LIVE FEED
1821 events · 4 sources · newest first
Events in view
1821
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 12:00
UTC
2026-06-12
NVD CVE
CVE-2026-50083: The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client c
CRITICAL
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS...
2026-06-11
NVD CVE
CVE-2026-49261: MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 th
CRITICAL
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled...
2026-06-10
NVD CVE
CVE-2026-26240: A buffer overflow vulnerability has been reported to affect File Station 5. The
CRITICAL
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the...
2026-06-10
NVD CVE
CVE-2026-0274: An improper validation of credentials vulnerability in the CommvaultSecurityIQ i
CRITICAL
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
2026-06-10
NVD CVE
CVE-2025-66276: QuTS hero is not affected.
We have already fixed the vulnerability in the follo
CRITICAL
QuTS hero is not affected.
We have already fixed the vulnerability in the following version:
QTS 5.2.7.3256 build 20250913 and later
2026-06-10
NVD CVE
CVE-2026-26241: A buffer overflow vulnerability has been reported to affect File Station 5. The
CRITICAL
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the...
2026-06-09
NVD CVE
CVE-2026-34691: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af
CRITICAL
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into...
2026-06-09
NVD CVE
CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Erro
CRITICAL
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length...
2026-06-09
NVD CVE
CVE-2026-44083: An authorization bypass through user-controlled key vulnerability has been repor
CRITICAL
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges.
We have already fixed the...
2026-06-09
NVD CVE
CVE-2026-10523: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10
CRITICAL
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full...
2026-06-09
NVD CVE
CVE-2026-47928: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Inpu
CRITICAL
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue...
2026-06-08
NVD CVE
CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language mod
CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct...
2026-06-08
NVD CVE
CVE-2026-42861: Flowise is a drag & drop user interface to build a customized large language mod
CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. The endpoint...
2026-06-08
CISA KEV
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN...
2026-06-08
NVD CVE
CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language mod
CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or...
2026-06-08
NVD CVE
CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language mod
CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint...
2026-06-05
NVD CVE
CVE-2026-48907: A vulnerability in the JCE editor extension for Joomla allows the creation of ne
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
2026-06-05
NVD CVE
CVE-2026-45777: OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Startin
CRITICAL
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web server hosting...
2026-06-05
NVD CVE
CVE-2026-45779: OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL
CRITICAL
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute...
2026-06-05
NVD CVE
CVE-2026-11420: Two path traversal vulnerabilities in the Network Installation Service (NIS) of
CRITICAL
Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server...
2026-06-04
NVD CVE
CVE-2026-8037: OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC
CRITICAL
◈ 2 sources · orig. NVD CVE
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input...
appliance-executioncisa-kevcommand-injectionprogress-loadmastersprogress-loadmasters-vulnerabilitiesunauthenticated-attacksunsanitized-inputs
2026-06-04
NVD CVE
CVE-2026-50214: The /v1/Plan service relies entirely on a shared global API token for full admin
CRITICAL
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
2026-06-04
NVD CVE
CVE-2026-49185: The FieldX MDM adb messaging topic passes unverified payloads directly into Runt
CRITICAL
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
2026-06-04
NVD CVE
CVE-2026-11113: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 14
CRITICAL
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted...
2026-06-04
NVD CVE
CVE-2026-48567: Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized atta
CRITICAL
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
2026-06-04
NVD CVE
CVE-2026-50225: The registration path /v1/account/register provides no bot mitigation mechanisms
CRITICAL
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
2026-06-04
NVD CVE
CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting in Google Chr
CRITICAL
Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape...
2026-06-04
NVD CVE
CVE-2026-49186: The local MQTT broker does not enforce topic-level Access Control Lists (ACLs).
CRITICAL
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
2026-06-04
NVD CVE
CVE-2026-49188: The ai_cmd utility executes with full root permissions. It pipes socket inputs d
CRITICAL
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
2026-06-04
NVD CVE
CVE-2026-49191: The production build of the M3WebServer hard-codes its backend API keys, which c
CRITICAL
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
2026-06-04
NVD CVE
CVE-2026-50208: High-risk TrustAllCerts routines disable standard TLS certificate validation. Co
CRITICAL
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
2026-06-04
NVD CVE
CVE-2026-48040: The netty incubator codec.bhttp is a java language binary http parser. The libra
CRITICAL
The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses for...
2026-06-04
NVD CVE
CVE-2026-10931: Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a r
CRITICAL
Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
2026-06-04
NVD CVE
CVE-2026-10966: Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 a
CRITICAL
Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)
2026-06-04
NVD CVE
CVE-2026-10971: Insufficient validation of untrusted input in Printing in Google Chrome on Windo
CRITICAL
Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via...
2026-06-04
NVD CVE
CVE-2026-10972: Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed
CRITICAL
Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
2026-06-04
NVD CVE
CVE-2026-10974: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 14
CRITICAL
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
2026-06-04
NVD CVE
CVE-2026-10990: Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote
CRITICAL
Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...
2026-06-04
NVD CVE
CVE-2026-11002: Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a rem
CRITICAL
Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium...
2026-06-04
NVD CVE
CVE-2026-50211: Leftover engineering diagnostics and factory-level diagnostic software remain ex
CRITICAL
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.