LIVE FEED
1759 events · 4 sources · newest first
Events in view
1759
all sources
Critical
1485
severity
Active sources
4
collectors
Last sync
2026-08-25 18:00
UTC
2026-08-20
NVD CVE
CVE-2026-69400: Improper limitation of a pathname to a restricted directory ('path traversal') i
CRITICAL
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
attackerazureazure-logic-appscve-2026-69400improper-limitationnetwork-securitynvd-cvepath-traversal
2026-08-20
NVD CVE
CVE-2026-72843: The customer update route in EverShop is declared with "access": "public" in pac
CRITICAL
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next()...
access-controlaccounts-takeoverapi-securityauthentication-bypasscustomer-datacve-2026-72843evershopmiddleware
2026-08-20
NVD CVE
CVE-2026-65801: Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauth
CRITICAL
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
cve-2026-65801exchange-onlinemicrosoftmicrosoft-exchange-onlinenetwork-securitynvd-cveprivileges-escalationservers-sides-requests-forgery
2026-08-20
NVD CVE
CVE-2026-68789: Improper neutralization of special elements used in an sql command ('sql injecti
CRITICAL
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
attackerauthorize-attackersazure-sql-databasecve-2026-68789database-securityelevate-privilegeimproper-neutralizationnetwork
2026-08-20
NVD CVE
CVE-2026-69555: Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate
CRITICAL
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
attackerazure-arcscve-2026-69555elevate-privilegeincorrect-authorizationmicrosoftnetwork-securitynvd-cve
2026-08-20
NVD CVE
CVE-2026-69836: Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-69836deserializationentra-ididentity-managementmicrosoftmicrosofts-entrasnetworks-attacks
2026-08-20
NVD CVE
CVE-2026-65816: Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorize
CRITICAL
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
azureazure-arcscve-2026-65816incident-responsemicrosoftnetwork-securitynvd-cveprivileges-escalation
2026-08-20
NVD CVE
CVE-2026-63509: Relative path traversal in Microsoft Fabric allows an authorized attacker to ele
CRITICAL
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
authorize-attackerscve-2026-63509elevate-privilegefabricmicrosoftnetwork-securitynvd-cveprivileges-escalation
2026-08-20
NVD CVE
CVE-2026-62834: Improper verification of cryptographic signature in Azure Data Factory allows an
CRITICAL
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
azure-data-factorycloud-securitycryptographic-signaturescve-2026-62834improper-verificationmicrosoftnetwork-securitynvd-cve
2026-08-20
NVD CVE
CVE-2026-65770: Improper neutralization of argument delimiters in a command ('argument injection
CRITICAL
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
apache-cassandraargument-injectionazureazure-managed-instancecisacmmccode-executioncve-2026-65770
2026-08-20
NVD CVE
CVE-2026-66309: Improper access control in Azure SQL Database allows an authorized attacker to e
CRITICAL
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
access-controlauthorize-attackersazureazure-sql-databasecisacloud-securitycve-2026-66309database-security
2026-08-20
NVD CVE
CVE-2026-17157: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
aixarbitrary-code-executioncve-2026-17157ibmnvd-cvepowervmremote-attackerssecurity-bulletin
2026-08-20
NVD CVE
CVE-2026-17142: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.
aixarbitrary-code-executioncommand-executioncve-2026-17142ibmimproper-authenticationnvd-cvepowervm
2026-08-20
NVD CVE
CVE-2026-17160: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
aixarbitrary-code-executioncve-2026-17160ibminteger-overflownvd-cvepowervmremote-attackers
2026-08-20
NVD CVE
CVE-2026-17118: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
aixarbitrary-code-executioncve-2026-17118freeibmnvd-cvepowervmremote-attackers
2026-08-20
NVD CVE
CVE-2026-66785: A flaw was found in Submariner. This vulnerability allows a malicious cluster (s
CRITICAL
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The...
cve-2026-66785information-disclosuremalicious-clusternetwork-routingnetwork-securitynetwork-subnetnetwork-trafficnetworks-attacks
2026-08-20
NVD CVE
CVE-2026-17122: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
aixarbitrary-code-executioncve-2026-17122ibmnvd-cvepowervmremote-attackerssecurity-bulletin
2026-08-20
NVD CVE
CVE-2026-17422: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to ex
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
aixarbitrary-code-executionbuffer-overflowcve-2026-17422ibmlocals-attackersnvd-cvepowervm
2026-08-20
NVD CVE
CVE-2026-17138: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
2026-08-20
NVD CVE
CVE-2026-18716: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
2026-08-20
NVD CVE
CVE-2026-66788: A flaw was found in Lighthouse. A remote attacker, by compromising a spoke clust
CRITICAL
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or...
attackers-controlledclustercve-2026-66788endpoints-sliceskubes-systemslighthousenamespacenvd-cve
2026-08-20
NVD CVE
CVE-2026-17436: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
2026-08-20
NVD CVE
CVE-2026-17060: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read.
2026-08-20
NVD CVE
CVE-2026-17000: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.
2026-08-20
NVD CVE
CVE-2026-18835: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
aixauthenticationcommand-injectioncve-2026-18835ibmnvd-cveoperating-systemspowervm
2026-08-20
NVD CVE
CVE-2026-16926: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
aixcve-2026-16926enterprise-softwarefiles-overwriteibminput-validationnvd-cveoperating-systems
2026-08-20
NVD CVE
CVE-2026-17423: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.
2026-08-20
NVD CVE
CVE-2026-13097: A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enfo
CRITICAL
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of...
389-dscve-2026-13097directory-serverdomain-compromisefreeipakerberokerberos-ticketldap
2026-08-20
NVD CVE
CVE-2026-17152: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17152ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20
NVD CVE
CVE-2026-17145: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
aixarbitrary-code-executioncve-2026-17145ibmnvd-cvepowervmprivileges-managementremote-code-execution
2026-08-20
NVD CVE
CVE-2026-77022: A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this
CRITICAL
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component SSID Configuration....
buffer-overflowcf-n1-scgi-bincomfastcve-2026-77022exploitnvd-cvepublic-exploit
2026-08-20
NVD CVE
CVE-2026-17141: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17141ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20
NVD CVE
CVE-2026-67567: A flaw was found in the multicloud-operators-subscription component. This vulner
CRITICAL
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The...
cluster-compromisecluster-securitycustom-resourcecve-2026-67567helm-charthelmreleasemulticloud-operators-subscriptionnvd-cve
2026-08-20
NVD CVE
CVE-2026-17040: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17040ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20
NVD CVE
CVE-2026-17136: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
aixcve-2026-17136format-string-vulnerabilityibmibm-aixibm-powervmnvd-cvepowervm
2026-08-19
NVD CVE
CVE-2026-76589: A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the
CRITICAL
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack...
buffer-overflowcvecve-2026-76589firmware-vulnerabilitiesnetwork-adapternetwork-securitynvd-cveremote-attacks
2026-08-19
NVD CVE
CVE-2026-76312: In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unaut
CRITICAL
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session...
authorization-boundariescve-2026-76312dispatches-archivesembedded-reportshtml-sourcenvd-cvereport-managementsearch-job-data
2026-08-19
NVD CVE
CVE-2026-76590: A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by
CRITICAL
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument...
cgi-bincve-2026-76590nvd-cvepppoepublicly-available-exploitremote-exploitsecurity-bulletinssi
2026-08-19
NVD CVE
CVE-2026-76311: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut
CRITICAL
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed...
authorization-flowcve-2026-76311dispatches-archivesembedded-reportsnvd-cvereport-managementscheduled-reportssecurity-configuration
2026-08-19
NVD CVE
CVE-2026-76310: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut
CRITICAL
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material,...
administrative-actionscve-2026-76310embedded-reportsnvd-cvereport-managementrest-apirole-based-accesssessions-materials