LIVE FEED
1767 events · 4 sources · newest first
Events in view
1767
all sources
Critical
1492
severity
Active sources
4
collectors
Last sync
2026-08-26 00:01
UTC
2026-08-03
NVD CVE
CVE-2026-68979: Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me
CRITICAL
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change...
apache-nifiauthorization-checkscode-executioncomponent-level-authorizationcve-2026-68979nifi-2110nvd-cveparameters-context
2026-08-03
NVD CVE
CVE-2026-68980: Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets
CRITICAL
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context...
apache-nifiasset-managementcvecve-2026-68980nvd-cveparameters-contextrest-apisecurity-boundaries
2026-08-03
NVD CVE
CVE-2026-18614: A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func
CRITICAL
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument...
command-injectioncybersecuritygl-inetgl-mt3000networks-devicesnvd-cvepublic-disclosureremote-attacks
2026-08-03
NVD CVE
CVE-2026-48333: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation...
accaccess-controladobeadobe-campaign-classiccve-2026-48333cybersecurityincorrect-authorizationinformation-security
2026-08-02
NVD CVE
CVE-2026-65321: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unau
CRITICAL
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes...
ctum-controldatum-exfiltrationdestructive-statementsnvd-cvepyathenasql-injectionunauthenticated-attacksunion-select
2026-08-02
NVD CVE
CVE-2026-8457: The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat
CRITICAL
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and...
apple-loginauthentication-bypasscve-2026-8457id-tokenjwtjwts-signaturenvd-cveplugins-vulnerabilities
2026-08-02
NVD CVE
CVE-2026-68579: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W
CRITICAL
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe)...
bound-writebuffer-overflowclipboardcve-2026-68579heap-based-buffer-overflownvd-cveole-paste-consumersout
2026-08-01
NVD CVE
CVE-2026-67341: ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o
CRITICAL
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting...
arbitrary-code-executionarcadedbcompliance-riskcve-2026-67341database-administrationdatabase-securitydefensives-programmingsincident-response
2026-08-01
NVD CVE
CVE-2026-67308: Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub
CRITICAL
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can...
aws-credentialcode-injectioncommand-executioncve-2026-67308environment-variablesgithub-actionsgithub-tokennvd-cve
2026-08-01
NVD CVE
CVE-2026-67324: GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value>
CRITICAL
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced...
clones-vulnerabilitiescode-executioncommand-injectioncve-2026-67324git-clonegit-securitygitpythonnvd-cve
2026-08-01
NVD CVE
CVE-2026-67330: @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.
CRITICAL
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs...
accounts-takeoverauthentication-bypassauthorization-bypassbetters-authscompliance-riskcve-2026-67330data-integrityidentity-management
2026-08-01
NVD CVE
CVE-2026-67289: FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c
CRITICAL
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname...
control-charactercrlf-injectioncryptographycve-2026-67289freerdpheaders-injectionhttps-proxynetwork-security
2026-08-01
NVD CVE
CVE-2026-67342: ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in
CRITICAL
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers...
access-controlarcadedbauthorization-bypassbatch-processingcve-2026-67342database-accessdatabase-permissionsendpoint-security
2026-08-01
NVD CVE
CVE-2026-67340: ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host
CRITICAL
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user...
arcadedbarcadedb-engineauthenticates-accessescommand-injectioncve-2026-67340databases-vulnerabilitiesjava-runtime-execjava-security
2026-08-01
NVD CVE
CVE-2026-3141: The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d
CRITICAL
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and...
arbitrary-file-deletionauthentication-bypasscisas-alertcmmc-level-2compliance-riskcve-2026-3141dodincident-response
2026-08-01
NVD CVE
CVE-2026-15964: The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication
CRITICAL
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function —...
authentication-bypassauthorization-checkscve-2026-15964incident-responsenoncenvd-cvepassword-resetplugins-vulnerabilities
2026-08-01
NVD CVE
CVE-2026-66402: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif
CRITICAL
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP...
certificate-chaincommon-names-matchingcve-2026-66402dns-sanencryptionfreerdpidentity-validationmisissued-certificate
2026-07-31
NVD CVE
CVE-2026-18452: DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v
CRITICAL
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
api-key-exploitationcisacmmc-level-2compliance-riskcve-2026-18452device-controldm-plusdod
2026-07-31
NVD CVE
CVE-2026-17351: The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query pas
CRITICAL
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running...
cve-2026-17351enforcementfalse-claim-actfedramp-authorizationincident-responsemulti-statementnvd-cvepgadmin
2026-07-31
NVD CVE
CVE-2026-17561: Improper Control of Generation of Code ('Code Injection') vulnerability in Innot
CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.
This issue affects Logsign SIEM:...
cmmccode-injectioncompliancecve-2026-17561defense-industrial-baseincident-responseinnotimlogsign-siem
2026-07-31
NVD CVE
CVE-2026-14483: The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner
CRITICAL
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type...
api-key-exposurearbitrary-files-uploadcve-2026-14483missing-file-validationnvd-cveplugin-seed-credentialspublic-endpointrealtynum-organics-idx
2026-07-31
NVD CVE
CVE-2026-68770: sentence-transformers contains a security control bypass vulnerability that allo
CRITICAL
sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within...
arbitrary-code-executioncode-executioncve-2026-68770import-modules-classesimport-timeloading-processlogic-flawmodel-directory
2026-07-31
NVD CVE
CVE-2026-68771: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai
CRITICAL
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and...
ai-model-toolarbitrary-code-executioncomfyuicve-2026-68771cve-disclosuresimages-uploadnvd-cvepickle-vulnerability
2026-07-31
NVD CVE
CVE-2026-14537: Incorrect Authorization in the direct HTTP API tool invocation endpoint in Googl
CRITICAL
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via...
cve-2026-14537cybersecurityenable-api-flagsgooglehttps-apiincorrect-authorizationinformation-securitylegacy-endpoint
2026-07-31
NVD CVE
CVE-2026-21662: Unrestricted upload of file with dangerous type vulnerability in Johnson Control
CRITICAL
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.
This issue affects FM Systems Employee: before 2025.3.1.
2026-07-30
NVD CVE
CVE-2026-44101: Due to missing authentication the CHARX OCPP Agent service allows an unauthentic
CRITICAL
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to...
authenticationbackends-reconfigurationscharging-station-securitycharxcompliance-riskcve-2026-44101data-disclosuredenial
2026-07-30
NVD CVE
CVE-2026-13379: The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remot
CRITICAL
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process
2026-07-30
NVD CVE
CVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with s
CRITICAL
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
2026-07-30
NVD CVE
CVE-2026-66421: OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all
CRITICAL
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup...
admins-endpointsagents-transcriptscooeycross-site-scriptingcve-2026-66421html-injectionjavascript-executionnvd-cve
2026-07-30
NVD CVE
CVE-2026-15435: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
CRITICAL
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request...
compliance-riskcve-2026-15435directories-traversalfile-writeibm-apps-connect-enterprisenvd-cveremote-code-executionsecurity-patch
2026-07-30
NVD CVE
CVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for
CRITICAL
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
82x-befores-823383x-befores-833384x-befores-842485x-befores-859cve-2026-17543nvd-cvephp-vulnerabilitiessql-injection
2026-07-30
NVD CVE
CVE-2026-66756: Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue
CRITICAL
Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
2026-07-30
NVD CVE
CVE-2026-12118: IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated
CRITICAL
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
arbitrary-code-executioncode-executioncve-2026-12118deserializationdeserialization-vulnerabilitiesibmintegration-softwarenvd-cve
2026-07-30
NVD CVE
CVE-2026-67208: Juggle through 1.6.0 contains a remote code execution vulnerability that allows
CRITICAL
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default...
compliance-riskcve-2026-67208default-credentialsdockerh2-databaseincident-responsejugglenvd-cve
2026-07-30
NVD CVE
CVE-2026-66418: OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t
CRITICAL
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed...
audit-logsauthentication-bypassconfiguration-changescontents-security-policycross-site-scriptingcve-2026-66418endpoint-accessesfailed-login
2026-07-30
NVD CVE
CVE-2026-67594: Spikster through commit e1cdf8c contains a missing authentication vulnerability
CRITICAL
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is...
api-enumerationapi-vulnerabilitiesauthentication-bypasscapiauth-middlewarecommit-e1cdf8ccve-2026-67594database-user-creationfile-write
2026-07-30
NVD CVE
CVE-2026-44100: The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig
CRITICAL
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
charging-infrastructurecharging-pointcharxcve-2026-44100denialfiles-tamperingjupicorenvd-cve
2026-07-30
NVD CVE
CVE-2026-28323: SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass
CRITICAL
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
authentication-bypasscisacmmc-level-2compliancecve-2026-28323defense-industrial-basedodfedramp-authorization
2026-07-30
NVD CVE
CVE-2026-7849: Due to improper neutralization of special elements, an unauthenticated remote at
CRITICAL
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
cmmccommand-injectionconfigurations-vulnerabilitiescve-2026-7849defense-industrial-baseneutralization-failurenist-800-171nvd-cve
2026-07-30
NVD CVE
CVE-2026-44108: Due to a flaw in the execution order of scripts during shutdown, the firewall is
CRITICAL
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally...
cisacmmc-level-2cve-2026-44108dodfirewallincident-responseinternal-servicesnetwork-security