LIVE FEED
1767 events · 4 sources · newest first
Events in view
1767
all sources
Critical
1492
severity
Active sources
4
collectors
Last sync
2026-08-26 00:01
UTC
2026-08-14
NVD CVE
CVE-2026-17182: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass a
CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
authentication-bypasscve-2026-17182db2ibmimproper-validationnvd-cvepaths-segmentsremote-attackers
2026-08-14
NVD CVE
CVE-2026-73678: MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated re
CRITICAL
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts...
apiarbitrary-code-executioncredentialcve-2026-73678endpointexecllmmind-platform
2026-08-13
NVD CVE
CVE-2026-72841: luci-app-openvpn fails to properly validate the instance_name2 parameter during
CRITICAL
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers...
authenticate-usercve-2026-72841files-uploadluci-apps-openvpnmalicious-payloadsnvd-cveopenvpnpath-traversal
2026-08-13
NVD CVE
CVE-2026-72850: Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authe
CRITICAL
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .....
arbitrary-file-writeauthenticate-attacksauthenticationbudibasecloud-storagecve-2026-72850exportfile-traversal
2026-08-13
NVD CVE
CVE-2026-72842: luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privile
CRITICAL
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit...
acl-inconsistencyauthorization-checkscontainer-managementcve-2026-72842host-side-scriptlow-privileges-authenticate-userlucuses-apps-lxcnetwork-security
2026-08-13
NVD CVE
CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain una
CRITICAL
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
authenticationcve-2026-19297ibmlangflownvd-cveossremote-attackerssecurity
2026-08-13
NVD CVE
CVE-2026-72776: AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution v
CRITICAL
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected...
agenticseekapi-vulnerabilitiesbashinterpretercommand-injectioncors-misconfigurationcvecve-2026-72776host-level-compromise
2026-08-13
NVD CVE
CVE-2026-19747: A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B
CRITICAL
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE...
attack-vectorscommand-injectioncve-2026-19747cybersecurityexploitnetwork-securitynetworks-devicesnvd-cve
2026-08-13
NVD CVE
CVE-2026-17482: IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e
CRITICAL
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
cve-2026-17482documentationfile-pathibmibm-documentation-offlineimproper-controlnvd-cveremote-code-execution
2026-08-13
NVD CVE
CVE-2026-72839: filebrowser through 2.63.16 fails to properly restrict scope and permissions whe
CRITICAL
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server...
access-controlcve-2026-72839default-settingsfile-managementfile-systemfilebrowserfiles-accessfiles-downloads
2026-08-13
NVD CVE
CVE-2026-73532: Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introdu
CRITICAL
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file...
administrator-accountbackdoorcve-2026-73532decommissionedfluent-forms-prosmalicious-codenvd-cvepersistent-file
2026-08-13
NVD CVE
CVE-2026-53791: rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that all
CRITICAL
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source...
access-controls-bypassallow-deny-rulecve-2026-53791daemonforged-source-addressip-spoofingnetwork-securitynvd-cve
2026-08-13
NVD CVE
CVE-2026-73533: Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introd
CRITICAL
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file...
administrator-accountbackdoorcve-2026-73533decommissionedmalicious-codeninja-table-pronvd-cvepersistent-file
2026-08-13
NVD CVE
CVE-2026-67614: CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the We
CRITICAL
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an...
authenticationcve-2026-67614cyberpanelfastapihard-coded-secretjwtnvd-cveremote-attacks
2026-08-13
NVD CVE
CVE-2026-14525: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphe
CRITICAL
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
application-serverauthentication-bypasscve-2026-14525featureibmlibertynvd-cvertcomm-10
2026-08-13
NVD CVE
CVE-2026-72851: Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability i
CRITICAL
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to...
automationbudibasecve-2026-72851data-modificationdatasourcedatum-exfiltrationexecutives-queriesjson
2026-08-13
NVD CVE
CVE-2026-17197: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
client-asserted-identitycve-2026-17197ibmibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6
2026-08-13
NVD CVE
CVE-2026-16815: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
cve-2026-16815denialibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6nvd-cve
2026-08-13
NVD CVE
CVE-2026-16961: IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could s
HIGH
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
cvecve-2026-16961data-deletiondata-modificationdatabaseibmibm-iinformation-disclosure
2026-08-13
NVD CVE
CVE-2026-16867: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server reso
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
authenticate-userauthenticationcve-2026-16867ibm-iimproper-authenticationntlm-session-negotiationnvd-cveremote-attackers
2026-08-13
NVD CVE
CVE-2026-18193: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
2026-08-13
NVD CVE
CVE-2026-18249: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.
2026-08-13
NVD CVE
CVE-2026-17101: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.
2026-08-13
NVD CVE
CVE-2026-17481: IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e
HIGH
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.
arbitrary-code-executioncve-2026-17481documentationibmimproper-outputs-neutralizationlognvd-cveoffline
2026-08-13
NVD CVE
CVE-2026-17206: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
arbitrary-code-executionbuffer-overflowcve-2026-17206ibmibm-invd-cveoperating-systemsremote-code-execution
2026-08-12
NVD CVE
CVE-2026-18847: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to ha
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
credential-harvestingcve-2026-18847iibmibm-inavigatornvd-cveremote-attacks
2026-08-12
NVD CVE
CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec
CRITICAL
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
arbitrary-code-executionauthenticate-attackercve-2026-16860ibmibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5
2026-08-12
NVD CVE
CVE-2026-73519: WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret comp
CRITICAL
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication...
nvd-cve
2026-08-12
NVD CVE
CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca
CRITICAL
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
cve-2026-17276high-authority-threadibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6improper-authorization
2026-08-12
NVD CVE
CVE-2026-73268: A flaw was found in the cluster-curator-controller component of multicluster eng
CRITICAL
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is...
nvd-cve
2026-08-12
NVD CVE
CVE-2026-72508: A flaw was found in the multicloud-operators-subscription component of Red Hat A
CRITICAL
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating...
nvd-cve
2026-08-12
NVD CVE
CVE-2024-27253: IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated
CRITICAL
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
nvd-cve
2026-08-12
NVD CVE
CVE-2026-71471: A flaw was found in acm-search-v2-rhel9. An attacker with administrative privile
CRITICAL
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the...
nvd-cve
2026-08-12
NVD CVE
CVE-2026-70398: A flaw was found in multicloud-integrations, a component of Red Hat Advanced Clu
CRITICAL
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster...
argos-cdbearer-tokencloud-securitycve-2026-70398data-disclosuregitopsclustermulticloud-integrationnvd-cve
2026-08-12
NVD CVE
CVE-2026-72526: A flaw was found in the multicloud-integrations component. The Application propa
CRITICAL
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A...
annotation-validationapplications-custom-resourceargos-cdcluster-managementcode-executioncve-2026-72526hub-clustermanifest-synchronization
2026-08-12
NVD CVE
CVE-2026-17083: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
CRITICAL
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd-cve
2026-08-12
NVD CVE
CVE-2025-41769: The device's PROFINET service is affected by a buffer overflow vulnerability tha
CRITICAL
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or...
arbitrary-code-executionbuffer-overflowcve-2025-41769default-configurationdevice-rebootexploitindustrial-control-systemnetworks-vulnerabilities
2026-08-12
NVD CVE
CVE-2026-17111: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker co
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
cve-2026-17111data-deletiondata-modificationdatabaseibmibm-iibm-i-7-3ibm-i-7-4
2026-08-12
NVD CVE
CVE-2026-16627: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
HIGH
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate...
2026-08-12
NVD CVE
CVE-2026-17616: IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
MEDIUM
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide...
cryptographic-validationcve-2026-17616ibmibm-security-verify-accessibm-verify-identity-accessibm-verify-identity-access-containernvd-cvereverse-proxy