LIVE FEED
1767 events · 4 sources · newest first
Events in view
1767
all sources
Critical
1492
severity
Active sources
4
collectors
Last sync
2026-08-26 00:01
UTC
2026-08-09
NVD CVE
CVE-2026-71984: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71984firmwaremalicious-commandsmsinvd-cve
2026-08-09
NVD CVE
CVE-2026-71989: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71990: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the...
axe6600command-injectioncve-2026-71990firmwaremsinvd-cveradixremote-attacks
2026-08-08
NVD CVE
CVE-2026-71958: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71957: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71983: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71953: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71951: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71954: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71949: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71950: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71955: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71956: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71946: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71947: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71948: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori
CRITICAL
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to...
administrator-accountai-copilotauthorization-bypasscontents-generatorcve-2026-14526frontend-pagejavascriptmalicious-workflow
2026-08-08
NVD CVE
CVE-2026-71952: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71944: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71945: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can...
nvd-cve
2026-08-07
NVD CVE
CVE-2026-56793: Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im
HIGH
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,...
cve-2026-56793cybersecuritydelldfar-252-204-7012improper-authenticationincident-responsenist-800-171nvd-cve
2026-08-07
NVD CVE
CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL
HIGH
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
azure-sqlimproper-restrictions-communicationsnetworks-vulnerabilitiesnvd-cveprivileges-elevationunauthorized-attacks
2026-08-07
NVD CVE
CVE-2026-14364: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CRITICAL
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the...
accounts-takeovernvd-cvepassword-reset-validationtruebookerunauthenticated-attacksvulnerabilitywordpress-plugin
2026-08-07
NVD CVE
CVE-2026-14365: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CRITICAL
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that...
authorization-bypassnvd-cvepasswords-manipulationsunauthenticated-attacksuser-accountvulnerabilitywordpress-plugin
2026-08-07
NVD CVE
CVE-2026-70332: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unau
CRITICAL
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
microsoftnetworks-spoofingnvd-cveoffice-sharepointssrfvulnerability
2026-08-07
NVD CVE
CVE-2026-50515: Deserialization of untrusted data in Azure Service Bus allows an authorized atta
CRITICAL
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
azure-service-busdeserializationexecution-codenetworknvd-cveuntrusted-datavulnerability
2026-08-07
NVD CVE
CVE-2026-62830: Missing authorization in Azure SRE Agent allows an authorized attacker to elevat
CRITICAL
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
authorized-accessazure-sres-agentsmissing-authorizationnetworks-attacksnvd-cveprivileges-elevation
2026-08-07
NVD CVE
CVE-2026-63508: Missing authentication for critical function in Microsoft Planetary Computer Pro
CRITICAL
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
authenticationcve-2026-63508microsoftnetworks-attacksnvd-cveplanetary-computer-proprivileges-escalationunauthorized-access
2026-08-07
NVD CVE
CVE-2026-68823: Exposed dangerous method or function in Azure Confidential Ledger allows an auth
CRITICAL
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
authentication-breachazure-confidential-ledgersincident-responsenist-800-171nvd-cveransomwarevulnerability
2026-08-06
NVD CVE
CVE-2026-64993: Dell RVTools versions prior to 4.8.1, contains an improper certificate validatio
MEDIUM
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of...
collectorconfidentialitycve-2026-64993delldell-rvtoolimproper-certificate-validationintegrityloss
2026-08-06
NVD CVE
CVE-2026-54489: Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.
CRITICAL
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this...
active-session-credentialsadministratorauthenticate-usercritical-vulnerabilitycve-2026-54489dell-virtual-storage-integratorimpersonationinformation-disclosure
2026-08-06
NVD CVE
CVE-2026-53984: Ground Station prior to 0.6.0 contains an unauthenticated database-destruction a
CRITICAL
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated...
arbitrary-data-injectionattackers-controlled-serverscve-2026-53984database-backupdatabase-destructiondisabled-authenticationexec-driver-sqlfull-restore-command
2026-08-06
NVD CVE
CVE-2026-67622: Flowise through 3.1.4 contains an insecure direct object reference vulnerability
CRITICAL
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by...
assistants-metadataauthenticate-attackscve-2026-67622files-uploadinsecure-direct-object-referencenvd-cveopenai-assistantvulnerability
2026-08-06
NVD CVE
CVE-2026-70558: Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied pa
CRITICAL
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and...
attack-pathclasspath-shadowscve-2026-70558dinkyfile-transferjvm-startsnvd-cvepath-validation
2026-08-05
NVD CVE
CVE-2026-17556: A path traversal vulnerability was identified in GitHub Enterprise Server that a
CRITICAL
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage...
2026-08-05
NVD CVE
CVE-2026-10059: A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator contro
CRITICAL
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator....
access-controlcluster-controlclustercuratorcybersecuritydefense-industrial-baseinformation-securitykubernetemulticluster-engine
2026-08-05
NVD CVE
CVE-2026-66747: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS,
CRITICAL
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package...
c2cleartext-communicationscommands-and-controlcve-2026-66747endlessdoorfirmwareimplantnvd-cve
2026-08-05
NVD CVE
CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operat
CRITICAL
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM...
advanced-cluster-managementapplication-subscription-controllercluster-adminscluster-role-bindingcve-2026-10090helmkubernetenamespaces-scoped-privilege
2026-08-05
NVD CVE
CVE-2026-9273: The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restr
CRITICAL
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0....
accounts-takeovercve-2026-9273cybersecurityemails-spoofinginformation-securitykadence-membershipnoncenvd-cve
2026-08-05
NVD CVE
CVE-2026-4431: The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modi
CRITICAL
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is...
ajaxauthenticationauthorizationcve-2026-4431cybersecuritydata-integritydata-modificationnvd-cve