LIVE FEED
3595 events · 4 sources · newest first
Events in view
3595
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2026-05-26
NVD CVE
CVE-2026-48691: FastNetMon Community Edition through 1.2.9 contains an integer overflow in the B
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as...
2026-05-26
NVD CVE
CVE-2026-48898: An improper access check allows privilege escalation through the com_users batch
CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
2026-05-26
NVD CVE
CVE-2026-35221: Improperly built filter clauses lead to a SQL injection vulnerability in the sea
CRITICAL
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
2026-05-26
NVD CVE
CVE-2026-48904: An improper access check allows privelege escalation through the com_users group
CRITICAL
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
2026-05-26
NVD CVE
CVE-2026-42496: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker contro
CRITICAL
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() without validating it...
2026-05-26
NVD CVE
CVE-2026-48687: FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118)...
2026-05-26
NVD CVE
CVE-2026-40383: An improper validation of user-supplied input leads to a local file inclusion vu
CRITICAL
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
2026-05-26
NVD CVE
CVE-2026-44985: Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSo
CRITICAL
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade...
2026-05-26
NVD CVE
CVE-2026-44966: Velocity.js is a JavaScript implementation of the Apache Velocity template engin
HIGH
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of...
2026-05-26
NVD CVE
CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
HIGH
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
2026-05-26
CISA KEV
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
2026-05-26
NVD CVE
CVE-2026-8376: Perl versions through 5.43.10 have a heap buffer overflow when compiling regular
CRITICAL
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the joined...
2026-05-26
NVD CVE
CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
HIGH
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
2026-05-22
NVD CVE
CVE-2026-8673: Unprotected transport of credentials vulnerability in syslink software AG Avantr
MEDIUM
Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks.
This issue affects Avantra: before 25.3.0.
2026-05-22
CISA KEV
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
2026-05-22
NVD CVE
CVE-2026-47280: Improper authentication in Azure Resource Manager (ARM) allows an unauthorized a
CRITICAL
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
2026-05-22
NVD CVE
CVE-2026-23652: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
2026-05-22
NVD CVE
CVE-2026-33843: Authentication bypass using an alternate path or channel in Microsoft Azure Acti
CRITICAL
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
2026-05-22
NVD CVE
CVE-2026-44930: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s
CRITICAL
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to...
2026-05-22
NVD CVE
CVE-2026-40412: Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows a
CRITICAL
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
2026-05-21
NVD CVE
CVE-2026-48172: LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possi
CRITICAL
◈ 2 sources · orig. NVD CVE
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE...
2026-05-21
NVD CVE
CVE-2026-4858: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.
HIGH
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API...
2026-05-21
CISA KEV
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on...
2026-05-21
CISA KEV
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform...
2026-05-20
NVD CVE
CVE-2026-20223: A vulnerability in the access validation of internal REST APIs of Cisco Sec
CRITICAL
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin...
2026-05-20
NVD CVE
CVE-2026-24425: Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerabi
HIGH
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to...
2026-05-20
NVD CVE
CVE-2026-24163: NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where a
HIGH
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of...
2026-05-20
NVD CVE
CVE-2026-24206: NVIDIA Triton Inference Server contains a vulnerability where an attacker could
HIGH
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or...
2026-05-20
NVD CVE
CVE-2026-24214: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher
HIGH
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering,...
2026-05-20
NVD CVE
CVE-2026-42960: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning
CRITICAL
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used...
2026-05-20
NVD CVE
CVE-2025-31973: HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecur
MEDIUM
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the...
2026-05-20
NVD CVE
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1.
BIND 9 versions...
2026-05-20
NVD CVE
CVE-2026-33278: NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability
CRITICAL
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure...
2026-05-20
NVD CVE
CVE-2026-8631: A potential security vulnerability has been identified in the HP Linux Imaging a
CRITICAL
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer...
2026-05-20
CISA KEV
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
2026-05-20
CISA KEV
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
2026-05-20
CISA KEV
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
2026-05-20
CISA KEV
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
2026-05-20
NVD CVE
CVE-2025-33255: NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an
HIGH
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of...
2026-05-20
NVD CVE
CVE-2026-24142: NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and u
MEDIUM
NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.