LIVE FEED
1776 events · 4 sources · newest first
Events in view
1776
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-06-30
NVD CVE
CVE-2026-14120: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47
CRITICAL
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page....
2026-06-30
NVD CVE
CVE-2026-14109: Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47
CRITICAL
Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page....
2026-06-30
NVD CVE
CVE-2026-11714: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
2026-06-30
NVD CVE
CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
2026-06-30
NVD CVE
CVE-2026-14106: Insufficient validation of untrusted input in Text in Google Chrome on Android p
CRITICAL
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a...
2026-06-30
NVD CVE
CVE-2026-13782: Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remo
CRITICAL
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...
2026-06-30
NVD CVE
CVE-2026-13449: IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable
HIGH
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose...
2026-06-30
NVD CVE
CVE-2026-13785: Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allow
CRITICAL
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML...
2026-06-30
NVD CVE
CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome pr
CRITICAL
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security...
2026-06-30
NVD CVE
CVE-2026-58016: A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new
HIGH
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element...
2026-06-30
NVD CVE
CVE-2026-8452: Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CRITICAL
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy)...
2026-06-30
NVD CVE
CVE-2026-8655: Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway
CRITICAL
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler...
2026-06-30
NVD CVE
CVE-2026-14241: Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidenc
CRITICAL
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This...
2026-06-30
NVD CVE
CVE-2026-10560: IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerabi
HIGH
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a...
2026-06-30
NVD CVE
CVE-2026-13772: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language eng
HIGH
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks...
2026-06-30
NVD CVE
CVE-2026-13773: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated C
MEDIUM
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java...
2026-06-30
NVD CVE
CVE-2026-7663: IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to ac
CRITICAL
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP...
2026-06-30
NVD CVE
CVE-2026-11541: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
HIGH
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
2026-06-30
NVD CVE
CVE-2026-13775: Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote a
CRITICAL
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...
2026-06-30
NVD CVE
CVE-2026-13776: Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote
CRITICAL
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...
2026-06-30
NVD CVE
CVE-2026-13780: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 15
CRITICAL
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted...
2026-06-30
NVD CVE
CVE-2026-13781: Insufficient validation of untrusted input in Skia in Google Chrome prior to 150
CRITICAL
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML...
2026-06-29
NVD CVE
CVE-2026-56290: The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitra
CRITICAL
◈ 2 sources · orig. NVD CVE
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadcisa-kevcve-2026-56290improper-access-controljoomlackpage-builderremote-code-executionsoftware-vulnerabilities
2026-06-29
NVD CVE
CVE-2026-11720: A path traversal vulnerability exists in the HTTP tool URL builder of googleapis
CRITICAL
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox.
When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured...
2026-06-26
NVD CVE
CVE-2026-12411: Broken Access Control in the devLXDInstancePatchHandler component of Canonical L
HIGH
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over...
2026-06-26
NVD CVE
CVE-2026-31928: The DMP-5000 devices are shipped with a default administrative web account with
HIGH
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts...
2026-06-25
NVD CVE
CVE-2025-71338: Flowise contains a path traversal vulnerability in the /api/v1/document-store/lo
CRITICAL
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit...
2026-06-25
NVD CVE
CVE-2025-71333: Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerab
CRITICAL
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and...
2026-06-23
NVD CVE
CVE-2026-53622: Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a c
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass...
2026-06-23
NVD CVE
CVE-2026-48491: Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, ther
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass...
2026-06-23
NVD CVE
CVE-2026-48020: Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, an
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass...
2026-06-22
NVD CVE
CVE-2026-6653: Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.
CRITICAL
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
2026-06-22
NVD CVE
CVE-2026-49468: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
CRITICAL
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to...
2026-06-22
NVD CVE
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of...
2026-06-21
NVD CVE
CVE-2026-12773: A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the
HIGH
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy....
2026-06-20
NVD CVE
CVE-2026-48908: A vulnerability in SP Page Builder for Joomla allows unauthenticated users to up
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
arbitrary-files-uploadcisa-kevcve-2026-48908joomshaperphp-code-executionsecurities-riskssoftware-vulnerabilitiessp-page-builder
2026-06-20
NVD CVE
CVE-2026-48939: A vulnerability in the iCagenda extension for Joomla allows the upload of arbitr
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
arbitrary-files-uploadcisa-kevcve-2026-48939cybersecuritydata-protectionfiles-attachmentsicagendaincident-response
2026-06-19
NVD CVE
CVE-2026-51844: Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /go
CRITICAL
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.
2026-06-19
NVD CVE
CVE-2026-51846: In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMac
CRITICAL
In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.
2026-06-19
NVD CVE
CVE-2026-51845: Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /go
CRITICAL
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.