LIVE FEED
1821 events · 4 sources · newest first
Events in view
1821
all sources
Critical
1821
severity
Active sources
4
collectors
Last sync
2026-08-26 00:01
UTC
2026-08-13
NVD CVE
CVE-2026-73532: Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introdu
CRITICAL
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file...
administrator-accountbackdoorcve-2026-73532decommissionedfluent-forms-prosmalicious-codenvd-cvepersistent-file
2026-08-13
NVD CVE
CVE-2026-67614: CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the We
CRITICAL
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an...
authenticationcve-2026-67614cyberpanelfastapihard-coded-secretjwtnvd-cveremote-attacks
2026-08-13
NVD CVE
CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain una
CRITICAL
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
authenticationcve-2026-19297ibmlangflownvd-cveossremote-attackerssecurity
2026-08-13
NVD CVE
CVE-2026-53791: rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that all
CRITICAL
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source...
access-controls-bypassallow-deny-rulecve-2026-53791daemonforged-source-addressip-spoofingnetwork-securitynvd-cve
2026-08-12
NVD CVE
CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec
CRITICAL
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
arbitrary-code-executionauthenticate-attackercve-2026-16860ibmibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5
2026-08-12
NVD CVE
CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca
CRITICAL
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
cve-2026-17276high-authority-threadibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6improper-authorization
2026-08-12
NVD CVE
CVE-2026-73519: WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret comp
CRITICAL
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication...
nvd-cve
2026-08-12
NVD CVE
CVE-2025-41769: The device's PROFINET service is affected by a buffer overflow vulnerability tha
CRITICAL
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or...
arbitrary-code-executionbuffer-overflowcve-2025-41769default-configurationdevice-rebootexploitindustrial-control-systemnetworks-vulnerabilities
2026-08-12
NVD CVE
CVE-2026-17083: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
CRITICAL
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd-cve
2026-08-12
NVD CVE
CVE-2026-72526: A flaw was found in the multicloud-integrations component. The Application propa
CRITICAL
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A...
annotation-validationapplications-custom-resourceargos-cdcluster-managementcode-executioncve-2026-72526hub-clustermanifest-synchronization
2026-08-12
NVD CVE
CVE-2026-72508: A flaw was found in the multicloud-operators-subscription component of Red Hat A
CRITICAL
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating...
nvd-cve
2026-08-12
NVD CVE
CVE-2026-70398: A flaw was found in multicloud-integrations, a component of Red Hat Advanced Clu
CRITICAL
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster...
argos-cdbearer-tokencloud-securitycve-2026-70398data-disclosuregitopsclustermulticloud-integrationnvd-cve
2026-08-12
NVD CVE
CVE-2026-73268: A flaw was found in the cluster-curator-controller component of multicluster eng
CRITICAL
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is...
nvd-cve
2026-08-12
NVD CVE
CVE-2024-27253: IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated
CRITICAL
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
nvd-cve
2026-08-12
NVD CVE
CVE-2026-71471: A flaw was found in acm-search-v2-rhel9. An attacker with administrative privile
CRITICAL
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the...
nvd-cve
2026-08-11
NVD CVE
CVE-2026-73034: DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allo
CRITICAL
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id...
agent-scriptattackers-controlledcron-directoriescve-2026-73034db-gptdirectories-traversalfiles-uploadhttps-headers
2026-08-11
NVD CVE
CVE-2026-71362: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CRITICAL
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources....
access-controladobeadobe-commercecommercecve-2026-71362exploitincorrect-authorizationnvd-cve
2026-08-11
NVD CVE
CVE-2026-71398: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to...
adobeadobe-campaign-classicarbitrary-code-executioncve-2026-71398incorrect-authorizationnvd-cvesecurityvulnerability
2026-08-11
NVD CVE
CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that a
CRITICAL
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to...
chrome-privilegescve-2026-73032file-readsfile-writejavascriptllmmitmnvd-cve
2026-08-11
NVD CVE
CVE-2026-69102: MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT sig
CRITICAL
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any...
admin-sessionapplication-secretcve-2026-69102forged-tokenhard-coded-secretjwtmaxkeynvd-cve
2026-08-11
NVD CVE
CVE-2026-70306: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcve-2026-70306inputs-neutralizationmicrosoftnetwork-securitynvd-cvesharepointspoofing
2026-08-11
NVD CVE
CVE-2026-62893: Use after free in Windows Deployment Services allows an unauthorized attacker to
CRITICAL
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-62893freeincident-responsenetworks-attacksnvd-cvepatch-managementremote-code-execution
2026-08-11
NVD CVE
CVE-2026-71384: is affected by an Incorrect Authorization vulnerability that could result in a S
CRITICAL
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write...
access-controladministrative-network-zoneapplications-vulnerabilitiescve-2026-71384cybersecuritydenialexploitincorrect-authorization
2026-08-11
NVD CVE
CVE-2026-62815: Use after free in Microsoft QUIC allows an unauthorized attacker to execute code
CRITICAL
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
attackercode-executioncve-2026-62815exploitfreemicrosoftnetwork-securitynvd-cve
2026-08-11
NVD CVE
CVE-2026-59124: Deserialization of untrusted data in Microsoft High Performance Computing (HPC)
CRITICAL
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-59124deserializationhigh-performance-computinghpcmicrosoftnetworks-attacksnvd-cve
2026-08-11
NVD CVE
CVE-2026-62878: Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to ex
CRITICAL
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-62878dns-securityexploitnetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-08-11
NVD CVE
CVE-2026-5917: libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_
CRITICAL
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server...
arbitrary-command-executioncommand-injectioncve-2026-5917gitgit-submodulelibgit2libssh2nvd-cve
2026-08-11
NVD CVE
CVE-2026-58115: A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1
CRITICAL
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the...
arbitrary-code-executionauthenticationcve-2026-58115https-interfaceindustrial-osindustrials-iotmalicious-flowsnodes-red
2026-08-11
NVD CVE
CVE-2026-48362: ColdFusion is affected by an Improper Neutralization of Special Elements used in
CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescommand-injectioncve-2026-48362exploitnvd-cve
2026-08-11
NVD CVE
CVE-2026-27302: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to...
adobeadobe-campaign-classicarbitrary-code-executioncve-2026-27302incorrect-authorizationnvd-cvesecurityvulnerability
2026-08-11
NVD CVE
CVE-2026-50516: Missing authentication for critical function in Microsoft Azure Kubernetes Servi
CRITICAL
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
azurecloud-securitycve-2026-50516incident-responsekubernetemicrosoftmissing-authenticationnetwork-security
2026-08-11
NVD CVE
CVE-2026-19425: Travel Agency Management System developed by Win Men Intermational has a SQL Inj
CRITICAL
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
code-injectioncve-2026-19425data-deletiondata-modificationdatabases-compromisesdatum-exfiltrationnvd-cvepatch-management
2026-08-11
NVD CVE
CVE-2026-44758: SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig
CRITICAL
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation....
arbitrary-code-executionavailabilityconfidentialitycve-2026-44758high-privilegeinput-validationintegritymanufacturing-integration-and-intelligence
2026-08-11
NVD CVE
CVE-2026-34265: SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl
CRITICAL
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive...
abapavailabilityconfidentialitycve-2026-34265diagnostic-protocolsintegritymemory-corruptionnvd-cve
2026-08-11
NVD CVE
CVE-2026-10579: A flaw was found in Picketlink Federation SAML; the unsolcited response handler
CRITICAL
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in...
access-controlauthentication-bypassauthorizationcve-2026-10579federationforged-assertionsidentity-managementinformation-disclosure
2026-08-11
NVD CVE
CVE-2026-65791: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize
CRITICAL
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-65791exploitheap-based-buffer-overflowiscsinetworks-attacksnvd-cve
2026-08-11
NVD CVE
CVE-2026-58231: SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authent
CRITICAL
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially crafted
input to certain functions lacking sufficient validation. Successful
exploitation could...
arbitrary-code-executionauthentication-bypassavailabilityconfidentialitycve-2026-58231default-authentication-clienthigh-impactinput-validation
2026-08-10
NVD CVE
CVE-2026-14450: A flaw was found in the MaaS API. This vulnerability allows any pod within the c
CRITICAL
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are...
api-keycve-2026-14450first-parties-authenticationforged-headershttps-headerskuadrant-authpolicykubernetemaas-apus
2026-08-10
NVD CVE
CVE-2026-18948: A flaw was found in Feast. The system improperly deserializes user-defined funct
CRITICAL
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious...
arbitrary-code-executioncross-tenant-data-accesscve-2026-18948deserializationdillfeastlateral-movementnvd-cve
2026-08-10
NVD CVE
CVE-2026-63106: ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil
CRITICAL
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause...
administrator-passwords-hashescve-2026-63106database-contentfile-system-accessincident-responsemysqlnvd-cveproduct-controller