Skip to content
COOEY
LIVE FEED
1814 events · 4 sources · newest first
2026-08-20 NVD CVE
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
authorize-attackerscve-2026-63509elevate-privilegefabricmicrosoftnetwork-securitynvd-cveprivileges-escalation
2026-08-20 NVD CVE
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
azure-data-factorycloud-securitycryptographic-signaturescve-2026-62834improper-verificationmicrosoftnetwork-securitynvd-cve
2026-08-20 NVD CVE
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
authorize-attackersazureazure-sql-databasecve-2026-68782database-securitymicrosoftnetwork-securityneutralization
2026-08-20 NVD CVE
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
attackerauthorize-attackersazure-sql-databasecve-2026-68789database-securityelevate-privilegeimproper-neutralizationnetwork
2026-08-20 NVD CVE
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
attackerazure-arcscve-2026-69555elevate-privilegeincorrect-authorizationmicrosoftnetwork-securitynvd-cve
2026-08-20 NVD CVE
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-69836deserializationentra-ididentity-managementmicrosoftmicrosofts-entrasnetworks-attacks
2026-08-20 NVD CVE
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
apache-cassandraargument-injectionazureazure-managed-instancecisacmmccode-executioncve-2026-65770
2026-08-20 NVD CVE
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
access-controlauthorize-attackersazureazure-sql-databasecisacloud-securitycve-2026-66309database-security
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
aixarbitrary-code-executioncve-2026-17157ibmnvd-cvepowervmremote-attackerssecurity-bulletin
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.
aixarbitrary-code-executioncommand-executioncve-2026-17142ibmimproper-authenticationnvd-cvepowervm
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
aixarbitrary-code-executioncve-2026-17160ibminteger-overflownvd-cvepowervmremote-attackers
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
aixarbitrary-code-executioncve-2026-17118freeibmnvd-cvepowervmremote-attackers
2026-08-20 NVD CVE
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The...
cve-2026-66785information-disclosuremalicious-clusternetwork-routingnetwork-securitynetwork-subnetnetwork-trafficnetworks-attacks
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
aixarbitrary-code-executioncve-2026-17122ibmnvd-cvepowervmremote-attackerssecurity-bulletin
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
aixarbitrary-code-executionbuffer-overflowcve-2026-17422ibmlocals-attackersnvd-cvepowervm
2026-08-20 NVD CVE
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or...
attackers-controlledclustercve-2026-66788endpoints-sliceskubes-systemslighthousenamespacenvd-cve
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
aixcve-2026-16926enterprise-softwarefiles-overwriteibminput-validationnvd-cveoperating-systems
2026-08-20 NVD CVE
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration....
buffer-overflowcf-n1-scgi-bincomfastcve-2026-77022exploitnvd-cvepublic-exploit
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
aixcve-2026-17136format-string-vulnerabilityibmibm-aixibm-powervmnvd-cvepowervm
2026-08-20 NVD CVE
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of...
389-dscve-2026-13097directory-serverdomain-compromisefreeipakerberokerberos-ticketldap
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
aixauthenticationcommand-injectioncve-2026-18835ibmnvd-cveoperating-systemspowervm
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17040ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20 NVD CVE
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The...
cluster-compromisecluster-securitycustom-resourcecve-2026-67567helm-charthelmreleasemulticloud-operators-subscriptionnvd-cve
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17141ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-19 NVD CVE
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack...
buffer-overflowcvecve-2026-76589firmware-vulnerabilitiesnetwork-adapternetwork-securitynvd-cveremote-attacks
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material,...
administrative-actionscve-2026-76310embedded-reportsnvd-cvereport-managementrest-apirole-based-accesssessions-materials
2026-08-19 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
aixarbitrary-code-executioncve-2026-16919ibmimproper-validationnetwork-supplied-pointernvd-cvepowervm
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed...
authorization-flowcve-2026-76311dispatches-archivesembedded-reportsnvd-cvereport-managementscheduled-reportssecurity-configuration
2026-08-19 NVD CVE
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument...
cgi-bincve-2026-76590nvd-cvepppoepublicly-available-exploitremote-exploitsecurity-bulletinssi
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session...
authorization-boundariescve-2026-76312dispatches-archivesembedded-reportshtml-sourcenvd-cvereport-managementsearch-job-data
2026-08-19 NVD CVE
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and...
authentication-bypassauthorization-bypasscluster-compromisecluster-proxy-addoncve-2026-66794information-disclosureinternal-service-accesskubernete
2026-08-19 NVD CVE
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT...
authenticationcudycve-2026-71960firmwarehmacjwtmesh-networkingmosquitto
2026-08-19 NVD CVE
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including,...
accounts-takeoverauthorization-bypasscve-2026-18315emails-overwritelost-password-flownvd-cveplugins-vulnerabilitiessecurity-vulnerability
2026-08-19 NVD CVE
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes...
buffer-overflowcgi-bincve-2026-75976exploitnetwork-attached-storagenvd-cvenvrremote-attacks
2026-08-19 NVD CVE
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based...
cve-2026-76003nvd-cveremote-attacksstack-based-buffer-overflowstrcpyuttutt-hyper-1200gwutt-hypers
2026-08-19 NVD CVE
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC)...
certificates-signing-requestcluster-administratorsclusterrolecve-2026-70496excessive-privilegeimpersonationkubernetemanifestwork
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availability-impactcompromiseconfidentiality-impactcorbacve-2026-62639cvss-31cvss-98integrity-impact
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62624cvss-31iiopintegritynetwork-accessnvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62640cvss-31iiopintegritynetwork-accessnvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62621cvss-31integritynetwork-accessnvd-cveoracle-fusion-middleware
◀ PREV PAGE 02 / 46 NEXT ▶