LIVE FEED
1573 events · 4 sources · newest first
Events in view
1573
all sources
Critical
0
severity
Active sources
4
collectors
Last sync
2026-08-25 18:00
UTC
2026-07-21
CISA KEV
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
arbitrary-code-executioncisa-kevcve-2026-0770cybersecurityfunctionalityinclusionlangflowremote-attacks
2026-07-21
CISA KEV
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain...
cisa-kevcve-2026-60137cve-2026-63030cybersecurityinformation-securityplugins-vulnerabilitiesremote-code-executionsoftware-vulnerabilities
2026-07-21
CISA KEV
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
cisa-kevcve-2026-60137cve-2026-63030cybersecurityremote-code-executionsoftware-vulnerabilitiessql-injectionvulnerability
2026-07-21
CISA KEV
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
buffer-overflowcisa-kevcode-executioncve-2021-27137cybersecuritydd-wrtinformation-securitynetworks-devices
2026-07-21
NVD CVE
CVE-2026-56820: Netty is a network application framework for development of protocol servers and
HIGH
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the...
2026-07-20
NVD CVE
CVE-2026-28220: Wazuh is a free and open source platform used for threat prevention, detection,
HIGH
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to...
2026-07-20
NVD CVE
CVE-2026-41521: xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer
HIGH
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send...
2026-07-20
NVD CVE
CVE-2026-12341: This vulnerability
impacts all versions of IdentityIQ and allows an unauthentica
HIGH
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
2026-07-18
NVD CVE
CVE-2026-15631: Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail
HIGH
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
2026-07-18
NVD CVE
CVE-2026-16158: Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 b
HIGH
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source...
2026-07-17
NVD CVE
CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
HIGH
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker...
2026-07-17
NVD CVE
CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
HIGH
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems...
agent-componentapi-v1code-act-agentcsv-agentcve-2026-13448denialflow-idibm
2026-07-16
CISA KEV
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
cisa-kevcommand-injectioncve-2026-39808fortinetfortisandboxhttps-requestsos-command-injectionsecurity-vulnerability
2026-07-16
CISA KEV
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
cisa-kevcloud-platformcloud-securitycommand-injectioncrafted-requestscve-2026-25089fortinetfortisandbox
2026-07-16
CISA KEV
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
attack-vectorscode-executioncve-2026-58644datum-exfiltrationdeserializationexploitmicrosoftmicrosoft-office
2026-07-15
NVD CVE
CVE-2026-20157: As part of Cisco's ongoing commitment to proactive security and product quality,
HIGH
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-15
CISA KEV
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security...
account-lockoutattackerbcuses-keycisa-kevcve-2023-4346device-purgeknx-protocolknxes-association
2026-07-15
NVD CVE
CVE-2026-56398: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in
HIGH
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header,...
accounts-takeoverauthentication-token-theftcontent-typescross-site-scriptingcve-2026-56398datum-urifile-extensioninline-disposition
2026-07-15
NVD CVE
CVE-2026-56400: open-webui before 0.3.14 contains a cross-origin resource sharing misconfigurati
HIGH
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute...
admins-usersapi-endpointarbitrary-code-executionattackers-controlled-websitesauthenticate-requestscross-origin-resources-sharingcross-site-requestcve-2026-56400
2026-07-15
CISA KEV
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...
cisa-kevcompromisecve-2026-46817e-business-suitehttpimproper-privileges-managementnetwork-accessoracle
2026-07-15
NVD CVE
CVE-2026-20156: As part of Cisco's ongoing commitment to proactive security and product quality,
HIGH
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-14
CISA KEV
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
authentication-bypasscisa-kevcritical-functionscve-2026-56164microsoftmissing-authenticationnetwork-securityprivileges-escalation
2026-07-14
NVD CVE
CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau
HIGH
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-14
NVD CVE
CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized
HIGH
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
2026-07-14
NVD CVE
CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unautho
HIGH
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-50487: Use after free in Microsoft Windows DNS allows an unauthorized attacker to eleva
HIGH
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unautho
HIGH
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-47988: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
HIGH
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47988exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14
NVD CVE
CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to
HIGH
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-49181: Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthor
HIGH
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut
HIGH
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-50330: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac
HIGH
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-47984: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
HIGH
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47984exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14
NVD CVE
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14
NVD CVE
CVE-2026-50439: Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized
HIGH
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
2026-07-14
CISA KEV
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
appliancecisa-kevcve-2026-15409cybersecuritydatum-exfiltrationfirewalls-vulnerabilitiesnetwork-securityremote-code-execution
2026-07-14
NVD CVE
CVE-2026-48320: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
HIGH
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control...
coldfusioncross-site-scriptingcve-2026-48320elevated-accessmalicious-scriptsnvd-cvereflecteds-xsssession-control
2026-07-14
CISA KEV
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
access-controlactive-directories-federation-servicesadfauthorize-attackerscisa-kevcve-2026-56155insufficient-granularitylocal-privileges-escalation
2026-07-14
NVD CVE
CVE-2026-10672: subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI
HIGH
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri,...