LIVE FEED
3560 events · 4 sources · newest first
Events in view
3560
all sources
Critical
1814
severity
Active sources
4
collectors
Last sync
2026-08-25 18:00
UTC
2026-08-17
NVD CVE
CVE-2026-74875: openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when
CRITICAL
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or...
bypass-schema-checkscve-2026-74875json-schemas-validationsjsonschemalibrary-missingmalformed-metadatamalicious-datametadata-formats
2026-08-17
NVD CVE
CVE-2026-74876: openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle
CRITICAL
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by...
attackers-controlled-keyscryptographycve-2026-74876data-leakencryptionfroms-dictskeys-bundlenvd-cve
2026-08-17
NVD CVE
CVE-2026-74899: openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in
CRITICAL
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy...
arbitrary-code-executionclasses-hierarchies-traversalscve-2026-74899isolate-plugins-executornvd-cveopensslopenssl-encryptos-command-execution
2026-08-17
NVD CVE
CVE-2026-19977: A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element
CRITICAL
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper...
a304tattackcve-2026-19977disclosureefmexploithttpcon-check-session-urlimproper-authentication
2026-08-17
NVD CVE
CVE-2026-74799: SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap a
CRITICAL
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and...
accesses-auth-codeai-provider-api-keyauthentication-bypasscve-2026-74799debug-endpointgo-languagegoroutine-dumpheap-dump
2026-08-17
NVD CVE
CVE-2026-66792: A flaw was found in the multicloud-operators-subscription component. This vulner
CRITICAL
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations....
cloud-securitycluster-resourcecrafted-annotationscve-2026-66792kubernetemanaged-clustermulticloud-operators-subscriptionnamespace
2026-08-17
CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycode-injectioncvecve-2025-62593cyber-attacksfederal-agencies
2026-08-17
NVD CVE
CVE-2026-66795: A flaw was found in the managedcluster-import-controller. The Certificate Signin
CRITICAL
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the...
administrative-credentialscertificates-signing-requestcsrcve-2026-66795hub-clustermaliciouses-csrmanagedcluster-import-controllernvd-cve
2026-08-17
NVD CVE
CVE-2026-75106: OpnForm derives editable-submission secrets from sequential row identifiers usin
CRITICAL
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other...
answer-endpointcve-2026-75106data-integritydatum-exfiltrationdefaults-salteditable-submissionshashes-computationshashid
2026-08-17
NVD CVE
CVE-2026-74900: openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py
CRITICAL
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of...
ciphertextcritical-vulnerabilitycve-2026-74900decapsulationfallbackkemnvd-cveopenssl
2026-08-17
NVD CVE
CVE-2026-74800: SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options
CRITICAL
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files...
assets-linksauthenticationcontents-dispositioncross-site-scriptingcve-2026-74800files-uploadkernel-api-accessesnvd-cve
2026-08-17
NVD CVE
CVE-2026-75110: MemOS is a memory operating system for LLMs and AI agents. In deployments where
CRITICAL
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset,...
ai-agentapi-key-managementauthenticationauthorizationcve-2026-75110data-endpointenvironment-variablesinternal-services
2026-08-17
CISA KEV
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
cisa-kevcode-injectioncve-2025-62593development-toolsexploitablefirefoxrayray-project
2026-08-17
NVD CVE
CVE-2026-71472: A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authentica
CRITICAL
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements....
acm-search-v2-rhel9arbitrary-code-executionauthenticationcode-executioncommand-injectioncve-2026-71472nvd-cvepostgresql
2026-08-17
NVD CVE
CVE-2026-74894: openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in
CRITICAL
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public...
authentication-bypassauthorization-headerbearer-tokencve-2026-74894keys-enumerationkeys-revocationnvd-cveopenssl
2026-08-17
NVD CVE
CVE-2026-74891: openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in
CRITICAL
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default...
attackercve-2026-74891data-breachesdatabase-credentialsdefault-credentialshardcoded-credentialnetwork-securitynvd-cve
2026-08-17
NVD CVE
CVE-2026-74896: openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in
CRITICAL
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__,...
arbitrary-code-executionast-analyzercve-2026-74896dunder-attribute-traversalnvd-cveopensslopenssl-encryptplugin-code
2026-08-17
NVD CVE
CVE-2026-74901: openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerabi
CRITICAL
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in...
aes-ctraes-gcmauthentication-bypassbit-flipping-attackciphertext-modificationcve-2026-74901integrity-verificationnvd-cve
2026-08-17
NVD CVE
CVE-2026-74889: openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info para
CRITICAL
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with...
cryptographic-securitycryptographic-vulnerabilitiescve-2026-74889entropy-extractionhkdfkey-derivationmulti-targets-attacknvd-cve
2026-08-17
NVD CVE
CVE-2026-74886: openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerabil
CRITICAL
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass...
arbitrary-code-executionast-analyzercve-2026-74886dangerous-moduleencodingimportlibmultiprocessingnvd-cve
2026-08-17
NVD CVE
CVE-2026-74895: openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the
CRITICAL
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem,...
cve-2026-74895default-process-isolationfilesystem-accessesmalicious-pluginsnetwork-accessnvd-cveopensslplugin-execution
2026-08-16
NVD CVE
CVE-2026-19959: A weakness has been identified in Edimax EW-7478APC 1.04. This affects the funct
CRITICAL
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer...
buffer-overflowcve-2026-19959edimaxew-7478apcnvd-cveremote-exploitationsecurities-disclosuresstack-based-buffer-overflow
2026-08-16
NVD CVE
CVE-2026-18316: The Solace Extra plugin for WordPress is vulnerable to unauthorized modification
CRITICAL
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is...
authenticate-attackercapability-checkscve-2026-18316data-lossesdemo-content-importelementor-templateimport-zipnavigation-menus
2026-08-16
NVD CVE
CVE-2024-13784: The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPre
CRITICAL
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form...
arformcode-executioncve-2024-13784deserializationfile-deletionnvd-cvephp-object-injectionplugins-vulnerabilities
2026-08-16
NVD CVE
CVE-2026-73056: SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive
CRITICAL
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an...
apiapi-tokenauthenticationcaptchacve-2026-73056file-operationkernellockout-mechanism
2026-08-16
NVD CVE
CVE-2026-19961: A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function
CRITICAL
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow....
buffer-overflowcve-2026-19961edimaxew-7478apcnvd-cveremote-attackssecurities-disclosuresvendor-response
2026-08-16
NVD CVE
CVE-2026-18432: The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege
CRITICAL
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the...
administrator-privilegesauthorization-bypasscve-2026-18432dynamiappfrontend-adminsnvd-cvepassword-overwriteplugins-vulnerabilities
2026-08-16
NVD CVE
CVE-2026-19924: A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01
CRITICAL
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper...
ac10authentication-bypasscve-2026-19924cybersecurityexploithttpdimproper-authenticationnetwork-security
2026-08-16
NVD CVE
CVE-2026-14524: The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d
CRITICAL
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8....
arbitrary-file-deletioncve-2026-14524file-path-validationnoncenvd-cvepath-traversalpluginprosolution
2026-08-16
NVD CVE
CVE-2026-16098: The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U
CRITICAL
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the...
arbitrary-files-uploadcontents-dispositioncve-2026-16098executablefile-validationfiles-uploadnonce-exposuresnvd-cve
2026-08-16
NVD CVE
CVE-2026-73061: Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb
CRITICAL
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties...
accesses-modifier-bypassclrcode-executioncve-2026-73061init-only-setterinternals-settersmass-assignmentnvd-cve
2026-08-16
NVD CVE
CVE-2026-74790: Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering
CRITICAL
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered...
access-controlbypasscve-2026-74790member-filternvd-cvesandbox-policyscribansecurity-research
2026-08-15
NVD CVE
CVE-2026-15303: The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass
CRITICAL
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on...
6storage-rentalauthentication-bypasscve-2026-15303nvd-cvepluginsecurity-breachunauthenticated-attacksvulnerability
2026-08-15
NVD CVE
CVE-2026-73044: SiYuan versions before v3.7.4 fail to validate or escape table column width valu
CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the...
api-injectionarbitrary-code-executioncross-site-scriptingcve-2026-73044electronevent-handlernode-integrationnvd-cve
2026-08-15
NVD CVE
CVE-2026-73053: SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th
CRITICAL
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that...
arbitrary-code-executioncode-executioncross-site-scriptingcve-2026-73053document-iconhex-encodingnodenvd-cve
2026-08-15
NVD CVE
CVE-2026-73041: SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt
CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the...
code-injectioncve-2026-73041data-validationendpoint-securitymalicious-markupmalware-executionnodejnvd-cve
2026-08-15
NVD CVE
CVE-2026-73042: SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int
CRITICAL
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup...
code-executioncve-2026-73042electronhtml-injectionnodenvd-cvescript-executionsecurity-bulletin
2026-08-15
NVD CVE
CVE-2026-73050: SiYuan versions before v3.7.4 fail to validate or escape the color field in attr
CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler...
arbitrary-javascriptattributes-viewcolor-fieldcross-site-scriptingcve-2026-73050database-injectionevent-handler-attributejavascript-execution
2026-08-15
NVD CVE
CVE-2026-18855: The Link Library plugin for WordPress is vulnerable to arbitrary file deletion d
CRITICAL
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it...
arbitrary-file-deletioncve-2026-18855file-path-validationlinks-librariesnvd-cvepluginremote-code-executionsecurity
2026-08-15
NVD CVE
CVE-2026-73046: SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t
CRITICAL
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace...
access-controlapi-securityauthenticationbrute-forcecve-2026-73046http-basic-authenticationkernel-accessesmiddleware