LIVE FEED
1573 events · 4 sources · newest first
Events in view
1573
all sources
Critical
0
severity
Active sources
4
collectors
Last sync
2026-08-25 18:00
UTC
2026-07-14
NVD CVE
CVE-2026-48320: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
HIGH
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control...
coldfusioncross-site-scriptingcve-2026-48320elevated-accessmalicious-scriptsnvd-cvereflecteds-xsssession-control
2026-07-14
NVD CVE
CVE-2026-47984: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
HIGH
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47984exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14
NVD CVE
CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unautho
HIGH
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-13
CISA KEV
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain...
cisa-kevcisco-ioscmmccommand-injectioncompliancecross-site-requests-forgerycves-2008-4128defense-industrial-base
2026-07-12
NVD CVE
CVE-2026-10666: parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for string
HIGH
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a...
2026-07-10
CISA KEV
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
arbitrary-files-uploadbalbooon-formcybersecurityfiles-uploadjoomlanvd-cverceremote-code-execution
2026-07-10
CISA KEV
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
arbitrary-files-uploadcisa-kevcve-2026-48939cybersecuritydata-protectionfiles-attachmentsicagendaincident-response
2026-07-09
NVD CVE
CVE-2026-59216: Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat
HIGH
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after...
ai-platformauthentication-bypasscisacode-executioncve-2026-59216dodnist-800-171nvd-cve
2026-07-09
NVD CVE
CVE-2026-58459: gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injecti
HIGH
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by...
arbitrary-shell-command-executionbackticks-payloadscommand-escapingcommand-injectioncommit-4c06658cve-2026-58459gnuplotgpsd
2026-07-09
NVD CVE
CVE-2026-59214: Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat
HIGH
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that...
ai-platformauthenticate-requestsclient-side-pythoncve-2026-59214cybersecuritydata-exposureendpoint-securitynvd-cve
2026-07-09
NVD CVE
CVE-2026-53963: Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 20
HIGH
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation...
2026-07-08
NVD CVE
CVE-2026-3144: IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could a
HIGH
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
api-connectcredentials-managementcve-2026-3144cybersecuritydata-exposuredefault-credentialsdefense-industrial-baseibm
2026-07-08
NVD CVE
CVE-2026-60002: ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its h
HIGH
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
clients-sidescve-2026-60002cybersecuritydefense-industrial-basedfar-252-204-7012freehost-keyinformation-security
2026-07-08
NVD CVE
CVE-2026-29009: U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readl
HIGH
U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte...
2026-07-07
NVD CVE
CVE-2026-13020: A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal
HIGH
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s...
account-compromiseadministrator-privilegesarcgicve-2026-13020cybersecurityemail-serveresriinformation-security
2026-07-07
CISA KEV
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
arbitrary-files-uploadcisa-kevcve-2026-56290improper-access-controljoomlackpage-builderremote-code-executionsoftware-vulnerabilities
2026-07-07
CISA KEV
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
arbitrary-files-uploadcisa-kevcve-2026-48908joomshaperphp-code-executionsecurities-riskssoftware-vulnerabilitiessp-page-builder
2026-07-07
CISA KEV
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
adobearbitrary-code-executioncisa-kevcoldfusioncve-2026-48282cybersecurityincident-responsepath-traversal
2026-07-07
CISA KEV
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
authenticate-attackerauthorization-bypasscisa-kevcve-2026-55255cybersecurityflow-executionlangflowsecurities-risks
2026-07-04
NVD CVE
CVE-2026-14535: In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImports
HIGH
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the...
2026-07-03
NVD CVE
CVE-2026-57983: Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized
HIGH
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
2026-07-02
NVD CVE
CVE-2026-59092: JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypas
HIGH
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper...
2026-07-02
NVD CVE
CVE-2026-54408: A malicious actor with access to the network could exploit an Improper Access Co
HIGH
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
2026-07-01
CISA KEV
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
2026-06-30
NVD CVE
CVE-2026-11541: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
HIGH
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
2026-06-30
NVD CVE
CVE-2026-13772: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language eng
HIGH
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks...
2026-06-30
NVD CVE
CVE-2026-11714: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
2026-06-30
NVD CVE
CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
2026-06-30
NVD CVE
CVE-2026-10560: IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerabi
HIGH
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a...
2026-06-30
NVD CVE
CVE-2026-58016: A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new
HIGH
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element...
2026-06-30
NVD CVE
CVE-2026-13449: IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable
HIGH
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose...
2026-06-29
CISA KEV
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their...
2026-06-26
NVD CVE
CVE-2026-31928: The DMP-5000 devices are shipped with a default administrative web account with
HIGH
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts...
2026-06-26
NVD CVE
CVE-2026-12411: Broken Access Control in the devLXDInstancePatchHandler component of Canonical L
HIGH
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over...
2026-06-25
CISA KEV
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
2026-06-25
CISA KEV
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an...
2026-06-23
CISA KEV
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
2026-06-23
CISA KEV
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
2026-06-23
CISA KEV
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.