Skip to content
COOEY
LIVE FEED
1821 events · 4 sources · newest first
2026-07-14 NVD CVE
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
cve-2026-49798freekernel-exploitlocal-attacknvd-cveprivileges-escalationsecurity-bulletinunauthorized-access
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14 NVD CVE
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14 NVD CVE
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on...
applications-securitycode-executioncve-2024-50340cve-2026-47767debug-modeenvironment-variablesnvd-cvephp
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(),...
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key...
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
2026-07-14 NVD CVE
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-42990heap-based-buffer-overflowmicrosoftnetworks-attacksnvd-cveodbc-driver
2026-07-14 NVD CVE
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument...
buffer-overflowcooeys-clubcve-2026-15701form-logoutformlogouthtmlighttpdnetworks-devicesnvd-cve
2026-07-14 NVD CVE
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache...
apache-softwaresapaches-kylinapi-vulnerabilitiescommand-injectioncve-2026-62392cybersecuritydata-breaches-preventionincident-response
2026-07-14 NVD CVE
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue...
apaches-kylinapicisacmmccve-2026-62390databasedodnist-800-171
2026-07-14 NVD CVE
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative...
administratives-apisapaches-dori-3-1-0apaches-dorisauthenticationcluster-availabilitycluster-integritycve-2026-58319denial
2026-07-13 NVD CVE
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It...
32-bit-buildcrashes-vulnerabilitiescve-2026-40469do-subgawkheap-overflowinteger-overflownvd-cve
2026-07-13 NVD CVE
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and...
cisacmmc-level-2cve-2026-40468dodfedramp-authorizationgawkheap-metadatainteger-overflow
2026-07-13 NVD CVE
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single...
9routerai-provider-accountapi-key-exposurebilling-fraudcompliance-riskcve-2026-62327information-leakagemissing-authentication-middleware
2026-07-13 NVD CVE
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to...
9routerapi-endpointapi-keyauthentication-middlewarecompliance-riskcredentials-exposurecve-2026-59801denial
2026-07-13 NVD CVE
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote...
administrative-accessauthenticationconfigurations-featurescve-2026-61500login-responsesnon-cryptographic-generatornvd-cverejetto
2026-07-13 NVD CVE
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying...
cmmc-level-2command-injectioncve-2026-61498graph-generationinput-sanitizationnist-800-171nvd-cveos-command-execution
2026-07-13 NVD CVE
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without...
cisacmmc-level-2cve-2026-4769defense-industrial-basedevices-compromisefedramp-authorizationincident-responseinternal-diagnostic
2026-07-13 NVD CVE
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are...
access-controlcve-2026-13221false-negativefalse-positivesfilteringnvd-cveoverflowperl
2026-07-13 NVD CVE
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
arbitrary-file-deletioncve-2026-57830extensionfile-deletionhelixes-ultimatesjoomlanvd-cvesecurity
2026-07-12 NVD CVE
A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This...
cf-wr631axcomfastcommand-injectioncve-2026-15511fastcgi-backendsfile-path-manipulationnvd-cveos-command-injection
2026-07-12 NVD CVE
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise...
api-securityauthentication-bypassauthentication-middlewarecve-2026-56271default-credentialsflowisehardcoded-secretimpersonation
2026-07-12 NVD CVE
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation,...
api-serverarbitrary-file-writecrawl4aicve-2026-56260denialdockerdocker-apusendpoint-security
2026-07-11 NVD CVE
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement....
arbitrary-code-executioncodeagentcve-2026-61447cybersecuritydatum-exfiltrationenvironment-secretslarge-language-modelllm
2026-07-11 NVD CVE
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject...
aicoder-componentarbitrary-file-writecommand-executioncommands-sanitizationcve-2026-61445cybersecurityinformation-securityllms-tool
2026-07-11 NVD CVE
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name...
cassandracql-injectioncreate-tablescve-2026-60090cybersecuritydata-validationdatabase-securityddl-injections
2026-07-11 NVD CVE
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadcve-2026-57827files-uploadjoomlanvd-cveremote-code-executionrsfilesecurity
2026-07-10 NVD CVE
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying...
32-bit-buildcve-2026-57156cve-disclosuresfreerdpheap-buffer-overflowheap-buffers-undersizeheap-overflowinteger-overflow
2026-07-10 NVD CVE
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in...
buffer-overflowcmmc-level-2compliancecve-2026-23530cve-2026-57158dodfedrampfreerdp
2026-07-10 NVD CVE
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due...
accounts-takeoveradministrators-accessauthentication-bypasscve-2026-12761cybersecuritydata-compromiseemail-address-verificationminiorange
2026-07-10 NVD CVE
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security...
api-serverargument-injectionbearer-tokencluster-compromisecve-2026-61459cybersecuritydefense-industrial-baseincident-response
2026-07-10 NVD CVE
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
code-executioncve-2026-59792cybersecuritydfar-252-204-7012incident-responseintellij-ideajetbrainnist-800-171
2026-07-10 NVD CVE
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary...
apicode-injectioncve-2026-61444cybersecuritydeploymentnvd-cvepraiseaipython
2026-07-10 NVD CVE
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition...
cloud-metadata-servicescredentials-theftcve-2026-15378file-readsguardrail-detectorsinternal-networkkubernete-apiminio
2026-07-10 NVD CVE
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via...
cve-2026-15300cybersecurityescape-functiongeo-my-wp-plugininformation-securitynumeric-validationnvd-cvephp
2026-07-10 NVD CVE
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2....
arbitrary-files-uploadcve-2026-15282cybersecurityfile-type-validationinformation-securityinstant-appointmentnvd-cveplugin
2026-07-10 NVD CVE
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type...
ajaxarbitrary-files-uploadcve-2026-14894cybersecurityfile-type-validationnoncenoprivnvd-cve
2026-07-09 NVD CVE
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially...
cloud-ngfwcve-2026-0284data-corruptioninformation-disclosurelsvpnmalicious-contentsnetwork-accessnot-impacted
2026-07-09 NVD CVE
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
arbitrary-file-writeblob-ymlbosh-clicli-toolcloud-foundrycodecve-2026-47826datum-exfiltration
◀ PREV PAGE 20 / 46 NEXT ▶