LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-06-04
NVD CVE
CVE-2026-11113: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 14
CRITICAL
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted...
2026-06-04
NVD CVE
CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting in Google Chr
CRITICAL
Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape...
2026-06-04
NVD CVE
CVE-2026-50225: The registration path /v1/account/register provides no bot mitigation mechanisms
CRITICAL
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
2026-06-04
NVD CVE
CVE-2026-50214: The /v1/Plan service relies entirely on a shared global API token for full admin
CRITICAL
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
2026-06-04
NVD CVE
CVE-2026-48567: Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized atta
CRITICAL
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
2026-06-04
NVD CVE
CVE-2026-8037: OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC
CRITICAL
◈ 2 sources · orig. NVD CVE
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input...
appliance-executioncisa-kevcommand-injectionprogress-loadmastersprogress-loadmasters-vulnerabilitiesunauthenticated-attacksunsanitized-inputs
2026-06-04
NVD CVE
CVE-2026-49185: The FieldX MDM adb messaging topic passes unverified payloads directly into Runt
CRITICAL
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
2026-06-03
NVD CVE
CVE-2026-5241: A vulnerability in the LightGlue model loading path of huggingface/transformers
CRITICAL
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises...
2026-06-02
NVD CVE
CVE-2026-10611: An authentication bypass vulnerability exists in MISP when LDAP mixed authentica
CRITICAL
An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users...
2026-06-02
NVD CVE
CVE-2026-42074: OpenClaude is an open-source coding-agent command line interface for cloud and l
CRITICAL
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema,...
2026-06-01
NVD CVE
CVE-2026-22872: Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsul
CRITICAL
Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this...
2026-05-29
NVD CVE
CVE-2025-41274: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41273: Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Altern
CRITICAL
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote...
2026-05-29
NVD CVE
CVE-2025-41272: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41270: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41269: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41268: Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Adminis
CRITICAL
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete...
2026-05-29
NVD CVE
CVE-2026-49201: The upload.cgi binary, responsible for processing device backups, contains a har
CRITICAL
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
2026-05-29
NVD CVE
CVE-2026-45700: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c,...
2026-05-29
NVD CVE
CVE-2026-46376: FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, una
CRITICAL
FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not...
2026-05-29
NVD CVE
CVE-2026-49200: The acer_cgi.log file in the device firmware is accessible without authenticatio
CRITICAL
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
2026-05-29
NVD CVE
CVE-2025-41277: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2026-49199: Crafted MQTT messages can trigger command injection, resulting in root-level cod
CRITICAL
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
2026-05-29
NVD CVE
CVE-2026-49197: Web endpoints intended for the Acer Connect app improperly validate the HTTP Aut
CRITICAL
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.
2026-05-29
NVD CVE
CVE-2025-41276: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41275: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-28
NVD CVE
CVE-2026-4408: A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S
CRITICAL
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u...
2026-05-28
NVD CVE
CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote
CRITICAL
Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
2026-05-28
NVD CVE
CVE-2026-44881: Portainer Community Edition is a lightweight service delivery platform for conta
CRITICAL
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2,...
2026-05-28
NVD CVE
CVE-2026-44477: CloudNativePG is a platform designed to manage PostgreSQL databases within Kuber
CRITICAL
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres...
2026-05-27
CISA KEV
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials...
2026-05-27
CISA KEV
TanStack Unspecified Vulnerability
CRITICAL
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
2026-05-26
NVD CVE
CVE-2026-48899: An improper access check allows privilege escalation through the com_users batch
CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
2026-05-26
NVD CVE
CVE-2026-42496: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker contro
CRITICAL
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() without validating it...
2026-05-26
NVD CVE
CVE-2026-48898: An improper access check allows privilege escalation through the com_users batch
CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
2026-05-26
NVD CVE
CVE-2026-48691: FastNetMon Community Edition through 1.2.9 contains an integer overflow in the B
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as...
2026-05-26
NVD CVE
CVE-2026-35221: Improperly built filter clauses lead to a SQL injection vulnerability in the sea
CRITICAL
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
2026-05-26
NVD CVE
CVE-2026-48686: FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflo
CRITICAL
FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() in...
2026-05-26
NVD CVE
CVE-2026-35223: An improper access check allows unauthorized access to com_config webservice end
CRITICAL
An improper access check allows unauthorized access to com_config webservice endpoints.
2026-05-26
NVD CVE
CVE-2026-35222: Improperly validated order clauses lead to a SQL injection vulnerability in com_
CRITICAL
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.