LIVE FEED
1767 events · 4 sources · newest first
Events in view
1767
all sources
Critical
1492
severity
Active sources
4
collectors
Last sync
2026-08-26 12:00
UTC
2026-07-15
NVD CVE
CVE-2026-56400: open-webui before 0.3.14 contains a cross-origin resource sharing misconfigurati
HIGH
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute...
admins-usersapi-endpointarbitrary-code-executionattackers-controlled-websitesauthenticate-requestscross-origin-resources-sharingcross-site-requestcve-2026-56400
2026-07-15
NVD CVE
CVE-2026-56398: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in
HIGH
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header,...
accounts-takeoverauthentication-token-theftcontent-typescross-site-scriptingcve-2026-56398datum-urifile-extensioninline-disposition
2026-07-14
NVD CVE
CVE-2026-58644: Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
attack-vectorscode-executioncve-2026-58644datum-exfiltrationdeserializationexploitmicrosoftmicrosoft-office
2026-07-14
NVD CVE
CVE-2026-55008: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
attackercross-site-scriptingcve-2026-55008exchange-serverinputs-neutralizationmicrosoftnetwork-securitynvd-cve
2026-07-14
NVD CVE
CVE-2026-54990: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac
CRITICAL
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-54990exploitheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14
NVD CVE
CVE-2026-50522: Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint
2026-07-14
NVD CVE
CVE-2026-49798: Use after free in Windows Kernel allows an unauthorized attacker to elevate priv
CRITICAL
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
cve-2026-49798freekernel-exploitlocal-attacknvd-cveprivileges-escalationsecurity-bulletinunauthorized-access
2026-07-14
NVD CVE
CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacke
CRITICAL
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14
NVD CVE
CVE-2026-48561: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14
NVD CVE
CVE-2026-10672: subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI
HIGH
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri,...
2026-07-14
NVD CVE
CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin o
MEDIUM
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
2026-07-14
NVD CVE
CVE-2026-59836: A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3
HIGH
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via...
certificate-validationcve-2026-59836endpoint-securityforticlientemfortinetimproper-certificate-validationinformation-disclosurenetwork-security
2026-07-14
NVD CVE
CVE-2026-24227: NVIDIA TensorRT for contains a vulnerability where a user might cause a deserial
MEDIUM
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.
code-executioncve-2026-24227deserializationexploitnvd-cvenvidiasecuritytensorrt
2026-07-14
NVD CVE
CVE-2026-54058: Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncomp
CRITICAL
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller...
2026-07-14
NVD CVE
CVE-2026-42990: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized atta
CRITICAL
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-42990heap-based-buffer-overflowmicrosoftnetworks-attacksnvd-cveodbc-driver
2026-07-14
NVD CVE
CVE-2026-15701: A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affect
CRITICAL
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument...
buffer-overflowcooeys-clubcve-2026-15701form-logoutformlogouthtmlighttpdnetworks-devicesnvd-cve
2026-07-14
NVD CVE
CVE-2026-62392: Improper Neutralization of Special Elements used in an OS Command ('OS Command I
CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.
This issue affects Apache...
apache-softwaresapaches-kylinapi-vulnerabilitiescommand-injectioncve-2026-62392cybersecuritydata-breaches-preventionincident-response
2026-07-14
NVD CVE
CVE-2026-62390: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.
This issue...
apaches-kylinapicisacmmccve-2026-62390databasedodnist-800-171
2026-07-14
NVD CVE
CVE-2026-58319: Certain Apache Doris FE HTTP REST administrative APIs were accessible without pr
CRITICAL
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative...
administratives-apisapaches-dori-3-1-0apaches-dorisauthenticationcluster-availabilitycluster-integritycve-2026-58319denial
2026-07-14
NVD CVE
CVE-2026-56451: A vulnerability has been identified in Opcenter X (All versions < V2604). Affect
CRITICAL
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
This could allow an...
access-controlapplications-securityauthentication-bypasscve-2026-56451cve-trackingsimpersonationjson-web-tokenjwt-forges
2026-07-14
NVD CVE
CVE-2026-44761: SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented
CRITICAL
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an...
apus-exploitationscompliance-riskconfidentiality-impactcredentials-exposurecve-2026-44761data-integrityhelp-portalnvd-cve
2026-07-14
NVD CVE
CVE-2026-44747: SAP NetWeaver Application Server ABAP allows an authenticated attacker to levera
CRITICAL
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system...
abapauthenticate-attackeravailabilitycmmcconfidentialitycve-2026-44747data-accessdefense-industrial-base
2026-07-14
NVD CVE
CVE-2026-27690: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthentica
CRITICAL
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the...
availability-impactconfidentiality-impactcve-2026-27690https-requests-smugglingnvd-cverequests-responses-desynchronizationsap-approutersecurity-vulnerability
2026-07-14
NVD CVE
CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized
HIGH
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
2026-07-14
NVD CVE
CVE-2026-50487: Use after free in Microsoft Windows DNS allows an unauthorized attacker to eleva
HIGH
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-50439: Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized
HIGH
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-50330: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac
HIGH
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unautho
HIGH
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-49181: Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthor
HIGH
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14
NVD CVE
CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut
HIGH
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allow
HIGH
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-48807: Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() c
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
2026-07-14
NVD CVE
CVE-2026-48806: Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not g
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key...
2026-07-14
NVD CVE
CVE-2026-48805: Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappe
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(),...
2026-07-14
NVD CVE
CVE-2026-58617: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized
HIGH
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to
HIGH
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-14
NVD CVE
CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau
HIGH
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unautho
HIGH
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.