LIVE FEED
1776 events · 4 sources · newest first
Events in view
1776
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-05-22
NVD CVE
CVE-2026-44930: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s
CRITICAL
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to...
2026-05-22
NVD CVE
CVE-2026-33843: Authentication bypass using an alternate path or channel in Microsoft Azure Acti
CRITICAL
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
2026-05-22
NVD CVE
CVE-2026-23652: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
2026-05-21
NVD CVE
CVE-2026-48172: LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possi
CRITICAL
◈ 2 sources · orig. NVD CVE
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE...
2026-05-21
NVD CVE
CVE-2026-4858: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.
HIGH
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API...
2026-05-20
NVD CVE
CVE-2026-24214: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher
HIGH
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering,...
2026-05-20
NVD CVE
CVE-2026-24213: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher
HIGH
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data...
2026-05-20
NVD CVE
CVE-2026-33278: NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability
CRITICAL
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure...
2026-05-20
NVD CVE
CVE-2026-24163: NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where a
HIGH
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of...
2026-05-20
NVD CVE
CVE-2025-31973: HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecur
MEDIUM
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the...
2026-05-20
NVD CVE
CVE-2025-33255: NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an
HIGH
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of...
2026-05-20
NVD CVE
CVE-2026-20223: A vulnerability in the access validation of internal REST APIs of Cisco Sec
CRITICAL
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin...
2026-05-20
NVD CVE
CVE-2026-8631: A potential security vulnerability has been identified in the HP Linux Imaging a
CRITICAL
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer...
2026-05-20
NVD CVE
CVE-2026-24142: NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and u
MEDIUM
NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
2026-05-20
NVD CVE
CVE-2026-24425: Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerabi
HIGH
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to...
2026-05-20
NVD CVE
CVE-2026-24206: NVIDIA Triton Inference Server contains a vulnerability where an attacker could
HIGH
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or...
2026-05-20
NVD CVE
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1.
BIND 9 versions...
2026-05-20
NVD CVE
CVE-2026-42960: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning
CRITICAL
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used...
2026-05-19
NVD CVE
CVE-2026-47311: Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows
HIGH
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
2026-05-19
NVD CVE
CVE-2026-8605: In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al
CRITICAL
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
2026-05-19
NVD CVE
CVE-2026-8603: In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an a
CRITICAL
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
2026-05-19
NVD CVE
CVE-2026-8602: In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnera
CRITICAL
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.
2026-05-19
NVD CVE
CVE-2026-47310: Use after free vulnerability in Samsung Open Source Escargot allows Pointer Mani
HIGH
Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
2026-05-19
NVD CVE
CVE-2026-47314: Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflo
HIGH
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
2026-05-19
NVD CVE
CVE-2026-8711: NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is config
HIGH
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the...
2026-05-19
NVD CVE
CVE-2026-33642: Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the
CRITICAL
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic...
2026-05-15
NVD CVE
CVE-2026-44774: Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, an
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider...
2026-05-14
NVD CVE
CVE-2026-44484: PyTorch Lightning is a deep learning framework to pretrain and finetune AI model
CRITICAL
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
2026-05-13
NVD CVE
CVE-2026-42579: Netty is an asynchronous, event-driven network application framework. Prior to 4
HIGH
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding....
2026-05-13
NVD CVE
CVE-2026-0258: A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation o
CRITICAL
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended...
2026-05-13
NVD CVE
CVE-2026-42584: Netty is an asynchronous, event-driven network application framework. Prior to 4
HIGH
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response,...
2026-05-13
NVD CVE
CVE-2026-42581: Netty is an asynchronous, event-driven network application framework. Prior to 4
MEDIUM
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both...
2026-05-13
NVD CVE
CVE-2026-42557: jupyterlab is an extensible environment for interactive and reproducible computi
CRITICAL
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and...
2026-05-13
NVD CVE
CVE-2026-0263: A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PA
CRITICAL
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or...
2026-05-13
NVD CVE
CVE-2026-0264: A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo
CRITICAL
A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all...
2026-05-12
NVD CVE
CVE-2026-27851: When safe filter is used with variable expansion, all following pipelines on the
HIGH
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks...
2026-05-11
NVD CVE
CVE-2026-43639: Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerabili
HIGH
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST...
2026-05-11
NVD CVE
CVE-2026-8263: A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affect
MEDIUM
A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the...
2026-05-10
NVD CVE
CVE-2025-14179: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query...
2026-05-10
NVD CVE
CVE-2026-7261: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via...