Skip to content
COOEY
LIVE FEED
3593 events · 4 sources · newest first
2026-07-11 NVD CVE
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name...
cassandracql-injectioncreate-tablescve-2026-60090cybersecuritydata-validationdatabase-securityddl-injections
2026-07-11 NVD CVE
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadcve-2026-57827files-uploadjoomlanvd-cveremote-code-executionrsfilesecurity
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2021 Q3: July - September
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2021 Q2: April - June
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2021 Q1: January - March
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2021 Q4: October - December
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2022 Q3: July - September
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2022 Q2: April - June
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2022 Q1: January - March
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2024 Q4: October - December
2024cyber-threatscybersecuritydc3-dcisedcbdcmidecemberdefense-industrial-base
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2024 Q3: July - September
augustcalendar-year-2024cyber-threatscybersecuritydc3-dcisedcbdcmidefense-industrial-base
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2025 Q4: October - December
cyber-threatscybersecuritydc3-dcisedcmdecemberdefense-industrial-basedodfiscal-year-2025
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2025 Q2: April - June
2025aprilcyber-threatscybersecuritydc3-dcisedcbdcmidefense-industrial-base
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2023 Q4: October - December
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2023 Q3: July - September
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2023 Q2: April - June
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2023 Q1: January - March
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2024 Q2: April - June
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2024 Q1: January - March
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2025 Q3: July - September
DC3 DCISE
<span class="fa fa-file-pdf-o">&nbsp;</span>&nbsp;CY2025 Q1: January - March
2026-07-10 NVD CVE
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via...
cve-2026-15300cybersecurityescape-functiongeo-my-wp-plugininformation-securitynumeric-validationnvd-cvephp
2026-07-10 NVD CVE
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2....
arbitrary-files-uploadcve-2026-15282cybersecurityfile-type-validationinformation-securityinstant-appointmentnvd-cveplugin
2026-07-10 NVD CVE
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type...
ajaxarbitrary-files-uploadcve-2026-14894cybersecurityfile-type-validationnoncenoprivnvd-cve
2026-07-10 NVD CVE
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying...
32-bit-buildcve-2026-57156cve-disclosuresfreerdpheap-buffer-overflowheap-buffers-undersizeheap-overflowinteger-overflow
2026-07-10 NVD CVE
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect...
amqp-protocolauthentication-bypasscve-2026-57216guests-usersloopback-restrictionmessaging-brokernetwork-securitynvd-cve
2026-07-10 NVD CVE
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to...
cve-2026-57211dns-exfiltrationdns-smberlangmanagement-pluginsnetwork-securitynvd-cveoutbound-requests
2026-07-10 NVD CVE
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in...
buffer-overflowcmmc-level-2compliancecve-2026-23530cve-2026-57158dodfedrampfreerdp
2026-07-10 CISA advisory
<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
balbooon-formbinding-operational-directivesbod-26-04cisacisa-advisorycve-2026-48939cve-2026-56291cyber-attacks
2026-07-10 NVD CVE
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due...
accounts-takeoveradministrators-accessauthentication-bypasscve-2026-12761cybersecuritydata-compromiseemail-address-verificationminiorange
2026-07-10 NVD CVE
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security...
api-serverargument-injectionbearer-tokencluster-compromisecve-2026-61459cybersecuritydefense-industrial-baseincident-response
2026-07-10 NVD CVE
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
code-executioncve-2026-59792cybersecuritydfar-252-204-7012incident-responseintellij-ideajetbrainnist-800-171
2026-07-10 NVD CVE
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary...
apicode-injectioncve-2026-61444cybersecuritydeploymentnvd-cvepraiseaipython
2026-07-10 CISA KEV
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
arbitrary-files-uploadcisa-kevcve-2026-48939cybersecuritydata-protectionfiles-attachmentsicagendaincident-response
2026-07-10 CISA KEV
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
arbitrary-files-uploadbalbooon-formcybersecurityfiles-uploadjoomlanvd-cverceremote-code-execution
2026-07-10 NVD CVE
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition...
cloud-metadata-servicescredentials-theftcve-2026-15378file-readsguardrail-detectorsinternal-networkkubernete-apiminio
2026-07-09 NVD CVE
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without...
api-endpointcommand-executioncybersecuritydefense-industrial-basehermes-webuihttps-requestsincident-responsenvd-cve
2026-07-09 NVD CVE
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed...
accesses-tokenapi-keyauthentication-bypasscloud-metadata-endpointcve-2026-58122device-code-flowheaderhermes-webui
2026-07-09 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Schneider Electric is aware of a vulnerability in...
best-practicecisacisa-advisorycritical-infrastructurecritical-manufacturingcsafcve-2026-4832cwe-798
2026-07-09 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
arbitrary-code-executionauthenticate-attackercisacisa-advisorycritical-infrastructurecritical-manufacturingcve-2026-14480cwes-73
◀ PREV PAGE 27 / 90 NEXT ▶