Skip to content
COOEY
LIVE FEED
3593 events · 4 sources · newest first
2026-07-14 NVD CVE
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri,...
2026-07-14 NVD CVE
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller...
2026-07-14 NVD CVE
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage...
adobe-experience-managersarbitrary-code-executioncve-2026-48259elevated-accessno-user-interaction-requiresnvd-cveservers-sides-requests-forgerysession-control
2026-07-14 NVD CVE
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
adobearbitrary-code-executioncve-2026-48334illustratorimproper-input-validationmalicious-filesnvd-cvesecurity
2026-07-14 NVD CVE
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an...
access-controlapplications-securityauthentication-bypasscve-2026-56451cve-trackingsimpersonationjson-web-tokenjwt-forges
2026-07-14 NVD CVE
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14 NVD CVE
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an...
apus-exploitationscompliance-riskconfidentiality-impactcredentials-exposurecve-2026-44761data-integrityhelp-portalnvd-cve
2026-07-14 NVD CVE
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system...
abapauthenticate-attackeravailabilitycmmcconfidentialitycve-2026-44747data-accessdefense-industrial-base
2026-07-14 NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint
2026-07-14 NVD CVE
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the...
availability-impactconfidentiality-impactcve-2026-27690https-requests-smugglingnvd-cverequests-responses-desynchronizationsap-approutersecurity-vulnerability
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14 NVD CVE
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and...
audience-checkauthenticationclaim-verificationcve-2026-45069expiry-checksissuer-checksjwtnvd-cve
2026-07-14 CISA advisory
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisorycve-2026-15409cve-2026-15410cve-2026-56155cve-2026-56164cyber-attacks
2026-07-14 NVD CVE
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox...
2026-07-14 NVD CVE
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
code-executioncode-execution-vulnerabilitycve-2026-56190networks-attacksnetworks-vulnerabilitiesnvd-cverdpremote-desktop-protocol
2026-07-14 NVD CVE
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
attackercross-site-scriptingcve-2026-55008exchange-serverinputs-neutralizationmicrosoftnetwork-securitynvd-cve
2026-07-14 NVD CVE
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14 NVD CVE
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14 NVD CVE
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-13 NVD CVE
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are...
access-controlcve-2026-13221false-negativefalse-positivesfilteringnvd-cveoverflowperl
2026-07-13 NVD CVE
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It...
32-bit-buildcrashes-vulnerabilitiescve-2026-40469do-subgawkheap-overflowinteger-overflownvd-cve
2026-07-13 NVD CVE
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and...
cisacmmc-level-2cve-2026-40468dodfedramp-authorizationgawkheap-metadatainteger-overflow
2026-07-13 NVD CVE
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single...
9routerai-provider-accountapi-key-exposurebilling-fraudcompliance-riskcve-2026-62327information-leakagemissing-authentication-middleware
2026-07-13 NVD CVE
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to...
9routerapi-endpointapi-keyauthentication-middlewarecompliance-riskcredentials-exposurecve-2026-59801denial
2026-07-13 NVD CVE
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote...
administrative-accessauthenticationconfigurations-featurescve-2026-61500login-responsesnon-cryptographic-generatornvd-cverejetto
2026-07-13 CISA advisory
<p>Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors</p> <h2><strong>Executive summary</strong></h2> <p>Russian Federal Security Service (FSB) Center 16...
cisa-advisory
2026-07-13 NVD CVE
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying...
cmmc-level-2command-injectioncve-2026-61498graph-generationinput-sanitizationnist-800-171nvd-cveos-command-execution
2026-07-13 NVD CVE
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
arbitrary-file-deletioncve-2026-57830extensionfile-deletionhelixes-ultimatesjoomlanvd-cvesecurity
2026-07-13 CISA KEV
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain...
cisa-kevcisco-ioscmmccommand-injectioncompliancecross-site-requests-forgerycves-2008-4128defense-industrial-base
2026-07-13 NVD CVE
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without...
cisacmmc-level-2cve-2026-4769defense-industrial-basedevices-compromisefedramp-authorizationincident-responseinternal-diagnostic
2026-07-13 CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://edit.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisoryciscocves-2008-4128cybersecurityfederal-agenciesfederal-enterprises
2026-07-12 NVD CVE
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a...
2026-07-12 NVD CVE
A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This...
cf-wr631axcomfastcommand-injectioncve-2026-15511fastcgi-backendsfile-path-manipulationnvd-cveos-command-injection
2026-07-12 NVD CVE
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise...
api-securityauthentication-bypassauthentication-middlewarecve-2026-56271default-credentialsflowisehardcoded-secretimpersonation
2026-07-12 NVD CVE
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation,...
api-serverarbitrary-file-writecrawl4aicve-2026-56260denialdockerdocker-apusendpoint-security
2026-07-11 NVD CVE
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds...
bound-readcmmccve-2026-56372defense-industrial-basedenialdodfedrampheap-buffer-overflow
2026-07-11 NVD CVE
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadcve-2026-57827files-uploadjoomlanvd-cveremote-code-executionrsfilesecurity
2026-07-11 NVD CVE
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement....
arbitrary-code-executioncodeagentcve-2026-61447cybersecuritydatum-exfiltrationenvironment-secretslarge-language-modelllm
◀ PREV PAGE 26 / 90 NEXT ▶