LIVE FEED
3593 events · 4 sources · newest first
Events in view
3593
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-07-14
NVD CVE
CVE-2026-10672: subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI
HIGH
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri,...
2026-07-14
NVD CVE
CVE-2026-54058: Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncomp
CRITICAL
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller...
2026-07-14
NVD CVE
CVE-2026-48259: Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vul
CRITICAL
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage...
adobe-experience-managersarbitrary-code-executioncve-2026-48259elevated-accessno-user-interaction-requiresnvd-cveservers-sides-requests-forgerysession-control
2026-07-14
NVD CVE
CVE-2026-48334: Illustrator is affected by an Improper Input Validation vulnerability that could
CRITICAL
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
adobearbitrary-code-executioncve-2026-48334illustratorimproper-input-validationmalicious-filesnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-56451: A vulnerability has been identified in Opcenter X (All versions < V2604). Affect
CRITICAL
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
This could allow an...
access-controlapplications-securityauthentication-bypasscve-2026-56451cve-trackingsimpersonationjson-web-tokenjwt-forges
2026-07-14
NVD CVE
CVE-2026-48561: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14
NVD CVE
CVE-2026-44761: SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented
CRITICAL
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an...
apus-exploitationscompliance-riskconfidentiality-impactcredentials-exposurecve-2026-44761data-integrityhelp-portalnvd-cve
2026-07-14
NVD CVE
CVE-2026-44747: SAP NetWeaver Application Server ABAP allows an authenticated attacker to levera
CRITICAL
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system...
abapauthenticate-attackeravailabilitycmmcconfidentialitycve-2026-44747data-accessdefense-industrial-base
2026-07-14
NVD CVE
CVE-2026-50522: Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint
2026-07-14
NVD CVE
CVE-2026-27690: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthentica
CRITICAL
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the...
availability-impactconfidentiality-impactcve-2026-27690https-requests-smugglingnvd-cverequests-responses-desynchronizationsap-approutersecurity-vulnerability
2026-07-14
NVD CVE
CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacke
CRITICAL
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14
NVD CVE
CVE-2026-45069: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and...
audience-checkauthenticationclaim-verificationcve-2026-45069expiry-checksissuer-checksjwtnvd-cve
2026-07-14
CISA advisory
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisorycve-2026-15409cve-2026-15410cve-2026-56155cve-2026-56164cyber-attacks
2026-07-14
NVD CVE
CVE-2026-46634: Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_stri
CRITICAL
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox...
2026-07-14
NVD CVE
CVE-2026-56190: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to
CRITICAL
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
code-executioncode-execution-vulnerabilitycve-2026-56190networks-attacksnetworks-vulnerabilitiesnvd-cverdpremote-desktop-protocol
2026-07-14
NVD CVE
CVE-2026-55008: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
attackercross-site-scriptingcve-2026-55008exchange-serverinputs-neutralizationmicrosoftnetwork-securitynvd-cve
2026-07-14
NVD CVE
CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unautho
HIGH
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau
HIGH
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14
NVD CVE
CVE-2026-49181: Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthor
HIGH
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-54118: Deserialization of untrusted data in SQL Server allows an unauthorized attacker
CRITICAL
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-13
NVD CVE
CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression match
CRITICAL
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.
When such branches are...
access-controlcve-2026-13221false-negativefalse-positivesfilteringnvd-cveoverflowperl
2026-07-13
NVD CVE
CVE-2026-40469: Integer overflow vulnerability has been found in "builtin.c" program file of gaw
CRITICAL
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It...
32-bit-buildcrashes-vulnerabilitiescve-2026-40469do-subgawkheap-overflowinteger-overflownvd-cve
2026-07-13
NVD CVE
CVE-2026-40468: Integer overflow vulnerability has been found in "builtin.c" program file of gaw
CRITICAL
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and...
cisacmmc-level-2cve-2026-40468dodfedramp-authorizationgawkheap-metadatainteger-overflow
2026-07-13
NVD CVE
CVE-2026-62327: 9Router through version 0.4.41 contain an unauthenticated information disclosure
CRITICAL
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single...
9routerai-provider-accountapi-key-exposurebilling-fraudcompliance-riskcve-2026-62327information-leakagemissing-authentication-middleware
2026-07-13
NVD CVE
CVE-2026-59801: 9Router through version 0.4.41 contains an unauthenticated access vulnerability
CRITICAL
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to...
9routerapi-endpointapi-keyauthentication-middlewarecompliance-riskcredentials-exposurecve-2026-59801denial
2026-07-13
NVD CVE
CVE-2026-61500: Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the
CRITICAL
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote...
administrative-accessauthenticationconfigurations-featurescve-2026-61500login-responsesnon-cryptographic-generatornvd-cverejetto
2026-07-13
CISA advisory
<p>Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors</p>
<h2><strong>Executive summary</strong></h2>
<p>Russian Federal Security Service (FSB) Center 16...
cisa-advisory
2026-07-13
NVD CVE
CVE-2026-61498: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerabi
CRITICAL
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying...
cmmc-level-2command-injectioncve-2026-61498graph-generationinput-sanitizationnist-800-171nvd-cveos-command-execution
2026-07-13
NVD CVE
CVE-2026-57830: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrar
CRITICAL
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
arbitrary-file-deletioncve-2026-57830extensionfile-deletionhelixes-ultimatesjoomlanvd-cvesecurity
2026-07-13
CISA KEV
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain...
cisa-kevcisco-ioscmmccommand-injectioncompliancecross-site-requests-forgerycves-2008-4128defense-industrial-base
2026-07-13
NVD CVE
CVE-2026-4769: Certain devices in the WAGO System I/O Field series activate an internal diagnos
CRITICAL
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without...
cisacmmc-level-2cve-2026-4769defense-industrial-basedevices-compromisefedramp-authorizationincident-responseinternal-diagnostic
2026-07-13
CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://edit.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisoryciscocves-2008-4128cybersecurityfederal-agenciesfederal-enterprises
2026-07-12
NVD CVE
CVE-2026-10666: parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for string
HIGH
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a...
2026-07-12
NVD CVE
CVE-2026-15511: A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected
CRITICAL
A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This...
cf-wr631axcomfastcommand-injectioncve-2026-15511fastcgi-backendsfile-path-manipulationnvd-cveos-command-injection
2026-07-12
NVD CVE
CVE-2026-56271: Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded
CRITICAL
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise...
api-securityauthentication-bypassauthentication-middlewarecve-2026-56271default-credentialsflowisehardcoded-secretimpersonation
2026-07-12
NVD CVE
CVE-2026-56260: Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Dock
CRITICAL
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation,...
api-serverarbitrary-file-writecrawl4aicve-2026-56260denialdockerdocker-apusendpoint-security
2026-07-11
NVD CVE
CVE-2026-56372: ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the
LOW
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds...
bound-readcmmccve-2026-56372defense-industrial-basedenialdodfedrampheap-buffer-overflow
2026-07-11
NVD CVE
CVE-2026-57827: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file
CRITICAL
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadcve-2026-57827files-uploadjoomlanvd-cveremote-code-executionrsfilesecurity
2026-07-11
NVD CVE
CVE-2026-61447: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAg
CRITICAL
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement....
arbitrary-code-executioncodeagentcve-2026-61447cybersecuritydatum-exfiltrationenvironment-secretslarge-language-modelllm