeveloper-account-compromisehardcoded-credentialkick
2026-07-28 NVD CVE
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
asperaauthenticationcve-2026-14959cybersecurityfaspexibmnvd-cvepatch-management
2026-07-28 NVD CVE
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
asperacve-2026-14973cybersecuritydata-integritydata-lossesdesktop-applicationsdownloads-destinationfile-integrity
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
applications-securityauthentication-bypasscve-2026-14512cybersecuritydata-protectiondefense-industrial-basedfar-252-204-7012ibm
2026-07-28 NVD CVE
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
asperaauthenticationcve-2026-14958cybersecurityfaspexibmnvd-cvepatch-management
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
administrative-consolebroken-access-controlcve-2026-14446cybersecuritydefense-industrial-basedfar-252-204-7012ibmincident-response
2026-07-28 NVD CVE
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including,...
accounts-takeoverauthenticationauthentication-bypassbilling-phonecve-2026-15014cybersecuritydefense-industrial-basedfar-252-204-7012
2026-07-28 NVD CVE
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
arbitrary-code-executioncritical-infrastructurecve-2026-16462cybersecuritydata-breachesendpoint-securityindustrial-control-systemnvd-cve
2026-07-27 NVD CVE
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
apache-thriftbuffer-overflowccve-2026-55971cyber-securitydfar-252-204-7012heap-based-buffer-overflowincident-response
2026-07-27 NVD CVE
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes...
apacheapache-thriftc-glibcertificate-validationcve-2026-48144cybersecurityhost-mismatchinformation-security
2026-07-27 NVD CVE
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
apache-thriftbound-readc-glib-bindingscve-2026-58023cybersecuritydfar-252-204-7012incident-responsenist-800-171
2026-07-27 NVD CVE
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version...
apache-thriftbound-readccve-2026-58662cyber-securitydefense-industrial-basedod-supply-chainimproper-input-validation
2026-07-25 NVD CVE
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This...
accesses-auth-codeadministrators-takeoveradmins-role-enforcementapi-tokenarbitrary-files-writingconf-conf-jsoncontext-isolationcookie-keys-plaintext
2026-07-24 NVD CVE
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
azure-portalscve-2026-62835improper-authorizationinformation-disclosurenetworknvd-cveunauthorized-access
2026-07-24 NVD CVE
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
azure-keys-vaultcybersecurityimproper-authenticationnetworks-attacksnvd-cveprivileges-escalationunauthorized-accessvulnerability
2026-07-24 NVD CVE
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
authorize-attackersexecutable-codeimproper-input-validationmicrosoft-surfacenetworknvd-cvevulnerability
2026-07-24 NVD CVE
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
azure-app-serviceazure-security-vulnerabilityimproper-access-controlnetworks-attacksnvd-cveunauthorized-privileges-escalation
2026-07-24 NVD CVE
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
buffer-overflowcve-2026-56165malware-attacksmicrosoft-accountsnetwork-executionnvd-cveunauthorized-access
2026-07-24 NVD CVE
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
authorize-attackersazure-red-hat-openshiftimproper-authorizationnetworknvd-cveprivileges-elevationvulnerability
2026-07-24 NVD CVE
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
azure-dnscve-2026-58275missing-authorizationnetworks-compromisenvd-cveprivileges-elevationunauthorized-attacks
◀ PREV PAGE 11 / 46 NEXT ▶