LIVE FEED
1821 events · 4 sources · newest first
Events in view
1821
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 12:00
UTC
2026-07-09
NVD CVE
CVE-2026-56291: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary
CRITICAL
◈ 2 sources · orig. NVD CVE
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadbalbooon-formcybersecurityfiles-uploadjoomlanvd-cverceremote-code-execution
2026-07-09
NVD CVE
CVE-2026-58123: Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution v
CRITICAL
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without...
api-endpointcommand-executioncybersecuritydefense-industrial-basehermes-webuihttps-requestsincident-responsenvd-cve
2026-07-09
NVD CVE
CVE-2026-58122: Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability tha
CRITICAL
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed...
accesses-tokenapi-keyauthentication-bypasscloud-metadata-endpointcve-2026-58122device-code-flowheaderhermes-webui
2026-07-09
NVD CVE
CVE-2026-5955: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection.
This issue affects BiEticaret: before v3.3.57.
applications-securitybieticaretcve-2026-5955cybersecuritydata-securityinrove-softwarenvd-cvesoftware-vulnerabilities
2026-07-09
NVD CVE
CVE-2026-2342: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS.
This issue affects ValeApp: through...
cross-site-scriptingcybersecuritydisclosureinput-validationnvd-cveoceanicsoftsoftware-vulnerabilitiesstoreds-xss
2026-07-09
NVD CVE
CVE-2026-15158: The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Uploa
CRITICAL
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering...
arbitrary-files-uploadblocksy-companionblocksy-companion-procustom-fontscve-2026-15158file-extensionmime-validationnvd-cve
2026-07-09
NVD CVE
CVE-2026-14245: The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPres
CRITICAL
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is...
accounts-takeoveradministrator-accounts-takeoverauthentication-bypasscve-2026-14245form-noncejavascriptminiorangenonce
2026-07-09
NVD CVE
CVE-2026-47646: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcustomer-voicecve-2026-47646cybersecuritydynamics-365information-securityinput-validationmicrosoft
2026-07-08
NVD CVE
CVE-2026-55471: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CRITICAL
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare...
2026-07-08
NVD CVE
CVE-2026-54527: JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, t
CRITICAL
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history,...
2026-07-08
NVD CVE
CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains
CRITICAL
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
api-connectcve-2026-9074cybersecuritydata-securitydefense-industrial-baseibmincident-responsenist-800-171
2026-07-08
NVD CVE
CVE-2026-58480: Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthentic
CRITICAL
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the...
blocksy-companion-pro-plugincustom-fonts-extensionscve-2026-58480cybersecurityextension-validationfiles-uploadnvd-cvephp
2026-07-08
NVD CVE
CVE-2026-8307: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection.
This issue affects Mediküm Web: through 08072026. NOTE: The...
cve-2026-8307cybersecuritydatabase-securityimproper-neutralizationmedikum-webnvd-cvesecurity-flawsql-injection
2026-07-08
NVD CVE
CVE-2026-12153: The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass
CRITICAL
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an...
arbitrary-code-executionauthorization-bypasscve-2026-12153cybersecuritynvd-cveplugin-activationplugin-installationplugins-vulnerabilities
2026-07-08
NVD CVE
CVE-2026-9701: The Eventer plugin for WordPress is vulnerable to an insecure password reset mec
CRITICAL
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the...
cve-2026-9700cve-2026-9701eventer-pluginnvd-cvepassword-resetphpphp-74plaintext
2026-07-08
NVD CVE
CVE-2026-14487: The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file de
CRITICAL
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes...
arbitrary-file-deletionauthenticationauthorizationcve-2026-14487cybersecurityfile-path-validationfile-removalhash-checks
2026-07-07
NVD CVE
CVE-2026-59705: mem0's openmemory/api component contains an unauthenticated access vulnerability
CRITICAL
mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without...
apiarbitrary-accessescve-2026-59705cybersecuritydata-breachesdata-exposuredenialincident-response
2026-07-07
NVD CVE
CVE-2026-59706: mem0 contains unauthenticated config API endpoints that expose LLM API keys in p
CRITICAL
mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve...
api-keycloud-imdsconfiguration-managementcve-2026-59706cybersecuritydata-exposuredefense-industrial-basenist-800-171
2026-07-07
NVD CVE
CVE-2026-58473: Cognee before 1.2.0 contains an improper access control vulnerability that allow
CRITICAL
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings...
cogneeconfiguration-overwritecve-2026-58473data-breachesdatum-exfiltrationendpoint-securityimproper-access-controlinstance-wide-impact
2026-07-07
NVD CVE
CVE-2026-14345: The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
CRITICAL
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter...
cve-2026-14345cybersecurityinclude-oncelog-filenvd-cvephppluginremote-code-execution
2026-07-06
NVD CVE
CVE-2026-54763: Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22,
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing...
2026-07-06
NVD CVE
CVE-2026-40141: A high-severity vulnerability exists in a web application component of BeyondTru
CRITICAL
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of...
2026-07-06
NVD CVE
CVE-2026-40139: A critical pre-authentication vulnerability exists in the authentication subsyst
CRITICAL
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass...
2026-07-03
NVD CVE
CVE-2026-47898: Improper Restriction of XML External Entity Reference vulnerability in Apache Lu
CRITICAL
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before...
2026-07-03
NVD CVE
CVE-2026-12481: A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code exe
CRITICAL
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()`...
2026-07-02
NVD CVE
CVE-2026-55116: A malicious actor with access to the network and under certain network configura
CRITICAL
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to...
2026-07-02
NVD CVE
CVE-2026-55115: A malicious actor with access to the network and low privileges could exploit a
CRITICAL
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
2026-07-02
NVD CVE
CVE-2026-41106: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an un
CRITICAL
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
2026-07-01
NVD CVE
CVE-2026-58025: Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik
CRITICAL
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php,...
2026-07-01
NVD CVE
CVE-2026-14363: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.
This issue affects Mediawiki - Cargo...
2026-07-01
NVD CVE
CVE-2026-53492: containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.
CRITICAL
containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint...
2026-07-01
NVD CVE
CVE-2026-50195: containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 a
CRITICAL
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a...
2026-07-01
NVD CVE
CVE-2026-58521: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.
This issue affects Mediawiki - Cargo...
2026-07-01
NVD CVE
CVE-2026-58453: JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a h
CRITICAL
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin...
2026-07-01
NVD CVE
CVE-2026-34106: Guardian language-system passes the id GET parameter directly into a PHP exec()
CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\"...
2026-07-01
NVD CVE
CVE-2026-34100: Guardian language-system passes the id GET parameter directly into an unsanitize
CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id =...
2026-06-30
NVD CVE
CVE-2026-14120: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47
CRITICAL
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page....
2026-06-30
NVD CVE
CVE-2026-14109: Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47
CRITICAL
Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page....
2026-06-30
NVD CVE
CVE-2026-14106: Insufficient validation of untrusted input in Text in Google Chrome on Android p
CRITICAL
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a...
2026-06-30
NVD CVE
CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome pr
CRITICAL
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security...