Skip to content
COOEY
LIVE FEED
3576 events · 4 sources · newest first
2026-07-15 NVD CVE
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's...
ai-assistantauthorization-headercredentials-exposurecve-2026-54052data-breacheshttps-modemcp-servermulti-tenancy
2026-07-15 NVD CVE
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession...
accesses-tokenauthenticationauthorizationbetters-authsclient-idclients-secretscve-2026-53512mcp-plugins
2026-07-15 NVD CVE
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a...
2026-07-15 NVD CVE
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute...
admins-usersapi-endpointarbitrary-code-executionattackers-controlled-websitesauthenticate-requestscross-origin-resources-sharingcross-site-requestcve-2026-56400
2026-07-15 CISA KEV
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...
cisa-kevcompromisecve-2026-46817e-business-suitehttpimproper-privileges-managementnetwork-accessoracle
2026-07-15 CISA KEV
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security...
account-lockoutattackerbcuses-keycisa-kevcve-2023-4346device-purgeknx-protocolknxes-association
2026-07-15 CISA advisory
<p>Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a...
cisacisa-advisorycomputer-security-incident-responsecoordinated-vulnerability-disclosurecve-identifiersincident-responsensaproduct-security
2026-07-15 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-15 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-15 CISA advisory
<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
binding-operational-directivesbod-26-04cisacisa-advisorycve-2023-4346cve-2026-46817cyber-actorsfceb-agency
2026-07-15 NVD CVE
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header,...
accounts-takeoverauthentication-token-theftcontent-typescross-site-scriptingcve-2026-56398datum-urifile-extensioninline-disposition
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
2026-07-14 CISA advisory
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisorycve-2026-15409cve-2026-15410cve-2026-56155cve-2026-56164cyber-attacks
2026-07-14 NVD CVE
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14 CISA advisory
<p>CISA is aware of active exploitation of vulnerabilities <a href="https://www.cve.org/CVERecord?id=CVE-2026-32201" target="_blank">CVE-2026-32201</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-45659"...
cisacisa-advisorycve-2026-32201cve-2026-45659cve-2026-55040cve-2026-56164cve-2026-58644iis
2026-07-14 NVD CVE
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14 NVD CVE
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14 NVD CVE
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50380exploitgdiheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14 NVD CVE
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
2026-07-14 NVD CVE
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument...
buffer-overflowcooeys-clubcve-2026-15701form-logoutformlogouthtmlighttpdnetworks-devicesnvd-cve
2026-07-14 NVD CVE
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on...
applications-securitycode-executioncve-2024-50340cve-2026-47767debug-modeenvironment-variablesnvd-cvephp
2026-07-14 NVD CVE
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....
arbitrary-code-executioncoldfusioncve-2026-48284exploitimproper-input-validationinput-validationnvd-cvesecurity
2026-07-14 NVD CVE
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
authentication-bypasscisa-kevcritical-functionscve-2026-56164microsoftmissing-authenticationnetwork-securityprivileges-escalation
2026-07-14 NVD CVE
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50518dhcp-serverheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14 NVD CVE
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
arbitrary-code-executioncoldfusioncritical-functionscve-2026-48325exploitmissing-authenticationnvd-cvesecurity
2026-07-14 NVD CVE
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this...
adobe-commercearbitrary-code-executioncve-2026-48356elevated-accessmalicious-scriptsnvd-cvesession-controlunrestricted-uploads
2026-07-14 NVD CVE
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
adobe-commercearbitrary-code-executioncode-executioncve-2026-48358improper-encodingimproper-escapingnvd-cvesecurities-risks
2026-07-14 NVD CVE
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A...
adobe-experience-managersarbitrary-code-executioncve-2026-48359elevated-accessno-user-interaction-requiresnvd-cvesensitive-file-readingsession-control
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescve-2026-48319directories-traversalexploitnvd-cve
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to...
access-controlarbitrary-file-readscoldfusioncve-2026-48318directories-traversalexploitfile-system-readnvd-cve
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncoldfusioncve-2026-48324exploitationimproper-neutralizationnvd-cvescope-changesspecial-elements
2026-07-14 NVD CVE
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of...
coldfusioncve-2026-48321exploitincorrect-authorizationnvd-cveprivileges-escalationsecurityunauthorized-access
2026-07-14 NVD CVE
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller...
◀ PREV PAGE 24 / 90 NEXT ▶