LIVE FEED
3576 events · 4 sources · newest first
Events in view
3576
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 12:00
UTC
2026-07-15
NVD CVE
CVE-2026-54052: n8n-MCP is an MCP server that provides AI assistants access to n8n node document
CRITICAL
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's...
ai-assistantauthorization-headercredentials-exposurecve-2026-54052data-breacheshttps-modemcp-servermulti-tenancy
2026-07-15
NVD CVE
CVE-2026-53512: Better Auth is an authentication and authorization library for TypeScript. Prior
CRITICAL
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession...
accesses-tokenauthenticationauthorizationbetters-authsclient-idclients-secretscve-2026-53512mcp-plugins
2026-07-15
NVD CVE
CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. Fr
CRITICAL
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a...
2026-07-15
NVD CVE
CVE-2026-56400: open-webui before 0.3.14 contains a cross-origin resource sharing misconfigurati
HIGH
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute...
admins-usersapi-endpointarbitrary-code-executionattackers-controlled-websitesauthenticate-requestscross-origin-resources-sharingcross-site-requestcve-2026-56400
2026-07-15
CISA KEV
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...
cisa-kevcompromisecve-2026-46817e-business-suitehttpimproper-privileges-managementnetwork-accessoracle
2026-07-15
CISA KEV
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security...
account-lockoutattackerbcuses-keycisa-kevcve-2023-4346device-purgeknx-protocolknxes-association
2026-07-15
CISA advisory
<p>Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a...
cisacisa-advisorycomputer-security-incident-responsecoordinated-vulnerability-disclosurecve-identifiersincident-responsensaproduct-security
2026-07-15
NVD CVE
CVE-2026-20157: As part of Cisco's ongoing commitment to proactive security and product quality,
HIGH
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-15
NVD CVE
CVE-2026-20156: As part of Cisco's ongoing commitment to proactive security and product quality,
HIGH
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-15
CISA advisory
<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
binding-operational-directivesbod-26-04cisacisa-advisorycve-2023-4346cve-2026-46817cyber-actorsfceb-agency
2026-07-15
NVD CVE
CVE-2026-56398: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in
HIGH
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header,...
accounts-takeoverauthentication-token-theftcontent-typescross-site-scriptingcve-2026-56398datum-urifile-extensioninline-disposition
2026-07-14
NVD CVE
CVE-2026-48807: Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() c
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
2026-07-14
CISA advisory
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisorycve-2026-15409cve-2026-15410cve-2026-56155cve-2026-56164cyber-attacks
2026-07-14
NVD CVE
CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut
HIGH
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14
CISA advisory
<p>CISA is aware of active exploitation of vulnerabilities <a href="https://www.cve.org/CVERecord?id=CVE-2026-32201" target="_blank">CVE-2026-32201</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-45659"...
cisacisa-advisorycve-2026-32201cve-2026-45659cve-2026-55040cve-2026-56164cve-2026-58644iis
2026-07-14
NVD CVE
CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allow
HIGH
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14
NVD CVE
CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unautho
HIGH
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-49181: Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthor
HIGH
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-48561: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14
NVD CVE
CVE-2026-50380: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to ex
CRITICAL
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50380exploitgdiheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14
NVD CVE
CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacke
CRITICAL
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14
NVD CVE
CVE-2026-62422: In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.
CRITICAL
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
2026-07-14
NVD CVE
CVE-2026-15701: A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affect
CRITICAL
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument...
buffer-overflowcooeys-clubcve-2026-15701form-logoutformlogouthtmlighttpdnetworks-devicesnvd-cve
2026-07-14
NVD CVE
CVE-2026-47767: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on...
applications-securitycode-executioncve-2024-50340cve-2026-47767debug-modeenvironment-variablesnvd-cvephp
2026-07-14
NVD CVE
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-14
NVD CVE
CVE-2026-48284: ColdFusion is affected by an Improper Input Validation vulnerability that could
CRITICAL
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....
arbitrary-code-executioncoldfusioncve-2026-48284exploitimproper-input-validationinput-validationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-50439: Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized
HIGH
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-56164: Missing authentication for critical function in Microsoft Office SharePoint allo
MEDIUM
◈ 2 sources · orig. NVD CVE
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
authentication-bypasscisa-kevcritical-functionscve-2026-56164microsoftmissing-authenticationnetwork-securityprivileges-escalation
2026-07-14
NVD CVE
CVE-2026-50487: Use after free in Microsoft Windows DNS allows an unauthorized attacker to eleva
HIGH
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-50518: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke
CRITICAL
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50518dhcp-serverheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14
NVD CVE
CVE-2026-48325: ColdFusion is affected by a Missing Authentication for Critical Function vulnera
CRITICAL
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
arbitrary-code-executioncoldfusioncritical-functionscve-2026-48325exploitmissing-authenticationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48356: Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type
CRITICAL
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this...
adobe-commercearbitrary-code-executioncve-2026-48356elevated-accessmalicious-scriptsnvd-cvesession-controlunrestricted-uploads
2026-07-14
NVD CVE
CVE-2026-48358: Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnera
CRITICAL
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
adobe-commercearbitrary-code-executioncode-executioncve-2026-48358improper-encodingimproper-escapingnvd-cvesecurities-risks
2026-07-14
NVD CVE
CVE-2026-48359: Adobe Experience Manager is affected by an Improper Restriction of XML External
CRITICAL
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A...
adobe-experience-managersarbitrary-code-executioncve-2026-48359elevated-accessno-user-interaction-requiresnvd-cvesensitive-file-readingsession-control
2026-07-14
NVD CVE
CVE-2026-48319: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CRITICAL
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescve-2026-48319directories-traversalexploitnvd-cve
2026-07-14
NVD CVE
CVE-2026-48318: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CRITICAL
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to...
access-controlarbitrary-file-readscoldfusioncve-2026-48318directories-traversalexploitfile-system-readnvd-cve
2026-07-14
NVD CVE
CVE-2026-48324: ColdFusion is affected by an Improper Neutralization of Special Elements used in
CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncoldfusioncve-2026-48324exploitationimproper-neutralizationnvd-cvescope-changesspecial-elements
2026-07-14
NVD CVE
CVE-2026-48321: ColdFusion is affected by an Incorrect Authorization vulnerability that could re
CRITICAL
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of...
coldfusioncve-2026-48321exploitincorrect-authorizationnvd-cveprivileges-escalationsecurityunauthorized-access
2026-07-14
NVD CVE
CVE-2026-54058: Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncomp
CRITICAL
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller...