LIVE FEED
1776 events · 4 sources · newest first
Events in view
1776
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-05-29
NVD CVE
CVE-2026-49199: Crafted MQTT messages can trigger command injection, resulting in root-level cod
CRITICAL
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
2026-05-29
NVD CVE
CVE-2025-41275: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41274: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41273: Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Altern
CRITICAL
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote...
2026-05-29
NVD CVE
CVE-2025-41272: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41269: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41270: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41268: Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Adminis
CRITICAL
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete...
2026-05-29
NVD CVE
CVE-2026-49201: The upload.cgi binary, responsible for processing device backups, contains a har
CRITICAL
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
2026-05-29
NVD CVE
CVE-2026-49200: The acer_cgi.log file in the device firmware is accessible without authenticatio
CRITICAL
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
2026-05-29
NVD CVE
CVE-2026-49197: Web endpoints intended for the Acer Connect app improperly validate the HTTP Aut
CRITICAL
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.
2026-05-29
NVD CVE
CVE-2026-48501: GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub
HIGH
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh...
2026-05-29
NVD CVE
CVE-2026-10064: A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects
MEDIUM
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name results in...
2026-05-28
NVD CVE
CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote
CRITICAL
Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
2026-05-28
NVD CVE
CVE-2026-4408: A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S
CRITICAL
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u...
2026-05-28
NVD CVE
CVE-2026-44477: CloudNativePG is a platform designed to manage PostgreSQL databases within Kuber
CRITICAL
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres...
2026-05-28
NVD CVE
CVE-2026-44881: Portainer Community Edition is a lightweight service delivery platform for conta
CRITICAL
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2,...
2026-05-26
NVD CVE
CVE-2026-48691: FastNetMon Community Edition through 1.2.9 contains an integer overflow in the B
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as...
2026-05-26
NVD CVE
CVE-2026-40383: An improper validation of user-supplied input leads to a local file inclusion vu
CRITICAL
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
2026-05-26
NVD CVE
CVE-2026-48689: FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buf
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer,...
2026-05-26
NVD CVE
CVE-2026-48904: An improper access check allows privelege escalation through the com_users group
CRITICAL
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
2026-05-26
NVD CVE
CVE-2026-48899: An improper access check allows privilege escalation through the com_users batch
CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
2026-05-26
NVD CVE
CVE-2026-48898: An improper access check allows privilege escalation through the com_users batch
CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
2026-05-26
NVD CVE
CVE-2026-44723: Vowpal Wabbit is a machine learning system. The workflow .github/workflows/pytho
MEDIUM
Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four...
2026-05-26
NVD CVE
CVE-2026-35221: Improperly built filter clauses lead to a SQL injection vulnerability in the sea
CRITICAL
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
2026-05-26
NVD CVE
CVE-2026-24212: NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive infor
HIGH
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,...
2026-05-26
NVD CVE
CVE-2025-36220: IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl
MEDIUM
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow...
2026-05-26
NVD CVE
CVE-2026-48686: FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflo
CRITICAL
FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() in...
2026-05-26
NVD CVE
CVE-2026-35223: An improper access check allows unauthorized access to com_config webservice end
CRITICAL
An improper access check allows unauthorized access to com_config webservice endpoints.
2026-05-26
NVD CVE
CVE-2026-8376: Perl versions through 5.43.10 have a heap buffer overflow when compiling regular
CRITICAL
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the joined...
2026-05-26
NVD CVE
CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
HIGH
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
2026-05-26
NVD CVE
CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
HIGH
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
2026-05-26
NVD CVE
CVE-2026-44966: Velocity.js is a JavaScript implementation of the Apache Velocity template engin
HIGH
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of...
2026-05-26
NVD CVE
CVE-2026-44985: Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSo
CRITICAL
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade...
2026-05-26
NVD CVE
CVE-2026-35222: Improperly validated order clauses lead to a SQL injection vulnerability in com_
CRITICAL
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
2026-05-26
NVD CVE
CVE-2026-48687: FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118)...
2026-05-26
NVD CVE
CVE-2026-42496: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker contro
CRITICAL
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() without validating it...
2026-05-22
NVD CVE
CVE-2026-8673: Unprotected transport of credentials vulnerability in syslink software AG Avantr
MEDIUM
Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks.
This issue affects Avantra: before 25.3.0.
2026-05-22
NVD CVE
CVE-2026-47280: Improper authentication in Azure Resource Manager (ARM) allows an unauthorized a
CRITICAL
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
2026-05-22
NVD CVE
CVE-2026-40412: Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows a
CRITICAL
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.