Skip to content
COOEY
LIVE FEED
1821 events · 4 sources · newest first
2026-07-16 NVD CVE
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
cve-2023-49900exploitincorrectly-sanitize-inputsnvd-cveremote-attackersremote-code-executionsecurity-bulletinsetparameter-command
2026-07-16 NVD CVE
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer...
brute-forcecredentials-theftcryptographic-weaknessescve-2026-63089impersonationnvd-cveone-time-linkpreshared-key
2026-07-16 NVD CVE
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
command-executioncommunications-channelscve-2023-49899nvd-cveorigin-verificationremote-attackerssecurityunauthenticate
2026-07-16 NVD CVE
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because...
authentication-bypasscve-2026-15013nvd-cvesamlsaml-signatures-algorithms-confusionsingle-signssowordpress
2026-07-16 NVD CVE
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to...
cve-2026-45568cybersecurityflaskincident-responseinformation-disclosurenetwork-resourcesnvd-cveproxy
2026-07-15 NVD CVE
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a...
2026-07-15 NVD CVE
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's...
ai-assistantauthorization-headercredentials-exposurecve-2026-54052data-breacheshttps-modemcp-servermulti-tenancy
2026-07-15 NVD CVE
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession...
accesses-tokenauthenticationauthorizationbetters-authsclient-idclients-secretscve-2026-53512mcp-plugins
2026-07-14 NVD CVE
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
2026-07-14 NVD CVE
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller...
2026-07-14 NVD CVE
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an...
access-controlapplications-securityauthentication-bypasscve-2026-56451cve-trackingsimpersonationjson-web-tokenjwt-forges
2026-07-14 NVD CVE
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an...
apus-exploitationscompliance-riskconfidentiality-impactcredentials-exposurecve-2026-44761data-integrityhelp-portalnvd-cve
2026-07-14 NVD CVE
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system...
abapauthenticate-attackeravailabilitycmmcconfidentialitycve-2026-44747data-accessdefense-industrial-base
2026-07-14 NVD CVE
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the...
availability-impactconfidentiality-impactcve-2026-27690https-requests-smugglingnvd-cverequests-responses-desynchronizationsap-approutersecurity-vulnerability
2026-07-14 NVD CVE
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
adobearbitrary-code-executioncve-2026-48334illustratorimproper-input-validationmalicious-filesnvd-cvesecurity
2026-07-14 NVD CVE
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope...
arbitrary-code-executioncoldfusioncve-2026-48327exploitincorrect-authorizationnvd-cvesecurityvulnerability
2026-07-14 NVD CVE
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
arbitrary-code-executioncoldfusioncritical-functionscve-2026-48325exploitmissing-authenticationnvd-cvesecurity
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncoldfusioncve-2026-48324exploitationimproper-neutralizationnvd-cvescope-changesspecial-elements
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does...
arbitrary-code-executioncode-injectioncoldfusioncve-2026-48322exploitnvd-cvescope-changessecurity
2026-07-14 NVD CVE
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of...
coldfusioncve-2026-48321exploitincorrect-authorizationnvd-cveprivileges-escalationsecurityunauthorized-access
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescve-2026-48319directories-traversalexploitnvd-cve
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to...
access-controlarbitrary-file-readscoldfusioncve-2026-48318directories-traversalexploitfile-system-readnvd-cve
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....
arbitrary-code-executioncoldfusioncve-2026-48284exploitimproper-input-validationinput-validationnvd-cvesecurity
2026-07-14 NVD CVE
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A...
adobe-experience-managersarbitrary-code-executioncve-2026-48359elevated-accessno-user-interaction-requiresnvd-cvesensitive-file-readingsession-control
2026-07-14 NVD CVE
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
adobe-commercearbitrary-code-executioncode-executioncve-2026-48358improper-encodingimproper-escapingnvd-cvesecurities-risks
2026-07-14 NVD CVE
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this...
adobe-commercearbitrary-code-executioncve-2026-48356elevated-accessmalicious-scriptsnvd-cvesession-controlunrestricted-uploads
2026-07-14 NVD CVE
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage...
adobe-experience-managersarbitrary-code-executioncve-2026-48259elevated-accessno-user-interaction-requiresnvd-cveservers-sides-requests-forgerysession-control
2026-07-14 NVD CVE
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
code-executioncode-execution-vulnerabilitycve-2026-56190networks-attacksnetworks-vulnerabilitiesnvd-cverdpremote-desktop-protocol
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50518dhcp-serverheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50380exploitgdiheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14 NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
attack-vectorscode-executioncve-2026-58644datum-exfiltrationdeserializationexploitmicrosoftmicrosoft-office
2026-07-14 NVD CVE
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
attackercross-site-scriptingcve-2026-55008exchange-serverinputs-neutralizationmicrosoftnetwork-securitynvd-cve
2026-07-14 NVD CVE
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-54990exploitheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14 NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint
2026-07-14 NVD CVE
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
cve-2026-49798freekernel-exploitlocal-attacknvd-cveprivileges-escalationsecurity-bulletinunauthorized-access
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14 NVD CVE
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key...
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
◀ PREV PAGE 19 / 46 NEXT ▶