LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-05-26
NVD CVE
CVE-2026-48687: FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118)...
2026-05-26
NVD CVE
CVE-2026-40383: An improper validation of user-supplied input leads to a local file inclusion vu
CRITICAL
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
2026-05-26
NVD CVE
CVE-2026-44985: Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSo
CRITICAL
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade...
2026-05-26
NVD CVE
CVE-2026-48689: FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buf
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer,...
2026-05-26
NVD CVE
CVE-2026-8376: Perl versions through 5.43.10 have a heap buffer overflow when compiling regular
CRITICAL
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the joined...
2026-05-26
NVD CVE
CVE-2026-48904: An improper access check allows privelege escalation through the com_users group
CRITICAL
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
2026-05-22
NVD CVE
CVE-2026-40412: Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows a
CRITICAL
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
2026-05-22
NVD CVE
CVE-2026-47280: Improper authentication in Azure Resource Manager (ARM) allows an unauthorized a
CRITICAL
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
2026-05-22
NVD CVE
CVE-2026-44930: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s
CRITICAL
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to...
2026-05-22
NVD CVE
CVE-2026-23652: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
2026-05-22
NVD CVE
CVE-2026-33843: Authentication bypass using an alternate path or channel in Microsoft Azure Acti
CRITICAL
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
2026-05-21
NVD CVE
CVE-2026-48172: LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possi
CRITICAL
◈ 2 sources · orig. NVD CVE
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE...
2026-05-20
NVD CVE
CVE-2026-20223: A vulnerability in the access validation of internal REST APIs of Cisco Sec
CRITICAL
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin...
2026-05-20
NVD CVE
CVE-2026-33278: NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability
CRITICAL
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure...
2026-05-20
NVD CVE
CVE-2026-8631: A potential security vulnerability has been identified in the HP Linux Imaging a
CRITICAL
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer...
2026-05-20
NVD CVE
CVE-2026-42960: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning
CRITICAL
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used...
2026-05-19
NVD CVE
CVE-2026-33642: Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the
CRITICAL
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic...
2026-05-19
NVD CVE
CVE-2026-8602: In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnera
CRITICAL
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.
2026-05-19
NVD CVE
CVE-2026-8603: In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an a
CRITICAL
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
2026-05-19
NVD CVE
CVE-2026-8605: In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al
CRITICAL
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
2026-05-15
NVD CVE
CVE-2026-44774: Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, an
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider...
2026-05-14
NVD CVE
CVE-2026-44484: PyTorch Lightning is a deep learning framework to pretrain and finetune AI model
CRITICAL
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
2026-05-13
NVD CVE
CVE-2026-0258: A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation o
CRITICAL
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended...
2026-05-13
NVD CVE
CVE-2026-0263: A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PA
CRITICAL
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or...
2026-05-13
NVD CVE
CVE-2026-42557: jupyterlab is an extensible environment for interactive and reproducible computi
CRITICAL
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and...
2026-05-13
NVD CVE
CVE-2026-0264: A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo
CRITICAL
A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all...
2026-05-10
NVD CVE
CVE-2026-7261: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via...
2026-05-10
NVD CVE
CVE-2026-6722: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without...
2026-05-10
NVD CVE
CVE-2026-6104: In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam
CRITICAL
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that...
2026-05-10
NVD CVE
CVE-2025-14179: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query...
2026-05-09
NVD CVE
CVE-2026-42257: Net::IMAP implements Internet Message Access Protocol (IMAP) client functionalit
CRITICAL
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the...
2026-05-09
NVD CVE
CVE-2026-42601: ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6
CRITICAL
ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without...
2026-05-08
NVD CVE
CVE-2026-42298: Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Re
CRITICAL
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any...
2026-05-08
NVD CVE
CVE-2026-42354: Sentry is an error tracking and performance monitoring tool. From version 21.12.
CRITICAL
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows...
2026-05-08
NVD CVE
CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
CRITICAL
◈ 2 sources · orig. NVD CVE
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key...
2026-05-07
NVD CVE
CVE-2026-41586: Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framew
CRITICAL
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes...
2026-05-07
NVD CVE
CVE-2026-7891: A vulnerability has been identified in Mendix Runtime (All versions). Mendix doc
CRITICAL
A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without...
2026-05-07
NVD CVE
CVE-2026-42216: OpenEXR provides the specification and reference implementation of the EXR file
CRITICAL
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0...
2026-05-05
NVD CVE
CVE-2026-34084: PhpSpreadsheet is a library for reading and writing spreadsheet files. In versio
CRITICAL
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename...
2026-05-05
NVD CVE
CVE-2026-35579: CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QU
CRITICAL
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the...