LIVE FEED
1776 events · 4 sources · newest first
Events in view
1776
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-05-10
NVD CVE
CVE-2026-6722: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without...
2026-05-10
NVD CVE
CVE-2026-6104: In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam
CRITICAL
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that...
2026-05-09
NVD CVE
CVE-2026-42257: Net::IMAP implements Internet Message Access Protocol (IMAP) client functionalit
CRITICAL
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the...
2026-05-09
NVD CVE
CVE-2026-6665: The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strl
HIGH
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM...
2026-05-09
NVD CVE
CVE-2026-42601: ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6
CRITICAL
ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without...
2026-05-08
NVD CVE
CVE-2026-42556: Postiz is an AI social media scheduling tool. From version 2.21.6 to before vers
HIGH
Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request...
2026-05-08
NVD CVE
CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
CRITICAL
◈ 2 sources · orig. NVD CVE
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key...
2026-05-08
NVD CVE
CVE-2026-42298: Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Re
CRITICAL
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any...
2026-05-08
NVD CVE
CVE-2026-42264: Axios is a promise based HTTP client for the browser and Node.js. From version 1
HIGH
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP...
2026-05-08
NVD CVE
CVE-2026-42354: Sentry is an error tracking and performance monitoring tool. From version 21.12.
CRITICAL
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows...
2026-05-07
NVD CVE
CVE-2026-7891: A vulnerability has been identified in Mendix Runtime (All versions). Mendix doc
CRITICAL
A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without...
2026-05-07
NVD CVE
CVE-2026-42010: A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adlem
HIGH
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit...
2026-05-07
NVD CVE
CVE-2026-41586: Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framew
CRITICAL
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes...
2026-05-07
NVD CVE
CVE-2026-42216: OpenEXR provides the specification and reference implementation of the EXR file
CRITICAL
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0...
2026-05-05
NVD CVE
CVE-2026-35579: CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QU
CRITICAL
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the...
2026-05-05
NVD CVE
CVE-2026-34084: PhpSpreadsheet is a library for reading and writing spreadsheet files. In versio
CRITICAL
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename...
2026-05-04
NVD CVE
CVE-2026-26332: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, Suppresse
CRITICAL
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
2026-04-30
NVD CVE
CVE-2026-39858: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based...
2026-04-30
NVD CVE
CVE-2026-33845: A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero len
HIGH
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is...
2026-04-30
NVD CVE
CVE-2026-35051: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false...
2026-04-28
NVD CVE
CVE-2026-40974: Spring Boot's Cassandra auto-configuration does not perform hostname verificatio
MEDIUM
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14),...
2026-04-27
NVD CVE
CVE-2026-40971: When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration
MEDIUM
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6),...
2026-04-24
NVD CVE
CVE-2026-42043: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.
HIGH
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than...
2026-04-24
NVD CVE
CVE-2026-42044: Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to
MEDIUM
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the...
2026-04-24
NVD CVE
CVE-2026-41473: CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerabilit
CRITICAL
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending...
2026-04-23
NVD CVE
CVE-2026-41179: Rclone is a command-line program to sync files and directories to and from diffe
CRITICAL
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed...
2026-04-23
NVD CVE
CVE-2026-41176: Rclone is a command-line program to sync files and directories to and from diffe
CRITICAL
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime...
2026-04-23
NVD CVE
CVE-2026-25874: LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the as
CRITICAL
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the...
2026-04-18
NVD CVE
CVE-2026-41242: protobufjs compiles protobuf definitions into JavaScript (JS) functions. In vers
CRITICAL
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute...
2026-04-17
NVD CVE
CVE-2026-40518: ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary
HIGH
ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply...
2026-04-14
NVD CVE
CVE-2026-39906: Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose
CRITICAL
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a...
2026-04-14
NVD CVE
CVE-2026-2332: In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when ch
HIGH
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
* https://w4ke.info/2025/06/18/funky-chunks.html
...
2026-04-14
NVD CVE
CVE-2026-34615: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati
CRITICAL
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could...
2026-04-14
NVD CVE
CVE-2026-39907: Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose
CRITICAL
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter,...
2026-04-14
NVD CVE
CVE-2026-35033: Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c
CRITICAL
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter...
2026-04-14
NVD CVE
CVE-2026-35589: nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site
HIGH
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete...
2026-04-13
NVD CVE
CVE-2026-0234: An improper verification of cryptographic signature vulnerability exists in Cort
CRITICAL
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify...
2026-04-13
NVD CVE
CVE-2026-5936: An attacker can control a server-side HTTP request by supplying a crafted URL, c
HIGH
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services,...
2026-04-13
NVD CVE
CVE-2025-31991: Rate Limiting for attempting a user login is not being properly enforced, making
MEDIUM
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7.
2026-04-12
NVD CVE
CVE-2026-40393: In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occu
HIGH
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.