LIVE FEED
1573 events · 4 sources · newest first
Events in view
1573
all sources
Critical
0
severity
Active sources
4
collectors
Last sync
2026-08-25 18:00
UTC
2026-06-23
CISA KEV
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
2026-06-22
NVD CVE
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of...
2026-06-21
NVD CVE
CVE-2026-12773: A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the
HIGH
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy....
2026-06-18
NVD CVE
CVE-2026-55203: HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vul
HIGH
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535...
2026-06-18
CISA KEV
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
2026-06-16
CISA KEV
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
2026-06-15
CISA KEV
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
2026-06-15
CISA KEV
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
2026-06-12
NVD CVE
CVE-2026-50085: The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command paylo
HIGH
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication...
2026-06-12
NVD CVE
CVE-2026-47691: Netty is a network application framework for development of protocol servers and
HIGH
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS...
2026-06-12
NVD CVE
CVE-2026-45674: Netty is a network application framework for development of protocol servers and
HIGH
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME...
2026-06-11
CISA KEV
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can...
2026-06-11
NVD CVE
CVE-2026-41699: Spring for GraphQL applications are vulnerable to Unsafe Deserialization when pr
HIGH
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the...
2026-06-09
CISA KEV
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands...
2026-06-09
CISA KEV
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination...
2026-06-09
CISA KEV
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web...
2026-06-09
NVD CVE
CVE-2026-47932: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limi
HIGH
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the...
2026-06-09
NVD CVE
CVE-2026-46749: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update
HIGH
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and...
2026-06-09
NVD CVE
CVE-2026-47929: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Aut
HIGH
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker...
2026-06-09
NVD CVE
CVE-2026-41855: In an untrusted JMS environment, org.springframework.jms.support.converter.Mappi
HIGH
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class...
2026-06-09
NVD CVE
CVE-2026-47931: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Inpu
HIGH
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high...
2026-06-08
CISA KEV
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
2026-06-05
CISA KEV
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
2026-06-04
NVD CVE
CVE-2026-50292: In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unesca
HIGH
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
2026-06-03
CISA KEV
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in...
2026-06-02
CISA KEV
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
2026-06-02
CISA KEV
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
2026-06-02
NVD CVE
CVE-2026-35482: alf.io is an open source ticket reservation system for conferences, trade shows,
HIGH
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an...
2026-06-01
NVD CVE
CVE-2026-49121: AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated rem
HIGH
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote...
2026-06-01
CISA KEV
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can...
2026-06-01
NVD CVE
CVE-2026-44825: Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab
HIGH
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster...
2026-05-29
NVD CVE
CVE-2026-10063: A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this
HIGH
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer...
2026-05-29
NVD CVE
CVE-2026-48501: GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub
HIGH
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh...
2026-05-29
NVD CVE
CVE-2026-10062: A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this
HIGH
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes...
2026-05-29
CISA KEV
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
2026-05-27
CISA KEV
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
2026-05-26
NVD CVE
CVE-2026-24212: NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive infor
HIGH
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,...
2026-05-26
NVD CVE
CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
HIGH
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
2026-05-26
NVD CVE
CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
HIGH
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
2026-05-26
NVD CVE
CVE-2026-44966: Velocity.js is a JavaScript implementation of the Apache Velocity template engin
HIGH
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of...