LIVE FEED
1776 events · 4 sources · newest first
Events in view
1776
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-06-19
NVD CVE
CVE-2026-51843: Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /go
CRITICAL
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.
2026-06-18
NVD CVE
CVE-2026-11718: An authentication bypass vulnerability exists in the generic opaque token valida
CRITICAL
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.
When the toolbox validates an opaque token via an OAuth 2.0 introspection...
2026-06-18
NVD CVE
CVE-2026-11717: An authentication bypass vulnerability exists in the generic opaque token valida
CRITICAL
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.
When verifying an unparsed opaque token via an OAuth 2.0 introspection...
2026-06-18
NVD CVE
CVE-2026-55203: HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vul
HIGH
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535...
2026-06-18
NVD CVE
CVE-2026-12569: A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CRITICAL
◈ 2 sources · orig. NVD CVE
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory...
2026-06-18
NVD CVE
CVE-2026-9158: In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE conne
CRITICAL
In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory...
2026-06-17
NVD CVE
CVE-2026-30803: Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core
CRITICAL
Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0.
2026-06-17
NVD CVE
CVE-2026-3894: Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) al
CRITICAL
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before...
2026-06-16
NVD CVE
CVE-2026-12293: Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed i
CRITICAL
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
2026-06-12
NVD CVE
CVE-2026-44170: MariaDB server is a community developed fork of MySQL server. From versions 10.6
CRITICAL
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with...
2026-06-12
NVD CVE
CVE-2026-44172: MariaDB server is a community developed fork of MySQL server. In versions 3.3.18
CRITICAL
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the...
2026-06-12
NVD CVE
CVE-2026-50085: The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command paylo
HIGH
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication...
2026-06-12
NVD CVE
CVE-2026-50083: The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client c
CRITICAL
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS...
2026-06-12
NVD CVE
CVE-2026-49875: Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct
CRITICAL
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
external entity resolution. Users...
2026-06-12
NVD CVE
CVE-2026-50627: The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Aud
CRITICAL
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a...
2026-06-12
NVD CVE
CVE-2026-45674: Netty is a network application framework for development of protocol servers and
HIGH
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME...
2026-06-12
NVD CVE
CVE-2026-47691: Netty is a network application framework for development of protocol servers and
HIGH
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS...
2026-06-12
NVD CVE
CVE-2026-50628: A logic error in OAuthRequestFilter rejects legitimate requests originating from
CRITICAL
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadvertently creates...
2026-06-12
NVD CVE
CVE-2026-50086: The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round
CRITICAL
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical...
2026-06-11
NVD CVE
CVE-2026-41699: Spring for GraphQL applications are vulnerable to Unsafe Deserialization when pr
HIGH
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the...
2026-06-11
NVD CVE
CVE-2026-49261: MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 th
CRITICAL
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled...
2026-06-10
NVD CVE
CVE-2026-0274: An improper validation of credentials vulnerability in the CommvaultSecurityIQ i
CRITICAL
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
2026-06-10
NVD CVE
CVE-2026-26240: A buffer overflow vulnerability has been reported to affect File Station 5. The
CRITICAL
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the...
2026-06-10
NVD CVE
CVE-2026-26241: A buffer overflow vulnerability has been reported to affect File Station 5. The
CRITICAL
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the...
2026-06-10
NVD CVE
CVE-2025-66276: QuTS hero is not affected.
We have already fixed the vulnerability in the follo
CRITICAL
QuTS hero is not affected.
We have already fixed the vulnerability in the following version:
QTS 5.2.7.3256 build 20250913 and later
2026-06-09
NVD CVE
CVE-2026-34691: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af
CRITICAL
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into...
2026-06-09
NVD CVE
CVE-2026-47932: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limi
HIGH
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the...
2026-06-09
NVD CVE
CVE-2026-41855: In an untrusted JMS environment, org.springframework.jms.support.converter.Mappi
HIGH
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class...
2026-06-09
NVD CVE
CVE-2026-44083: An authorization bypass through user-controlled key vulnerability has been repor
CRITICAL
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges.
We have already fixed the...
2026-06-09
NVD CVE
CVE-2026-46749: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update
HIGH
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and...
2026-06-09
NVD CVE
CVE-2026-10523: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10
CRITICAL
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full...
2026-06-09
NVD CVE
CVE-2026-47928: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Inpu
CRITICAL
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue...
2026-06-09
NVD CVE
CVE-2026-47929: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Aut
HIGH
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker...
2026-06-09
NVD CVE
CVE-2026-47931: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Inpu
HIGH
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high...
2026-06-09
NVD CVE
CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Erro
CRITICAL
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length...
2026-06-08
NVD CVE
CVE-2026-46441: Flowise is a drag & drop user interface to build a customized large language mod
CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint...
2026-06-08
NVD CVE
CVE-2026-46442: Flowise is a drag & drop user interface to build a customized large language mod
CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or...
2026-06-08
NVD CVE
CVE-2026-46440: Flowise is a drag & drop user interface to build a customized large language mod
CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct...
2026-06-08
NVD CVE
CVE-2026-42861: Flowise is a drag & drop user interface to build a customized large language mod
CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. The endpoint...
2026-06-05
NVD CVE
CVE-2026-48907: A vulnerability in the JCE editor extension for Joomla allows the creation of ne
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.