Skip to content
COOEY
LIVE FEED
3560 events · 4 sources · newest first
2026-08-20 CISA advisory
<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycve-2026-72529cve-2026-72530cyber-attacksexploit-vulnerabilitiesfederal-agencies
2026-08-20 NVD CVE
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The...
cluster-compromisecluster-securitycustom-resourcecve-2026-67567helm-charthelmreleasemulticloud-operators-subscriptionnvd-cve
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17152ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20 NVD CVE
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
authorize-attackersazureazure-sql-databasecve-2026-68782database-securitymicrosoftnetwork-securityneutralization
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed...
authorization-flowcve-2026-76311dispatches-archivesembedded-reportsnvd-cvereport-managementscheduled-reportssecurity-configuration
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material,...
administrative-actionscve-2026-76310embedded-reportsnvd-cvereport-managementrest-apirole-based-accesssessions-materials
2026-08-19 NVD CVE
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack...
buffer-overflowcvecve-2026-76589firmware-vulnerabilitiesnetwork-adapternetwork-securitynvd-cveremote-attacks
2026-08-19 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
aixarbitrary-code-executioncve-2026-16919ibmimproper-validationnetwork-supplied-pointernvd-cvepowervm
2026-08-19 NVD CVE
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including,...
accounts-takeoverauthorization-bypasscve-2026-18315emails-overwritelost-password-flownvd-cveplugins-vulnerabilitiessecurity-vulnerability
2026-08-19 NVD CVE
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and...
authentication-bypassauthorization-bypasscluster-compromisecluster-proxy-addoncve-2026-66794information-disclosureinternal-service-accesskubernete
2026-08-19 NVD CVE
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument...
cgi-bincve-2026-76590nvd-cvepppoepublicly-available-exploitremote-exploitsecurity-bulletinssi
2026-08-19 NVD CVE
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC)...
certificates-signing-requestcluster-administratorsclusterrolecve-2026-70496excessive-privilegeimpersonationkubernetemanifestwork
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session...
authorization-boundariescve-2026-76312dispatches-archivesembedded-reportshtml-sourcenvd-cvereport-managementsearch-job-data
2026-08-19 CISA KEV
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
attack-vectorscisa-kevcloud-metadatacloud-securitycve-2026-64849internal-servicesmetadata-servicesmlflow
2026-08-19 NVD CVE
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based...
cve-2026-76003nvd-cveremote-attacksstack-based-buffer-overflowstrcpyuttutt-hyper-1200gwutt-hypers
2026-08-19 NVD CVE
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes...
buffer-overflowcgi-bincve-2026-75976exploitnetwork-attached-storagenvd-cvenvrremote-attacks
2026-08-19 CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycompromisecve-2026-64849cyber-attacksfederal-agenciesfederal-enterprises
2026-08-19 CISA advisory
<h2><strong>Executive summary</strong></h2> <p><em><strong>Note:</strong> This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity...
access-controlcisa-advisoriescisa-advisorycritical-infrastructuredefensedepthincident-responseinternet-exposure
2026-08-19 NVD CVE
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT...
authenticationcudycve-2026-71960firmwarehmacjwtmesh-networkingmosquitto
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low...
2026-08-18 NVD CVE
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the...
buffer-overflowcve-2026-75784cybersecurityhttps-header-handlernetwork-securitynginxnvd-cvepublic-exploit
2026-08-18 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-230-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
arbitrary-code-executioncisacisa-advisorycve-2026-19670cve-2026-19671cve-2026-55676cve-2026-63133cve-2026-63134
2026-08-18 NVD CVE
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74940firefoxfirefox-esrfreegraphic-text-componentmozillanvd-cvesecurity-patch
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74943firefoxfreegraphicimagelibmozillanvd-cvepatch
2026-08-18 NVD CVE
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-70926cvss-31cvss-98integritynetwork-access
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to...
access-controlaccess-fieldsblueprintcore-groupcve-2026-75837delegated-adminsgravgrav-2-0-14
2026-08-18 CISA KEV
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
appleauthentication-bypasscisa-kevcve-2026-65400improper-authenticationmaconetworks-attacksoperating-systems
2026-08-18 NVD CVE
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and...
api-accessesawxcredentials-theftcve-2026-12564database-credentialsdjangohashicorphashicorp-vault
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62640cvss-31iiopintegritynetwork-accessnvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62624cvss-31iiopintegritynetwork-accessnvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low...
◀ PREV PAGE 03 / 89 NEXT ▶