LIVE FEED
3576 events · 4 sources · newest first
Events in view
3576
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 00:01
UTC
2026-08-04
NVD CVE
CVE-2026-14175: Unrestricted upload of file with dangerous type vulnerability in Bilin Software
CRITICAL
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue affects...
bilin-softwarecve-2026-14175cybersecurityfiles-uploadhumanists-digital-human-resourcesincident-responseinformatics-consultancynist-800-171
2026-08-04
NVD CVE
CVE-2026-14804: Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat
CRITICAL
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST...
bilin-softwarecryptographic-keyscve-2026-14804cybersecuritydata-encryptiondfar-252-204-7012executablehard-coded-keys
2026-08-04
NVD CVE
CVE-2026-70553: MaxSite CMS contains a remote code execution vulnerability that allows unauthent
CRITICAL
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install...
cve-2026-70553nvd-cvephpremote-code-executionvulnerability
2026-08-04
NVD CVE
CVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge
HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
chromiumcve-2026-66321cybersecuritydefense-industrial-basedfar-252-204-7012information-securitymicrosoftmicrosoft-edge
2026-08-04
NVD CVE
CVE-2026-10050: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-
CRITICAL
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.
This was done because the initial specification for HTTP did not specify explicitly a charset, and...
authenticationauthorization-headercve-2026-10050cybersecuritydata-integrityeclipse-jettyinformation-securityiso-8859-1
2026-08-04
NVD CVE
CVE-2026-70554: MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti
CRITICAL
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to...
arbitrary-code-executionmaxsite-cmnvd-cvephp-object-injectionunauthenticated-attacksvulnerability
2026-08-03
CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
actives-exploitationsbinding-operational-directivesbod-26-04cisacisa-advisorycve-2026-18577cyber-attackscyber-security
2026-08-03
NVD CVE
CVE-2026-48331: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)
CRITICAL
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
adobeadobe-campaign-classiccve-2026-48331cyber-attacksinformation-securitynvd-cveprivileges-escalationsecurities-risks
2026-08-03
NVD CVE
CVE-2026-48333: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation...
accaccess-controladobeadobe-campaign-classiccve-2026-48333cybersecurityincorrect-authorizationinformation-security
2026-08-03
NVD CVE
CVE-2026-48326: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the...
accadobeadobe-campaign-classicarbitrary-code-executioncve-2026-48326cybersecuritydata-securityimproper-neutralization
2026-08-03
NVD CVE
CVE-2026-48323: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An...
accadobe-campaign-classicarbitrary-code-executioncode-executioncve-2026-48323cybersecurityimproper-neutralizationnvd-cve
2026-08-03
NVD CVE
CVE-2026-48317: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Direct
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the...
adobe-campaign-classicarbitrary-code-executioncode-executioncve-2026-48317cybersecuritydirectivedynamic-code-evaluationeval-injection
2026-08-03
NVD CVE
CVE-2026-18616: A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted el
CRITICAL
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the...
command-injectioncve-2026-18616cybersecurityfirmwaregl-inetgl-mt3000native-pluginnetworks-devices
2026-08-03
NVD CVE
CVE-2026-18684: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affe
CRITICAL
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is...
command-injectioncve-2026-18684cybersecuritygl-inetgl-mt3000internetiots-securitymodem-so
2026-08-03
NVD CVE
CVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the...
accadobeadobe-campaign-classicapplications-securityarbitrary-code-executioncontrolcve-2026-48330cybersecurity
2026-08-03
NVD CVE
CVE-2026-41452: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installe
CRITICAL
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST...
administrator-accountarbitrary-valuesauthenticationcrmcve-2026-41452data-breachesendpointhttp-post
2026-08-03
NVD CVE
CVE-2026-18602: A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the
CRITICAL
A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a...
command-injectioncybersecuritygl-inetgl-mt3000native-pluginnetworks-devicesnvd-cveovpn-client
2026-08-03
NVD CVE
CVE-2026-39932: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the docu
CRITICAL
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating...
authenticate-administratorcommand-executioncve-2026-39932cybersecuritydatabase-securitydocuments-categories-treeevallibrary-class-tree-class-php
2026-08-03
NVD CVE
CVE-2026-69084: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, whic
CRITICAL
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin...
authenticationcleartext-datumcve-2026-69084cybersecuritydata-exposuredata-modificationencryptionendpoint
2026-08-03
CISA KEV
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for...
accounts-takeoveralternate-pathsauthentication-bypasschannelcisa-kevcve-2026-18556cve-2026-18577cybersecurity
2026-08-03
NVD CVE
CVE-2026-18601: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun
CRITICAL
A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the...
command-injectioncve-2026-18601cybersecurityfirmwaregl-inetgl-mt3000native-pluginnetworks-devices
2026-08-03
NVD CVE
CVE-2026-18589: A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the
CRITICAL
A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The...
cve-2026-18589firmwaremt7628nas-cginas-devicesnetworks-devicesnvd-cvepublic-disclosure
2026-08-03
NVD CVE
CVE-2026-18588: A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affect
CRITICAL
A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote...
buffer-overflowcve-2026-18588cybersecurityfirmwareincident-responsemt7628nas-cginetworks-devices
2026-08-03
NVD CVE
CVE-2026-68979: Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me
CRITICAL
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change...
apache-nifiauthorization-checkscode-executioncomponent-level-authorizationcve-2026-68979nifi-2110nvd-cveparameters-context
2026-08-03
NVD CVE
CVE-2026-18614: A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func
CRITICAL
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument...
command-injectioncybersecuritygl-inetgl-mt3000networks-devicesnvd-cvepublic-disclosureremote-attacks
2026-08-03
NVD CVE
CVE-2026-68980: Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets
CRITICAL
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context...
apache-nifiasset-managementcvecve-2026-68980nvd-cveparameters-contextrest-apisecurity-boundaries
2026-08-02
NVD CVE
CVE-2026-65321: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unau
CRITICAL
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes...
ctum-controldatum-exfiltrationdestructive-statementsnvd-cvepyathenasql-injectionunauthenticated-attacksunion-select
2026-08-02
NVD CVE
CVE-2026-8457: The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat
CRITICAL
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and...
apple-loginauthentication-bypasscve-2026-8457id-tokenjwtjwts-signaturenvd-cveplugins-vulnerabilities
2026-08-02
NVD CVE
CVE-2026-68579: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W
CRITICAL
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe)...
bound-writebuffer-overflowclipboardcve-2026-68579heap-based-buffer-overflownvd-cveole-paste-consumersout
2026-08-01
NVD CVE
CVE-2026-67324: GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value>
CRITICAL
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced...
clones-vulnerabilitiescode-executioncommand-injectioncve-2026-67324git-clonegit-securitygitpythonnvd-cve
2026-08-01
NVD CVE
CVE-2026-67330: @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.
CRITICAL
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs...
accounts-takeoverauthentication-bypassauthorization-bypassbetters-authscompliance-riskcve-2026-67330data-integrityidentity-management
2026-08-01
NVD CVE
CVE-2026-67340: ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host
CRITICAL
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user...
arcadedbarcadedb-engineauthenticates-accessescommand-injectioncve-2026-67340databases-vulnerabilitiesjava-runtime-execjava-security
2026-08-01
NVD CVE
CVE-2026-67341: ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o
CRITICAL
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting...
arbitrary-code-executionarcadedbcompliance-riskcve-2026-67341database-administrationdatabase-securitydefensives-programmingsincident-response
2026-08-01
NVD CVE
CVE-2026-67308: Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub
CRITICAL
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can...
aws-credentialcode-injectioncommand-executioncve-2026-67308environment-variablesgithub-actionsgithub-tokennvd-cve
2026-08-01
NVD CVE
CVE-2026-15964: The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication
CRITICAL
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function —...
authentication-bypassauthorization-checkscve-2026-15964incident-responsenoncenvd-cvepassword-resetplugins-vulnerabilities
2026-08-01
NVD CVE
CVE-2026-66402: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif
CRITICAL
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP...
certificate-chaincommon-names-matchingcve-2026-66402dns-sanencryptionfreerdpidentity-validationmisissued-certificate
2026-08-01
NVD CVE
CVE-2026-67289: FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c
CRITICAL
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname...
control-charactercrlf-injectioncryptographycve-2026-67289freerdpheaders-injectionhttps-proxynetwork-security
2026-08-01
NVD CVE
CVE-2026-67342: ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in
CRITICAL
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers...
access-controlarcadedbauthorization-bypassbatch-processingcve-2026-67342database-accessdatabase-permissionsendpoint-security
2026-08-01
NVD CVE
CVE-2026-3141: The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d
CRITICAL
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and...
arbitrary-file-deletionauthentication-bypasscisas-alertcmmc-level-2compliance-riskcve-2026-3141dodincident-response
2026-07-31
NVD CVE
CVE-2026-17351: The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query pas
CRITICAL
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running...
cve-2026-17351enforcementfalse-claim-actfedramp-authorizationincident-responsemulti-statementnvd-cvepgadmin