LIVE FEED
1573 events · 4 sources · newest first
Events in view
1573
all sources
Critical
0
severity
Active sources
4
collectors
Last sync
2026-08-25 18:00
UTC
2026-08-11
CISA KEV
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance....
administrators-accessapplications-securitycisa-kevcredentials-theftcve-2026-72898data-theftdatabase-securitydatum-exfiltration
2026-08-11
CISA KEV
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to...
cisa-kevciscocisco-asacisco-ftdcve-2026-20349denialdevice-reloaddo-s
2026-08-11
CISA KEV
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
ancillary-functions-driversauthorize-attackerscisa-kevcve-2026-68820freeincident-responselocal-attackmicrosoft
2026-08-10
NVD CVE
CVE-2026-59090: A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign
HIGH
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to...
2026-08-07
NVD CVE
CVE-2026-56793: Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im
HIGH
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,...
cve-2026-56793cybersecuritydelldfar-252-204-7012improper-authenticationincident-responsenist-800-171nvd-cve
2026-08-07
NVD CVE
CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL
HIGH
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
azure-sqlimproper-restrictions-communicationsnetworks-vulnerabilitiesnvd-cveprivileges-elevationunauthorized-attacks
2026-08-07
CISA KEV
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
appliance-executioncisa-kevcommand-injectionprogress-loadmastersprogress-loadmasters-vulnerabilitiesunauthenticated-attacksunsanitized-inputs
2026-08-05
CISA KEV
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
agents-pollingcisa-kevdeserializationjetbrainremote-code-executionteamcityuntrusted-datavulnerability
2026-08-05
NVD CVE
CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00
HIGH
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event...
authenticationcve-2026-10025event-processingibminjectioninterim-fixesnvd-cveport-514
2026-08-05
NVD CVE
CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv
HIGH
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server...
application-serverarbitrary-code-executionclass-loadingcve-2026-8400ibmibm-sdkiiopjava
2026-08-05
NVD CVE
CVE-2026-16442: A flaw was found in the SAML broker component of Keycloak, which is used to mana
HIGH
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a...
access-controlaccounts-linkingauthenticationcve-2026-16442identity-federationidentity-managementkeycloaklogins-restrictions
2026-08-05
NVD CVE
CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side
HIGH
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
applications-gateways-operatorscustom-resourcecve-2026-17617ibmnvd-cvesecurityservers-sides-requests-forgeryssrf
2026-08-05
NVD CVE
CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
HIGH
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under...
api-keyauthentication-tokencve-2026-8470deterministic-rngencryption-keysfernet-encryptionsibm-langflownvd-cve
2026-08-05
NVD CVE
CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in t
HIGH
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
cryptographiccve-2026-9205ibmkey-derivationlangflownvd-cvevulnerabilityweak-key
2026-08-05
NVD CVE
CVE-2026-16443: A flaw was found in the SAML metadata import functionality of the keycloak-servi
HIGH
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata...
authenticationcve-2026-16443forgeryidentity-brokeridentity-providerkeycloakmetadata-importnvd-cve
2026-08-04
CISA KEV
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
alternate-channelalternate-pathsauthentication-bypasscisa-kevcve-2026-18556cybersecurityinformation-securitymanaged-services-providers
2026-08-04
CISA KEV
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
apache-tomcatbypasscisa-kevcve-2026-34486cybersecuritydata-protectiondfar-252-204-7012encrypt-interceptor
2026-08-04
CISA KEV
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
api-vulnerabilitiescode-executioncve-2026-9198default-deploymentibmlangflownvd-cveopen-source
2026-08-04
NVD CVE
CVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge
HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
chromiumcve-2026-66321cybersecuritydefense-industrial-basedfar-252-204-7012information-securitymicrosoftmicrosoft-edge
2026-08-03
CISA KEV
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for...
accounts-takeoveralternate-pathsauthentication-bypasschannelcisa-kevcve-2026-18556cve-2026-18577cybersecurity
2026-07-30
NVD CVE
CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
HIGH
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
arbitrary-commandscrlf-character-neutralizationscve-2026-14522ibm-apps-connect-enterprisenvd-cveremote-attacksvulnerability
2026-07-29
NVD CVE
CVE-2026-58163: Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corr
HIGH
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apacheapache-traffic-serverscache-corruptioncve-2026-58163data-integritydata-lossesincident-responsenvd-cve
2026-07-29
NVD CVE
CVE-2026-13697: undici's cache interceptor mishandles malformed Cache-Control private directives
HIGH
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such...
cache-controlcaches-interceptorscve-2026-13697errors-handlinghttps-headersinformation-disclosuremalformed-headersnvd-cve
2026-07-29
CISA KEV
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an...
cisa-kevciscocmmccompliance-riskcve-2026-20316defense-industrial-basefirepower-management-centerfirewall
2026-07-29
NVD CVE
CVE-2026-58177: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traver
HIGH
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade...
apache-traffic-serversbound-writecmmccritical-patchescve-2026-58177defense-industrial-basefedrampfree
2026-07-29
NVD CVE
CVE-2026-58179: The Apache Traffic Server regex_remap plugin overflows the stack and integers fr
HIGH
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apache-traffic-serverscve-2026-58179cve-disclosuresinteger-overflownvd-cveregex-remap-pluginssecurity-patchsoftware
2026-07-28
NVD CVE
CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a
HIGH
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
2026-07-28
NVD CVE
CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b
HIGH
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
applications-securityauthentication-bypasscve-2026-16184cybersecuritydata-protectiondefense-industrial-baseibmnist-800-171
2026-07-28
NVD CVE
CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
2026-07-27
NVD CVE
CVE-2026-45623: PostCSS takes a CSS file and provides an API to analyze and modify its rules by
HIGH
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH...
2026-07-27
NVD CVE
CVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal reque
HIGH
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
access-controlauthentication-weaknessescompliance-riskcve-2026-66014internal-requests-processingjfrog-artifactorynvd-cveprivileges-escalation
2026-07-27
CISA KEV
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may...
aristaavailabilitycisa-kevcommand-injectionconfidentialitycve-2026-16812data-compromiseintegrity
2026-07-27
CISA KEV
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency...
cisa-kevcve-2025-68686cybersecurityexposurefilesystem-levelfortinetfortiohttps-requests
2026-07-23
NVD CVE
CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue a
HIGH
Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
authentication-bypasscisacmmc-level-2cve-2026-10697datum-exfiltrationdodfedramp-authorizationimproper-authentication
2026-07-23
NVD CVE
CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in
HIGH
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd-cve
2026-07-23
NVD CVE
CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s
HIGH
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
2026-07-23
NVD CVE
CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This
HIGH
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
cisacmmc-level-2compliancecve-2026-15967defense-industrial-basedodfedramp-authorizationincident-response
2026-07-23
NVD CVE
CVE-2026-64815: In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible v
HIGH
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
arbitrary-code-injectioncode-injectioncve-2026-64815cybersecuritydevelopers-toolsform-fileintellij-ideajetbrain
2026-07-22
CISA KEV
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...
administrative-privilegescheck-pointcisa-kevcve-2026-16232improper-authentication-vulnerabilityremote-attacks
2026-07-22
CISA KEV
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint