LIVE FEED
3576 events · 4 sources · newest first
Events in view
3576
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 06:00
UTC
2026-07-28
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Mendix documentation for access rules does not...
access-rulescisacisa-advisorycritical-infrastructurecritical-manufacturingcve-2026-7891cwe-277cybersecurity
2026-07-28
NVD CVE
CVE-2026-16462: In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a
CRITICAL
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
arbitrary-code-executioncritical-infrastructurecve-2026-16462cybersecuritydata-breachesendpoint-securityindustrial-control-systemnvd-cve
2026-07-28
NVD CVE
CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b
HIGH
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
applications-securityauthentication-bypasscve-2026-16184cybersecuritydata-protectiondefense-industrial-baseibmnist-800-171
2026-07-27
NVD CVE
CVE-2026-58023: Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue a
CRITICAL
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
apache-thriftbound-readc-glib-bindingscve-2026-58023cybersecuritydfar-252-204-7012incident-responsenist-800-171
2026-07-27
NVD CVE
CVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal reque
HIGH
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
access-controlauthentication-weaknessescompliance-riskcve-2026-66014internal-requests-processingjfrog-artifactorynvd-cveprivileges-escalation
2026-07-27
CISA KEV
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency...
cisa-kevcve-2025-68686cybersecurityexposurefilesystem-levelfortinetfortiohttps-requests
2026-07-27
CISA advisory
<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
aristabod-26-04cisacisa-advisorycvecve-2025-68686cve-2026-16812cyber-attacks
2026-07-27
NVD CVE
CVE-2026-58662: Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerabi
CRITICAL
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version...
apache-thriftbound-readccve-2026-58662cyber-securitydefense-industrial-basedod-supply-chainimproper-input-validation
2026-07-27
CISA KEV
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may...
aristaavailabilitycisa-kevcommand-injectionconfidentialitycve-2026-16812data-compromiseintegrity
2026-07-27
NVD CVE
CVE-2026-48144: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th
CRITICAL
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes...
apacheapache-thriftc-glibcertificate-validationcve-2026-48144cybersecurityhost-mismatchinformation-security
2026-07-27
NVD CVE
CVE-2026-55971: Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This is
CRITICAL
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
apache-thriftbuffer-overflowccve-2026-55971cyber-securitydfar-252-204-7012heap-based-buffer-overflowincident-response
2026-07-27
NVD CVE
CVE-2026-45623: PostCSS takes a CSS file and provides an API to analyze and modify its rules by
HIGH
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH...
2026-07-25
NVD CVE
CVE-2026-66012: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST
CRITICAL
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This...
accesses-auth-codeadministrators-takeoveradmins-role-enforcementapi-tokenarbitrary-files-writingconf-conf-jsoncontext-isolationcookie-keys-plaintext
2026-07-24
NVD CVE
CVE-2026-58275: Missing authorization in Azure DNS allows an unauthorized attacker to elevate pr
CRITICAL
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
azure-dnscve-2026-58275missing-authorizationnetworks-compromisenvd-cveprivileges-elevationunauthorized-attacks
2026-07-24
NVD CVE
CVE-2026-56191: Improper authentication in Microsoft Exchange Online allows an unauthorized atta
CRITICAL
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
cve-2026-56191improper-authenticationmicrosoft-exchange-onlinenetworks-tamperingnvd-cveunauthorized-access
2026-07-24
NVD CVE
CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to
CRITICAL
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
azure-app-serviceazure-security-vulnerabilityimproper-access-controlnetworks-attacksnvd-cveunauthorized-privileges-escalation
2026-07-24
NVD CVE
CVE-2026-62835: Improper authorization in Azure Portal allows an unauthorized attacker to disclo
CRITICAL
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
azure-portalscve-2026-62835improper-authorizationinformation-disclosurenetworknvd-cveunauthorized-access
2026-07-24
NVD CVE
CVE-2026-56160: Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att
CRITICAL
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
authorize-attackersazure-red-hat-openshiftimproper-authorizationnetworknvd-cveprivileges-elevationvulnerability
2026-07-24
NVD CVE
CVE-2026-62825: Improper authentication in Azure Key Vault allows an unauthorized attacker to el
CRITICAL
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
azure-keys-vaultcybersecurityimproper-authenticationnetworks-attacksnvd-cveprivileges-escalationunauthorized-accessvulnerability
2026-07-24
NVD CVE
CVE-2026-50517: Deserialization of untrusted data in M365 Copilot allows an authorized attacker
CRITICAL
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
authorize-attackerscode-executioncve-2026-50517deserializationm365-copilotnetworknvd-cveuntrusted-data
2026-07-24
NVD CVE
CVE-2026-54120: Improper input validation in Microsoft Surface allows an authorized attacker to
CRITICAL
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
authorize-attackersexecutable-codeimproper-input-validationmicrosoft-surfacenetworknvd-cvevulnerability
2026-07-24
NVD CVE
CVE-2026-56165: Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker
CRITICAL
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
buffer-overflowcve-2026-56165malware-attacksmicrosoft-accountsnetwork-executionnvd-cveunauthorized-access
2026-07-23
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
cisa-advisorycleartext-storagescritical-manufacturingcvss-v3cwes-312enforcementfalse-claim-actfedramp-authorization
2026-07-23
NVD CVE
CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s
HIGH
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
2026-07-23
NVD CVE
CVE-2026-15981: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen
CRITICAL
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose...
authentication-bypasscve-2026-15981nvd-cveopenssl-verifysaml-ssovulnerabilitywordpress-plugin
2026-07-23
NVD CVE
CVE-2025-71389: Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote co
CRITICAL
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes...
attack-controlled-inputcalcomcve-2025-55182cve-2025-71389dependencynextjnvd-cverce
2026-07-23
NVD CVE
CVE-2024-58354: cal.com (calcom repository, later renamed cal.diy) is affected by a repository t
CRITICAL
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's...
arbitrary-commandscalcomcheck-typesymldangerous-git-checkoutgithub-actionsgithub-tokennvd-cvepull-request
2026-07-23
NVD CVE
CVE-2026-63732: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcode
CRITICAL
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host...
9routercode-executiondefault-passwordhost-operating-systemsmalicious-pluginsnetworks-gatesnvd-cvespoofing
2026-07-23
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-06.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities...
cisacisa-advisorycritical-infrastructurecve-2026-49035cve-2026-50032cve-2026-50039cve-2026-50103cybersecurity
2026-07-23
NVD CVE
CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in
HIGH
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd-cve
2026-07-23
NVD CVE
CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This
HIGH
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
cisacmmc-level-2compliancecve-2026-15967defense-industrial-basedodfedramp-authorizationincident-response
2026-07-23
NVD CVE
CVE-2026-65700: h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compa
CRITICAL
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process...
021cve-2026-65700file-apih2ogptnvd-cveopenai-compatiblepath-traversalremote-code-execution
2026-07-23
NVD CVE
CVE-2026-65689: Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepa
CRITICAL
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the...
cve-2026-65689file-readingnvd-cvepath-traversalserver-filesystemunauthenticated-accessesvulnerability
2026-07-23
NVD CVE
CVE-2026-64815: In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible v
HIGH
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
arbitrary-code-injectioncode-injectioncve-2026-64815cybersecuritydevelopers-toolsform-fileintellij-ideajetbrain
2026-07-23
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-07.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
bound-readcisacisa-advisorycisagovcve-2026-16002cvss-v3cwes-125denial
2026-07-23
NVD CVE
CVE-2026-14282: The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folde
CRITICAL
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This...
arbitrary-files-uploadcve-2026-14282nvd-cveremote-code-executionunauthenticated-attacksvulnerabilitywordpresswpform
2026-07-23
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities...
application-servercisa-advisorycmmccompliancecyber-attackscybersecurityfederal-contractornetwork-security
2026-07-23
NVD CVE
CVE-2026-15011: The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable
CRITICAL
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on...
code-injectioncve-2026-15011nvd-cvesensitive-information-exposuresite-functionalityunauthenticated-attacksvulnerabilitywordpress-plugin
2026-07-23
NVD CVE
CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue a
HIGH
Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
authentication-bypasscisacmmc-level-2cve-2026-10697datum-exfiltrationdodfedramp-authorizationimproper-authentication
2026-07-23
NVD CVE
CVE-2026-15015: The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable t
CRITICAL
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is...
administrator-equivalent-accessauthorization-bypasscve-2026-15015nvd-cveoauth-bearer-tokenunauthenticated-accessesvulnerabilitywordpress-content