Skip to content
COOEY
LIVE FEED
1759 events · 4 sources · newest first
2026-08-18 NVD CVE
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows...
availabilityconfidentialitycve-2026-70954cvss-31cvss-98dynamo-application-frameworkhttpintegrity
2026-08-18 NVD CVE
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
nvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-70926cvss-31cvss-98integritynetwork-access
2026-08-18 NVD CVE
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
availability-impactcontent-acquisition-systemscve-2026-70976cvss-31data-creationdata-deletiondata-modificationdos
2026-08-18 NVD CVE
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated...
2026-08-18 NVD CVE
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
availability-impactcompromiseconfidentiality-impactcve-2026-61241cvss-100cvss-31integrity-impactldap
2026-08-18 NVD CVE
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
cve-2026-60990cvss-31cvss-99network-securitynvd-cveoracleoracle-fusionoracle-identity-manager-connector
2026-08-18 NVD CVE
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to...
access-controlaccess-fieldsblueprintcore-groupcve-2026-75837delegated-adminsgravgrav-2-0-14
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74943firefoxfreegraphicimagelibmozillanvd-cvepatch
2026-08-18 NVD CVE
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74940firefoxfirefox-esrfreegraphic-text-componentmozillanvd-cvesecurity-patch
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low...
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable...
availability-impactconfidentiality-impactcve-2026-60977cvss-31integrity-impactnetwork-accessnvd-cveoracle
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP...
attackerbrowser-historycve-2026-74880https-referer-headerskeyservernvd-cveopensslopenssl-encrypt
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass...
arbitrary-code-executionast-analyzercve-2026-74886dangerous-moduleencodingimportlibmultiprocessingnvd-cve
2026-08-17 NVD CVE
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper...
a304tattackcve-2026-19977disclosureefmexploithttpcon-check-session-urlimproper-authentication
2026-08-17 NVD CVE
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other...
answer-endpointcve-2026-75106data-integritydatum-exfiltrationdefaults-salteditable-submissionshashes-computationshashid
2026-08-17 NVD CVE
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the...
administrative-credentialscertificates-signing-requestcsrcve-2026-66795hub-clustermaliciouses-csrmanagedcluster-import-controllernvd-cve
2026-08-17 NVD CVE
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset,...
ai-agentapi-key-managementauthenticationauthorizationcve-2026-75110data-endpointenvironment-variablesinternal-services
2026-08-17 NVD CVE
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations....
cloud-securitycluster-resourcecrafted-annotationscve-2026-66792kubernetemanaged-clustermulticloud-operators-subscriptionnamespace
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or...
bypass-schema-checkscve-2026-74875json-schemas-validationsjsonschemalibrary-missingmalformed-metadatamalicious-datametadata-formats
2026-08-17 NVD CVE
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements....
acm-search-v2-rhel9arbitrary-code-executionauthenticationcode-executioncommand-injectioncve-2026-71472nvd-cvepostgresql
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in...
aes-ctraes-gcmauthentication-bypassbit-flipping-attackciphertext-modificationcve-2026-74901integrity-verificationnvd-cve
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy...
arbitrary-code-executionclasses-hierarchies-traversalscve-2026-74899isolate-plugins-executornvd-cveopensslopenssl-encryptos-command-execution
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of...
ciphertextcritical-vulnerabilitycve-2026-74900decapsulationfallbackkemnvd-cveopenssl
2026-08-17 NVD CVE
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public...
authentication-bypassauthorization-headerbearer-tokencve-2026-74894keys-enumerationkeys-revocationnvd-cveopenssl
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default...
attackercve-2026-74891data-breachesdatabase-credentialsdefault-credentialshardcoded-credentialnetwork-securitynvd-cve
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem,...
cve-2026-74895default-process-isolationfilesystem-accessesmalicious-pluginsnetwork-accessnvd-cveopensslplugin-execution
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts...
authenticationbrute-forcecve-2026-74878incident-responsenvd-cveopensslopenssl-encryptrate-limiter
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with...
cryptographic-securitycryptographic-vulnerabilitiescve-2026-74889entropy-extractionhkdfkey-derivationmulti-targets-attacknvd-cve
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__,...
arbitrary-code-executionast-analyzercve-2026-74896dunder-attribute-traversalnvd-cveopensslopenssl-encryptplugin-code
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers...
arbitrary-code-executioncve-2026-74872glob-patternhash-implementationsintegrity-verificationmalicious-so-filesnative-code-executionnvd-cve
2026-08-17 NVD CVE
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and...
accesses-auth-codeai-provider-api-keyauthentication-bypasscve-2026-74799debug-endpointgo-languagegoroutine-dumpheap-dump
2026-08-17 NVD CVE
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files...
assets-linksauthenticationcontents-dispositioncross-site-scriptingcve-2026-74800files-uploadkernel-api-accessesnvd-cve
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by...
attackers-controlled-keyscryptographycve-2026-74876data-leakencryptionfroms-dictskeys-bundlenvd-cve
◀ PREV PAGE 05 / 44 NEXT ▶