Skip to content
COOEY
LIVE FEED
3593 events · 4 sources · newest first
2026-07-09 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
authenticationcisa-advisorycommunicationcritical-infrastructurecve-2026-2399cve-2026-2400cve-2026-2401cve-2026-2402
2026-07-09 NVD CVE
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.
applications-securitybieticaretcve-2026-5955cybersecuritydata-securityinrove-softwarenvd-cvesoftware-vulnerabilities
2026-07-09 NVD CVE
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through...
cross-site-scriptingcybersecuritydisclosureinput-validationnvd-cveoceanicsoftsoftware-vulnerabilitiesstoreds-xss
2026-07-09 NVD CVE
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering...
arbitrary-files-uploadblocksy-companionblocksy-companion-procustom-fontscve-2026-15158file-extensionmime-validationnvd-cve
2026-07-09 NVD CVE
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is...
accounts-takeoveradministrator-accounts-takeoverauthentication-bypasscve-2026-14245form-noncejavascriptminiorangenonce
2026-07-09 NVD CVE
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcustomer-voicecve-2026-47646cybersecuritydynamics-365information-securityinput-validationmicrosoft
2026-07-09 NVD CVE
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation...
2026-07-09 NVD CVE
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially...
cloud-ngfwcve-2026-0284data-corruptioninformation-disclosurelsvpnmalicious-contentsnetwork-accessnot-impacted
2026-07-09 NVD CVE
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after...
ai-platformauthentication-bypasscisacode-executioncve-2026-59216dodnist-800-171nvd-cve
2026-07-09 NVD CVE
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by...
arbitrary-shell-command-executionbackticks-payloadscommand-escapingcommand-injectioncommit-4c06658cve-2026-58459gnuplotgpsd
2026-07-09 NVD CVE
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
arbitrary-file-writeblob-ymlbosh-clicli-toolcloud-foundrycodecve-2026-47826datum-exfiltration
2026-07-09 NVD CVE
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that...
ai-platformauthenticate-requestsclient-side-pythoncve-2026-59214cybersecuritydata-exposureendpoint-securitynvd-cve
2026-07-09 NVD CVE
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadbalbooon-formcybersecurityfiles-uploadjoomlanvd-cverceremote-code-execution
2026-07-08 NVD CVE
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
cmmccve-2026-8801cybersecuritydata-exposuredfar-252-204-7012federal-acquisition-regulationfiles-uploadincident-response
2026-07-08 NVD CVE
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
clients-sidescve-2026-60002cybersecuritydefense-industrial-basedfar-252-204-7012freehost-keyinformation-security
2026-07-08 NVD CVE
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the...
blocksy-companion-pro-plugincustom-fonts-extensionscve-2026-58480cybersecurityextension-validationfiles-uploadnvd-cvephp
2026-07-08 NVD CVE
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 08072026. NOTE: The...
cve-2026-8307cybersecuritydatabase-securityimproper-neutralizationmedikum-webnvd-cvesecurity-flawsql-injection
2026-07-08 NVD CVE
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an...
arbitrary-code-executionauthorization-bypasscve-2026-12153cybersecuritynvd-cveplugin-activationplugin-installationplugins-vulnerabilities
2026-07-08 NVD CVE
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the...
cve-2026-9700cve-2026-9701eventer-pluginnvd-cvepassword-resetphpphp-74plaintext
2026-07-08 NVD CVE
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes...
arbitrary-file-deletionauthenticationauthorizationcve-2026-14487cybersecurityfile-path-validationfile-removalhash-checks
2026-07-08 NVD CVE
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte...
2026-07-08 NVD CVE
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the...
2026-07-08 NVD CVE
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history,...
2026-07-08 NVD CVE
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare...
2026-07-08 NVD CVE
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
cve-2026-8649cybersecuritydata-querydata-securitydefense-industrial-basefederal-acquisition-regulationimproper-neutralizationmoveit
2026-07-08 NVD CVE
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
api-connectcve-2026-9074cybersecuritydata-securitydefense-industrial-baseibmincident-responsenist-800-171
2026-07-08 NVD CVE
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
api-connectcredentials-managementcve-2026-3144cybersecuritydata-exposuredefault-credentialsdefense-industrial-baseibm
2026-07-07 CISA advisory
<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
authorization-bypassbinding-operational-directivesbod-26-04cisacisa-advisorycvecve-2026-48908cve-2026-55255
2026-07-07 NVD CVE
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s...
account-compromiseadministrator-privilegesarcgicve-2026-13020cybersecurityemail-serveresriinformation-security
2026-07-07 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
arbitrary-code-executionbound-writecisacisa-advisorycommunicationcritical-infrastructurecritical-manufacturingcve-2026-42953
2026-07-07 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Hitachi Energy is aware of insecure HTTP...
cisacisa-advisorycredentials-theftcritical-infrastructurecve-2026-10763cwe-1428cybersecuritydefense
2026-07-07 NVD CVE
mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without...
apiarbitrary-accessescve-2026-59705cybersecuritydata-breachesdata-exposuredenialincident-response
2026-07-07 CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
actives-exploitationsadobebinding-operational-directivesbod-26-04cisacisa-advisorycoldfusioncve-2026-48282
2026-07-07 NVD CVE
mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve...
api-keycloud-imdsconfiguration-managementcve-2026-59706cybersecuritydata-exposuredefense-industrial-basenist-800-171
2026-07-07 NVD CVE
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings...
cogneeconfiguration-overwritecve-2026-58473data-breachesdatum-exfiltrationendpoint-securityimproper-access-controlinstance-wide-impact
2026-07-07 NVD CVE
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter...
cve-2026-14345cybersecurityinclude-oncelog-filenvd-cvephppluginremote-code-execution
2026-07-07 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Mendix Studio Pro versions before V11.12 are...
arbitrary-code-executionbuild-pipelinecisa-advisorycode-injectioncontrol-systems-securitycritical-manufacturingcve-2026-48192cwes-94
2026-07-07 CISA KEV
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
adobearbitrary-code-executioncisa-kevcoldfusioncve-2026-48282cybersecurityincident-responsepath-traversal
2026-07-07 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
authenticationbackendcanadacharging-stationscisa-advisorycritical-infrastructurecve-2026-20744cve-2026-42952
2026-07-07 CISA KEV
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
arbitrary-files-uploadcisa-kevcve-2026-56290improper-access-controljoomlackpage-builderremote-code-executionsoftware-vulnerabilities
◀ PREV PAGE 28 / 90 NEXT ▶