LIVE FEED
3576 events · 4 sources · newest first
Events in view
3576
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 12:00
UTC
2026-07-17
NVD CVE
CVE-2026-12694: Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform a
CRITICAL
Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
access-controlaclcve-2026-12694enterprise-video-platformmissing-authorizationnvd-cvesecurityvimesoft
2026-07-17
NVD CVE
CVE-2026-8297: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management...
applications-securitycode-injectioncve-2026-8297data-breaches-risksdatabase-securitygi-laboratory-management-systemsgis-informatics-engineering-consulting-laboratoryimproper-neutralization
2026-07-17
NVD CVE
CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain
CRITICAL
◈ 2 sources · orig. NVD CVE
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve...
api-vulnerabilitiescode-executioncve-2026-9198default-deploymentibmlangflownvd-cveopen-source
2026-07-17
NVD CVE
CVE-2026-8476: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize...
api-manipulationasyncdiskcachecustom-componentscve-2026-8476deserializationfile-system-accessibmlangflow
2026-07-17
NVD CVE
CVE-2026-9103: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unau
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer...
administrative-accessauthenticationbearer-tokencorcross-origin-resources-sharingcve-2026-9103ibmimproper-authentication
2026-07-17
NVD CVE
CVE-2026-8859: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability...
api-requestsarbitrary-file-writecontents-dispositioncve-2026-8859ibmincident-responseinput-validationlangflow
2026-07-17
NVD CVE
CVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes...
api-endpointauthenticate-usercode-validationcve-2026-8481exec-functionibminput-validationlangflow
2026-07-17
NVD CVE
CVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with...
arbitrary-code-executionauthenticate-usercve-2026-8635databases-manipulationibmlangflownvd-cveopen-source-software
2026-07-17
NVD CVE
CVE-2026-13446: IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or...
authenticationcve-2026-13446data-encryptionencryptionhard-coded-credentialsibminbound-authenticationinternal-data
2026-07-17
NVD CVE
CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
HIGH
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems...
agent-componentapi-v1code-act-agentcsv-agentcve-2026-13448denialflow-idibm
2026-07-17
NVD CVE
CVE-2026-9135: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 9498
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that...
agentic-mcpsauthenticate-users-attackscode-injectioncross-tenant-attackcve-2026-9135dynamic-code-validationflow-manipulationibm-langflow
2026-07-17
NVD CVE
CVE-2026-15091: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to
CRITICAL
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
arbitrary-script-executioncve-2026-15091ibmibm-engineering-ai-hub-1-0-0ibm-engineering-ai-hub-1-1-0ibm-engineering-ai-hub-1-2-0ibm-engineering-ai-hubsimproper-inputs-neutralization
2026-07-17
NVD CVE
CVE-2026-46420: setup-php is a GitHub action to set up PHP with extensions, php.ini configuratio
MEDIUM
setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled...
2026-07-17
NVD CVE
CVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key...
api-keyauthenticationbypassconfigurationcve-2026-8505default-settingsibmlangflow
2026-07-17
NVD CVE
CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
HIGH
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker...
2026-07-17
NVD CVE
CVE-2026-14501: IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacke
MEDIUM
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.
2026-07-16
NVD CVE
CVE-2026-44596: Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoi
MEDIUM
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting,...
account-lockoutauthenticationbrute-forcecve-2026-44596failed-attempts-throttlingframeworkmission-controlnvd-cve
2026-07-16
NVD CVE
CVE-2026-56453: HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vu
MEDIUM
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client...
accounts-takeoverauthentication-bypassauthorization-bypasscve-2026-56453hcl-dfxanalytichttps-responses-manipulationnvd-cveremote-attackers
2026-07-16
NVD CVE
CVE-2026-45568: zrok is software for sharing web services, files, and network resources. Prior t
CRITICAL
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to...
cve-2026-45568cybersecurityflaskincident-responseinformation-disclosurenetwork-resourcesnvd-cveproxy
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities...
air-gappeds-systemautomationdirectbound-readbound-writecisa-advisoriescisa-advisorycritical-manufacturingcve-2026-57896
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation these vulnerabilities...
arbitrary-code-executionarenabound-writecisacisa-advisorycontrol-systemcritical-manufacturingcve-2026-8085
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-03.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
cfcisacisa-advisorycore-flight-systemcvecve-2026-15352cwe-476denial
2026-07-16
NVD CVE
CVE-2026-54526: Argo Workflows is an open source container-native workflow engine for orchestrat
CRITICAL
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because...
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-09.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
cisacisa-advisorycritical-infrastructurecritical-manufacturingcross-site-scriptingcve-2026-9292cvss-31cvss-40
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-07.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
authorization-bypasscisacisa-advisorycommercial-facilitycritical-infrastructurecritical-manufacturingcve-2026-11889cwe-639
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-05.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Multiple SICAM 8 products are affected by multiple...
cisacisa-advisorycritical-infrastructurecve-2026-54798cve-2026-54799cve-2026-54800cve-2026-54801cwe-1188
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-08.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
cisacisa-advisorycritical-infrastructurecritical-manufacturingcve-2026-12659cvss-31cvss-40cwe-415
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-06.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities...
buffer-overflowcisacisa-advisorycompact-guardlogixcompactlogixcontrollogixcritical-infrastructurecritical-manufacturing
2026-07-16
CISA advisory
<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisorycommand-injectioncve-2026-25089cve-2026-39808cve-2026-58644deserialization
2026-07-16
NVD CVE
CVE-2026-44181: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distr
CRITICAL
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment...
2026-07-16
NVD CVE
CVE-2026-44182: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distr
CRITICAL
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates untrusted...
2026-07-16
NVD CVE
CVE-2026-15013: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen
CRITICAL
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because...
authentication-bypasscve-2026-15013nvd-cvesamlsaml-signatures-algorithms-confusionsingle-signssowordpress
2026-07-16
NVD CVE
CVE-2023-49900: An unauthenticated remote attacker is able to perform remote code execution due
CRITICAL
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
cve-2023-49900exploitincorrectly-sanitize-inputsnvd-cveremote-attackersremote-code-executionsecurity-bulletinsetparameter-command
2026-07-16
NVD CVE
CVE-2023-49899: An unauthenticated remote attacker can execute any command on the affected devic
CRITICAL
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
command-executioncommunications-channelscve-2023-49899nvd-cveorigin-verificationremote-attackerssecurityunauthenticate
2026-07-16
CISA KEV
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
attack-vectorscode-executioncve-2026-58644datum-exfiltrationdeserializationexploitmicrosoftmicrosoft-office
2026-07-16
CISA KEV
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
cisa-kevcommand-injectioncve-2026-39808fortinetfortisandboxhttps-requestsos-command-injectionsecurity-vulnerability
2026-07-16
CISA KEV
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
cisa-kevcloud-platformcloud-securitycommand-injectioncrafted-requestscve-2026-25089fortinetfortisandbox
2026-07-16
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
1756-en21756-en31756-enbtcisacisa-advisorycvecve-2026-9653cves-detail
2026-07-16
NVD CVE
CVE-2026-63087: Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability
CRITICAL
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using...
admins-usersapi-endpointapi-tokencve-2026-63087grafanagrafana-urlnvd-cveoncall
2026-07-16
NVD CVE
CVE-2026-63089: WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographic
CRITICAL
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer...
brute-forcecredentials-theftcryptographic-weaknessescve-2026-63089impersonationnvd-cveone-time-linkpreshared-key