Skip to content
COOEY
LIVE FEED
1573 events · 4 sources · newest first
2026-07-14 NVD CVE
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control...
coldfusioncross-site-scriptingcve-2026-48320elevated-accessmalicious-scriptsnvd-cvereflecteds-xsssession-control
2026-07-14 NVD CVE
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47984exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14 NVD CVE
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-13 CISA KEV
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain...
cisa-kevcisco-ioscmmccommand-injectioncompliancecross-site-requests-forgerycves-2008-4128defense-industrial-base
2026-07-12 NVD CVE
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a...
2026-07-10 CISA KEV
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
arbitrary-files-uploadbalbooon-formcybersecurityfiles-uploadjoomlanvd-cverceremote-code-execution
2026-07-10 CISA KEV
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
arbitrary-files-uploadcisa-kevcve-2026-48939cybersecuritydata-protectionfiles-attachmentsicagendaincident-response
2026-07-09 NVD CVE
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after...
ai-platformauthentication-bypasscisacode-executioncve-2026-59216dodnist-800-171nvd-cve
2026-07-09 NVD CVE
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by...
arbitrary-shell-command-executionbackticks-payloadscommand-escapingcommand-injectioncommit-4c06658cve-2026-58459gnuplotgpsd
2026-07-09 NVD CVE
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that...
ai-platformauthenticate-requestsclient-side-pythoncve-2026-59214cybersecuritydata-exposureendpoint-securitynvd-cve
2026-07-09 NVD CVE
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation...
2026-07-08 NVD CVE
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
api-connectcredentials-managementcve-2026-3144cybersecuritydata-exposuredefault-credentialsdefense-industrial-baseibm
2026-07-08 NVD CVE
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
clients-sidescve-2026-60002cybersecuritydefense-industrial-basedfar-252-204-7012freehost-keyinformation-security
2026-07-08 NVD CVE
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte...
2026-07-07 NVD CVE
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s...
account-compromiseadministrator-privilegesarcgicve-2026-13020cybersecurityemail-serveresriinformation-security
2026-07-07 CISA KEV
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
arbitrary-files-uploadcisa-kevcve-2026-56290improper-access-controljoomlackpage-builderremote-code-executionsoftware-vulnerabilities
2026-07-07 CISA KEV
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
arbitrary-files-uploadcisa-kevcve-2026-48908joomshaperphp-code-executionsecurities-riskssoftware-vulnerabilitiessp-page-builder
2026-07-07 CISA KEV
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
adobearbitrary-code-executioncisa-kevcoldfusioncve-2026-48282cybersecurityincident-responsepath-traversal
2026-07-07 CISA KEV
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
authenticate-attackerauthorization-bypasscisa-kevcve-2026-55255cybersecurityflow-executionlangflowsecurities-risks
2026-07-04 NVD CVE
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the...
2026-07-03 NVD CVE
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
2026-07-02 NVD CVE
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper...
2026-07-02 NVD CVE
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
2026-07-01 CISA KEV
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
2026-06-30 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
2026-06-30 NVD CVE
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks...
2026-06-30 NVD CVE
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
2026-06-30 NVD CVE
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
2026-06-30 NVD CVE
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a...
2026-06-30 NVD CVE
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element...
2026-06-30 NVD CVE
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose...
2026-06-29 CISA KEV
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their...
2026-06-26 NVD CVE
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts...
2026-06-26 NVD CVE
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over...
2026-06-25 CISA KEV
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
2026-06-25 CISA KEV
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an...
2026-06-23 CISA KEV
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
2026-06-23 CISA KEV
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
2026-06-23 CISA KEV
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
◀ PREV PAGE 04 / 40 NEXT ▶