LIVE FEED
3593 events · 4 sources · newest first
Events in view
3593
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-07-11
NVD CVE
CVE-2026-60090: PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argume
CRITICAL
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name...
cassandracql-injectioncreate-tablescve-2026-60090cybersecuritydata-validationdatabase-securityddl-injections
2026-07-11
NVD CVE
CVE-2026-57827: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file
CRITICAL
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadcve-2026-57827files-uploadjoomlanvd-cveremote-code-executionrsfilesecurity
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2021 Q3: July - September
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2021 Q2: April - June
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2021 Q1: January - March
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2021 Q4: October - December
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2022 Q3: July - September
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2022 Q2: April - June
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2022 Q1: January - March
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2024 Q4: October - December
2024cyber-threatscybersecuritydc3-dcisedcbdcmidecemberdefense-industrial-base
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2024 Q3: July - September
augustcalendar-year-2024cyber-threatscybersecuritydc3-dcisedcbdcmidefense-industrial-base
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2025 Q4: October - December
cyber-threatscybersecuritydc3-dcisedcmdecemberdefense-industrial-basedodfiscal-year-2025
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2025 Q2: April - June
2025aprilcyber-threatscybersecuritydc3-dcisedcbdcmidefense-industrial-base
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2023 Q4: October - December
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2023 Q3: July - September
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2023 Q2: April - June
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2023 Q1: January - March
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2024 Q2: April - June
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2024 Q1: January - March
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2025 Q3: July - September
—
DC3 DCISE
<span class="fa fa-file-pdf-o"> </span> CY2025 Q1: January - March
2026-07-10
NVD CVE
CVE-2026-15300: The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'dist
CRITICAL
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via...
cve-2026-15300cybersecurityescape-functiongeo-my-wp-plugininformation-securitynumeric-validationnvd-cvephp
2026-07-10
NVD CVE
CVE-2026-15282: The Instant Appointment plugin for WordPress is vulnerable to arbitrary file upl
CRITICAL
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2....
arbitrary-files-uploadcve-2026-15282cybersecurityfile-type-validationinformation-securityinstant-appointmentnvd-cveplugin
2026-07-10
NVD CVE
CVE-2026-14894: The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CRITICAL
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type...
ajaxarbitrary-files-uploadcve-2026-14894cybersecurityfile-type-validationnoncenoprivnvd-cve
2026-07-10
NVD CVE
CVE-2026-57156: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying...
32-bit-buildcve-2026-57156cve-disclosuresfreerdpheap-buffer-overflowheap-buffers-undersizeheap-overflowinteger-overflow
2026-07-10
NVD CVE
CVE-2026-57216: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11,
MEDIUM
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect...
amqp-protocolauthentication-bypasscve-2026-57216guests-usersloopback-restrictionmessaging-brokernetwork-securitynvd-cve
2026-07-10
NVD CVE
CVE-2026-57211: RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windo
MEDIUM
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to...
cve-2026-57211dns-exfiltrationdns-smberlangmanagement-pluginsnetwork-securitynvd-cveoutbound-requests
2026-07-10
NVD CVE
CVE-2026-57158: FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 bef
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in...
buffer-overflowcmmc-level-2compliancecve-2026-23530cve-2026-57158dodfedrampfreerdp
2026-07-10
CISA advisory
<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
balbooon-formbinding-operational-directivesbod-26-04cisacisa-advisorycve-2026-48939cve-2026-56291cyber-attacks
2026-07-10
NVD CVE
CVE-2026-12761: The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) pl
CRITICAL
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due...
accounts-takeoveradministrators-accessauthentication-bypasscve-2026-12761cybersecuritydata-compromiseemail-address-verificationminiorange
2026-07-10
NVD CVE
CVE-2026-61459: MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability
CRITICAL
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security...
api-serverargument-injectionbearer-tokencluster-compromisecve-2026-61459cybersecuritydefense-industrial-baseincident-response
2026-07-10
NVD CVE
CVE-2026-59792: In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path trav
CRITICAL
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID handling was possible
code-executioncve-2026-59792cybersecuritydfar-252-204-7012incident-responseintellij-ideajetbrainnist-800-171
2026-07-10
NVD CVE
CVE-2026-61444: PraisonAI versions before 4.6.78 contain a code injection vulnerability in deplo
CRITICAL
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary...
apicode-injectioncve-2026-61444cybersecuritydeploymentnvd-cvepraiseaipython
2026-07-10
CISA KEV
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
arbitrary-files-uploadcisa-kevcve-2026-48939cybersecuritydata-protectionfiles-attachmentsicagendaincident-response
2026-07-10
CISA KEV
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
arbitrary-files-uploadbalbooon-formcybersecurityfiles-uploadjoomlanvd-cverceremote-code-execution
2026-07-10
NVD CVE
CVE-2026-15378: A flaw was found in the `guardrails-detectors` component. This vulnerability all
CRITICAL
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition...
cloud-metadata-servicescredentials-theftcve-2026-15378file-readsguardrail-detectorsinternal-networkkubernete-apiminio
2026-07-09
NVD CVE
CVE-2026-58123: Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution v
CRITICAL
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without...
api-endpointcommand-executioncybersecuritydefense-industrial-basehermes-webuihttps-requestsincident-responsenvd-cve
2026-07-09
NVD CVE
CVE-2026-58122: Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability tha
CRITICAL
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed...
accesses-tokenapi-keyauthentication-bypasscloud-metadata-endpointcve-2026-58122device-code-flowheaderhermes-webui
2026-07-09
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-03.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Schneider Electric is aware of a vulnerability in...
best-practicecisacisa-advisorycritical-infrastructurecritical-manufacturingcsafcve-2026-4832cwe-798
2026-07-09
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
arbitrary-code-executionauthenticate-attackercisacisa-advisorycritical-infrastructurecritical-manufacturingcve-2026-14480cwes-73