LIVE FEED
1574 events · 4 sources · newest first
Events in view
1574
all sources
Critical
0
severity
Active sources
4
collectors
Last sync
2026-08-26 00:01
UTC
2026-04-24
NVD CVE
CVE-2026-42043: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.
HIGH
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than...
2026-04-24
CISA KEV
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding...
2026-04-24
CISA KEV
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
2026-04-23
CISA KEV
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
2026-04-20
CISA KEV
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
2026-04-20
CISA KEV
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by...
2026-04-20
CISA KEV
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA...
2026-04-20
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access...
2026-04-20
CISA KEV
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
2026-04-20
CISA KEV
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
2026-04-17
NVD CVE
CVE-2026-40518: ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary
HIGH
ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply...
2026-04-16
CISA KEV
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
2026-04-14
CISA KEV
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a...
2026-04-14
CISA KEV
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
2026-04-14
NVD CVE
CVE-2026-2332: In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when ch
HIGH
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
* https://w4ke.info/2025/06/18/funky-chunks.html
...
2026-04-14
NVD CVE
CVE-2026-35589: nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site
HIGH
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete...
2026-04-13
CISA KEV
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
2026-04-13
CISA KEV
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
2026-04-13
CISA KEV
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
2026-04-13
CISA KEV
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
2026-04-13
CISA KEV
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
2026-04-13
CISA KEV
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
2026-04-13
NVD CVE
CVE-2026-5936: An attacker can control a server-side HTTP request by supplying a crafted URL, c
HIGH
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services,...
2026-04-12
NVD CVE
CVE-2026-40393: In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occu
HIGH
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
2026-04-10
NVD CVE
CVE-2026-5483: A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in
HIGH
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a...
2026-04-08
CISA KEV
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
2026-04-08
NVD CVE
CVE-2026-39394: CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, mo
HIGH
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Install::index() controller reads the host POST...
2026-04-08
NVD CVE
CVE-2026-33466: Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash
HIGH
Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction...
2026-04-08
NVD CVE
CVE-2026-39429: kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kub
HIGH
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no...
2026-04-07
NVD CVE
CVE-2026-34045: Podman Desktop is a graphical tool for developing on containers and Kubernetes.
HIGH
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger...
2026-04-06
CISA KEV
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
2026-04-06
NVD CVE
CVE-2026-35408: Directus is a real-time API and App dashboard for managing SQL database content.
HIGH
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without...
2026-04-05
NVD CVE
CVE-2019-25688: Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted...
2026-04-05
NVD CVE
CVE-2026-5569: A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impac
HIGH
A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls....
2026-04-05
NVD CVE
A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible...
2026-04-05
NVD CVE
CVE-2026-5562: A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts t
HIGH
A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code...
2026-04-05
NVD CVE
CVE-2019-25700: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL...
2026-04-05
NVD CVE
A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipulation of the argument cwd can lead to unrestricted upload. The...
2026-04-05
NVD CVE
CVE-2019-25674: CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated
HIGH
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php...
2026-04-05
NVD CVE
CVE-2026-5584: A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the func
HIGH
A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py of the component query Endpoint. Such manipulation leads to code...