LIVE FEED
3595 events · 4 sources · newest first
Events in view
3595
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2026-01-29
CISA KEV
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
2026-01-27
NVD CVE
CVE-2026-24881: In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an
HIGH
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily...
2026-01-27
CISA KEV
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
HIGH
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log...
2026-01-26
CISA KEV
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature...
2026-01-26
CISA KEV
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
2026-01-26
CISA KEV
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify...
2026-01-26
CISA KEV
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server,...
2026-01-26
CISA KEV
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their...
2026-01-23
NVD CVE
CVE-2026-24304: Improper access control in Azure Resource Manager allows an authorized attacker
CRITICAL
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
2026-01-23
CISA KEV
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially...
2026-01-23
NVD CVE
CVE-2026-24423: SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated
CRITICAL
◈ 2 sources · orig. NVD CVE
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP...
2026-01-22
CISA KEV
Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
2026-01-22
CISA KEV
Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using...
2026-01-22
CISA KEV
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal...
2026-01-22
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching,...
2026-01-22
NVD CVE
CVE-2026-23760: SmarterTools SmarterMail versions prior to build 9511 contain an authentication
CRITICAL
◈ 2 sources · orig. NVD CVE
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the...
2026-01-21
NVD CVE
CVE-2026-22807: vLLM is an inference and serving engine for large language models (LLMs). Starti
HIGH
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without...
2026-01-21
CISA KEV
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco...
2026-01-20
NVD CVE
CVE-2025-55130: A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-rea
CRITICAL
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted...
2026-01-20
NVD CVE
CVE-2026-23876: ImageMagick is free and open-source software used for editing and manipulating d
HIGH
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage)...
2026-01-19
NVD CVE
CVE-2026-23534: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past...
2026-01-19
NVD CVE
CVE-2026-23883: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursorPixels` on failure, then `pointer_free` calls `xf_Pointer_Free` and frees it again, triggering...
2026-01-19
NVD CVE
CVE-2026-23533: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX ClearCodec decode path when maliciously crafted residual data causes...
2026-01-19
NVD CVE
CVE-2026-23884: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A...
2026-01-19
NVD CVE
CVE-2026-23531: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the...
2026-01-19
NVD CVE
CVE-2026-23532: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between...
2026-01-19
NVD CVE
CVE-2026-23530: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE...
2026-01-14
NVD CVE
CVE-2026-22855: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This...
2026-01-14
NVD CVE
CVE-2026-22858: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char...
2026-01-14
NVD CVE
CVE-2026-22853: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated...
2026-01-14
NVD CVE
CVE-2026-22859: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in...
2026-01-13
CISA KEV
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
2026-01-12
NVD CVE
CVE-2026-22213: RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buf
CRITICAL
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen()...
2026-01-12
NVD CVE
CVE-2026-22214: RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buf
CRITICAL
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incoming serial frame data. The...
2026-01-12
CISA KEV
Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
2026-01-09
NVD CVE
CVE-2025-13761: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6
HIGH
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an ...
2026-01-07
NVD CVE
CVE-2026-22189: The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains
CRITICAL
The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing...
2026-01-07
NVD CVE
CVE-2025-12543: A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBo
CRITICAL
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a...
2026-01-07
NVD CVE
CVE-2025-69264: pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted depend
HIGH
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution...
2026-01-07
CISA KEV
Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that...