LIVE FEED
3595 events · 4 sources · newest first
Events in view
3595
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2026-03-24
NVD CVE
CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC
CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-33195: Active Storage allows users to attach cloud and local files in Rails application
CRITICAL
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved...
2026-03-24
NVD CVE
CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th
CRITICAL
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability
CRITICAL
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f
CRITICAL
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe
CRITICAL
Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f
CRITICAL
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CRITICAL
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-23
NVD CVE
CVE-2026-31848: Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_p
CRITICAL
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is...
2026-03-23
NVD CVE
CVE-2026-4601: Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Crypto
HIGH
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private...
2026-03-23
NVD CVE
CVE-2026-4600: Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verif
HIGH
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509...
2026-03-20
NVD CVE
CVE-2026-33210: Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versi
CRITICAL
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information...
2026-03-20
CISA KEV
Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
2026-03-20
CISA KEV
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
2026-03-20
CISA KEV
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.
2026-03-20
NVD CVE
CVE-2026-33228: flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function
CRITICAL
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are...
2026-03-20
CISA KEV
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
2026-03-20
NVD CVE
CVE-2025-15608: This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient i
CRITICAL
This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that...
2026-03-20
CISA KEV
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
2026-03-19
NVD CVE
CVE-2025-71257: BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentica
HIGH
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated...
2026-03-19
NVD CVE
CVE-2006-10003: XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflo
CRITICAL
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.
In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at...
2026-03-19
CISA KEV
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that...
2026-03-18
NVD CVE
CVE-2025-15031: A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file
CRITICAL
A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables...
2026-03-18
CISA KEV
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
2026-03-18
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
2026-03-18
NVD CVE
CVE-2026-28500: Open Neural Network Exchange (ONNX) is an open standard for machine learning int
HIGH
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the...
2026-03-18
NVD CVE
CVE-2026-27459: pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22
CRITICAL
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256...
2026-03-16
CISA KEV
Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.
2026-03-16
NVD CVE
CVE-2026-32640: SimpleEval is a library for adding evaluatable expressions into python projects.
CRITICAL
SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modules through to direct access inside the sandbox. If the objects...
2026-03-13
CISA KEV
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML...
2026-03-13
CISA KEV
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS,...
2026-03-13
NVD CVE
CVE-2026-31806: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using...
2026-03-13
NVD CVE
CVE-2026-23941: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab
CRITICAL
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling.
This vulnerability is associated with program files...
2026-03-11
CISA KEV
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
2026-03-11
NVD CVE
CVE-2026-29515: MiCode FileExplorer contains an authentication bypass vulnerability in the embed
CRITICAL
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username...
2026-03-09
CISA KEV
SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.
2026-03-09
CISA KEV
Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests...
2026-03-09
CISA KEV
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.
2026-03-09
NVD CVE
CVE-2026-25960: vLLM is an inference and serving engine for large language models (LLMs). The SS
HIGH
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing...
2026-03-09
NVD CVE
CVE-2026-3823: EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Ov
CRITICAL
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.