Skip to content
COOEY
LIVE FEED
3576 events · 4 sources · newest first
2026-07-30 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
cfs-health-safety-applicationscisa-advisorycisa-ics-advisoriescontrol-systemcritical-infrastructurecve-2026-15352cve-2026-18064cwe-476
2026-07-30 NVD CVE
Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
2026-07-29 NVD CVE
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apacheapache-traffic-serverscache-corruptioncve-2026-58163data-integritydata-lossesincident-responsenvd-cve
2026-07-29 NVD CVE
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apache-traffic-serverscve-2026-58179cve-disclosuresinteger-overflownvd-cveregex-remap-pluginssecurity-patchsoftware
2026-07-29 NVD CVE
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to...
apache-softwaresapache-traffic-serverscritical-vulnerabilitycve-2026-58185freeintercept-pluginmemory-safetynvd-cve
2026-07-29 NVD CVE
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade...
apache-traffic-serversbound-writecmmccritical-patchescve-2026-58177defense-industrial-basefedrampfree
2026-07-29 NVD CVE
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by...
administrative-accesscares-everywhere-gatewayscmmccompliance-riskcve-2026-41939defense-industrial-basedeployment-interfacesend
2026-07-29 CISA KEV
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an...
cisa-kevciscocmmccompliance-riskcve-2026-20316defense-industrial-basefirepower-management-centerfirewall
2026-07-29 NVD CVE
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists...
administrator-privilegesadvanced-responsive-video-embedderauthentication-bypasscve-2026-18072cybersecuritydeveloper-account-compromisehardcoded-credentialkick
2026-07-29 NVD CVE
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the...
arbitrary-deletionauthorization-bypasscisaciscocve-2026-14488frontend-submissionmeta-boxmissing-authorization
2026-07-29 NVD CVE
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes...
admin-account-creationcve-2025-10656cve-disclosurese-commercelights-pluginmissing-authorizationnvd-cveplugins-vulnerabilities
2026-07-29 NVD CVE
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the...
authentication-bypasscode-injectioncve-2026-14900eval-exploitnonce-checksnvd-cvephp-evalplugins-vulnerabilities
2026-07-29 NVD CVE
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.
administrator-credentialscisacmmc-level-2compliance-riskcve-2026-18191devices-vulnerabilitiesdfar-252-204-7012dod
2026-07-29 NVD CVE
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network...
ammoapi-exposureauthentication-vulnerabilitycisacve-2026-60113deep-space-networkdefense-industrial-basehttps-requests
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative...
2026-07-29 NVD CVE
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15...
2026-07-29 NVD CVE
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
2026-07-29 CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
binding-operational-directivesbod-26-04cisacisa-advisoryciscocve-2026-20316cyber-securityexploit-vulnerabilities
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
2026-07-29 NVD CVE
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such...
cache-controlcaches-interceptorscve-2026-13697errors-handlinghttps-headersinformation-disclosuremalformed-headersnvd-cve
2026-07-29 CISA advisory
<p>CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance,&nbsp;<a...
2026-sbomartificial-intelligence-softwarecisa-advisorycisa-guidancescloud-softwarematerialntia-sbomrisk-management
2026-07-29 NVD CVE
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by...
ammo-instrument-toolkitarbitrary-command-executionauthentication-bypasscommand-buscommand-injectioncve-2026-60112defensives-mitigationsmissing-authentication
2026-07-29 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature...
applications-securitycve-2026-14529cybersecuritydefense-industrial-basedfar-252-204-7012ibmnist-800-171nvd-cve
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding...
2026-07-28 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>OpenSSL has published a stack based buffer...
buffer-overflowcisacisa-advisorycritical-infrastructurecve-2025-15467cyber-attackscybersecuritydenial
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
administrative-consolebroken-access-controlcve-2026-14446cybersecuritydefense-industrial-basedfar-252-204-7012ibmincident-response
2026-07-28 NVD CVE
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
asperaauthenticationcve-2026-14959cybersecurityfaspexibmnvd-cvepatch-management
2026-07-28 NVD CVE
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
asperacve-2026-14973cybersecuritydata-integritydata-lossesdesktop-applicationsdownloads-destinationfile-integrity
2026-07-28 NVD CVE
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
asperaauthenticationcve-2026-14958cybersecurityfaspexibmnvd-cvepatch-management
2026-07-28 CISA advisory
<div class="c-page-title__buttons"><a class="c-button" href="https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems"...
australian-signals-directoratecisacisa-advisorycritical-infrastructurecyber-security-centrecyber-threatscybersecurityfederal-bureau
2026-07-28 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>SIMATIC S7-PLCSIM Advanced contains a...
cisacisa-advisorycritical-infrastructurecritical-manufacturingcve-2026-54429cwes-770cybersecuritydefense
2026-07-28 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
access-controlandroidauthenticationbackend-servicescisacisa-advisorycommercial-facilitycve-2026-16581
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
applications-securityauthentication-bypasscve-2026-14512cybersecuritydata-protectiondefense-industrial-basedfar-252-204-7012ibm
2026-07-28 NVD CVE
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including,...
accounts-takeoverauthenticationauthentication-bypassbilling-phonecve-2026-15014cybersecuritydefense-industrial-basedfar-252-204-7012
2026-07-28 NVD CVE
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
arbitrary-code-executioncritical-infrastructurecve-2026-16462cybersecuritydata-breachesendpoint-securityindustrial-control-systemnvd-cve
2026-07-28 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Multiple vulnerabilities have been identified in...
cisa-advisory
2026-07-28 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
account-lockoutauthenticationbrute-forcecisacisa-advisorycloud-hosted-routerscommercial-facilitycritical-infrastructure
2026-07-28 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Mendix documentation for access rules does not...
access-rulescisacisa-advisorycritical-infrastructurecritical-manufacturingcve-2026-7891cwe-277cybersecurity
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
applications-securityauthentication-bypasscve-2026-16184cybersecuritydata-protectiondefense-industrial-baseibmnist-800-171
◀ PREV PAGE 14 / 90 NEXT ▶