LIVE FEED
3595 events · 4 sources · newest first
Events in view
3595
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2026-04-07
NVD CVE
CVE-2026-34078: Flatpak is a Linux application sandboxing and distribution framework. Prior to 1
CRITICAL
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths....
2026-04-07
NVD CVE
CVE-2026-28808: Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unaut
CRITICAL
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias.
When script_alias maps a URL prefix to a...
2026-04-07
NVD CVE
CVE-2026-39846: SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious no
CRITICAL
SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption...
2026-04-07
NVD CVE
CVE-2026-33439: Open Access Management (OpenAM) is an access management solution. Prior to 16.0.
CRITICAL
Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the...
2026-04-07
NVD CVE
CVE-2026-39397: @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual
CRITICAL
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with...
2026-04-07
NVD CVE
CVE-2026-31789: Issue summary: Converting an excessively large OCTET STRING value to
a hexadecim
CRITICAL
Issue summary: Converting an excessively large OCTET STRING value to
a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.
Impact summary: A heap buffer overflow may lead to a crash or...
2026-04-06
NVD CVE
CVE-2026-34444: Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier,
CRITICAL
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This...
2026-04-06
CISA KEV
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
2026-04-06
NVD CVE
CVE-2026-35184: EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQ
CRITICAL
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.
2026-04-06
NVD CVE
CVE-2026-35408: Directus is a real-time API and App dashboard for managing SQL database content.
HIGH
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without...
2026-04-06
NVD CVE
CVE-2026-35178: Workbench is a suite of tools for administrators and developers to interact with
CRITICAL
Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerability in the...
2026-04-06
NVD CVE
CVE-2026-35459: pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.
CRITICAL
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to...
2026-04-06
NVD CVE
CVE-2026-35197: dye is a portable and respectful color library for shell scripts. Prior to 1.1.1
MEDIUM
dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and...
2026-04-05
NVD CVE
CVE-2019-25704: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. Attackers can send crafted requests with...
2026-04-05
NVD CVE
CVE-2019-25688: Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted...
2026-04-05
NVD CVE
CVE-2019-25692: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with...
2026-04-05
NVD CVE
CVE-2026-5574: A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0
MEDIUM
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to...
2026-04-05
NVD CVE
CVE-2026-5584: A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the func
HIGH
A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py of the component query Endpoint. Such manipulation leads to code...
2026-04-05
NVD CVE
CVE-2019-25674: CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated
HIGH
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php...
2026-04-05
NVD CVE
CVE-2019-25680: Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that
HIGH
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers...
2026-04-05
NVD CVE
CVE-2019-25700: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL...
2026-04-05
NVD CVE
CVE-2026-5569: A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impac
HIGH
A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls....
2026-04-05
NVD CVE
A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible...
2026-04-05
NVD CVE
A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipulation of the argument cwd can lead to unrestricted upload. The...
2026-04-05
NVD CVE
CVE-2026-5562: A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts t
HIGH
A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code...
2026-04-05
NVD CVE
CVE-2019-25676: Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerab
HIGH
Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags...
2026-04-05
NVD CVE
CVE-2019-25694: Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted...
2026-04-05
NVD CVE
CVE-2019-25696: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements...
2026-04-05
NVD CVE
CVE-2019-25698: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with...
2026-04-05
NVD CVE
CVE-2019-25702: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with...
2026-04-04
NVD CVE
CVE-2026-34955: PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSand
HIGH
PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.run() with shell=True and relies solely on string-pattern matching...
2026-04-04
NVD CVE
CVE-2026-34775: Electron is a framework for writing cross-platform desktop applications using Ja
MEDIUM
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not...
2026-04-04
NVD CVE
CVE-2026-5526: A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/
HIGH
A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper...
2026-04-03
NVD CVE
CVE-2026-33107: Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized at
CRITICAL
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-33105: Improper authorization in Microsoft Azure Kubernetes Service allows an unauthori
CRITICAL
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-0545: In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not
CRITICAL
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the...
2026-04-03
NVD CVE
CVE-2017-20235: ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an
CRITICAL
ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative...
2026-04-03
NVD CVE
CVE-2026-34937: PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() i
HIGH
PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-controlled code into python3 -c "<code>" and passing it to...
2026-04-03
NVD CVE
CVE-2026-32213: Improper authorization in Azure AI Foundry allows an unauthorized attacker to el
CRITICAL
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-32186: Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized atta
CRITICAL
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.