LIVE FEED
1516 events · 13 sources · newest first
Events in view
1516
all sources
Critical
1516
severity
Active sources
13
collectors
Last sync
2026-08-28 12:00
UTC
All sources
NVD CVE · 1794CISA KEV · 1686News · 424CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-28
NVD CVE
CVE-2026-40541: An improper neutralization of input during web page generation ('Cross-site Scri
CRITICAL
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI...
2026-08-28
NVD CVE
CVE-2026-76581: The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa
CRITICAL
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the...
2026-08-28
NVD CVE
CVE-2026-82082: NUMail developed by Green-Computing has an OS Command Injection vulnerability. U
CRITICAL
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
2026-08-27
NVD CVE
CVE-2026-81735: startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its l
CRITICAL
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to...
arbitrary-command-executionauthentication-bypassauthentication-middlewarechild-process-execcommit-c2ad42e3eb9b27830db41a3e6f51ca7179d9b168cve-2026-81735file-read-write-toollisten-address-default
2026-08-27
NVD CVE
CVE-2026-81096: ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped,
CRITICAL
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected...
attribute-lookupauthenticationbearer-tokencode-executioncve-2026-81096debugging-enabledhttps-serverimport-allowlist
2026-08-27
NVD CVE
CVE-2026-81094: The mcp-router CLI served its MCP aggregator on every interface and enforced aut
CRITICAL
The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the...
aggregatorauthenticationclicommand-line-interfacecve-2026-81094default-configurationloopback-addressmcp-router
2026-08-27
NVD CVE
CVE-2026-81098: The Telnyx MCP server exposed its HTTP transport on every interface and did not
CRITICAL
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and...
api-keyauthenticationclients-secretscode-executioncredentials-exposurecve-2026-81098https-transportmcp-server
2026-08-27
NVD CVE
CVE-2026-81701: openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-i
CRITICAL
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification....
arbitrary-code-executionclicode-executioncryptocryptographic-keyscve-2026-81701malicious-pluginsnvd-cve
2026-08-27
NVD CVE
CVE-2026-81707: openssl_encrypt before 1.4.9 fails to sanitize the email field of imported ident
CRITICAL
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users....
attackbandbypasscve-2026-81707fingerprintidentitykey-substitutionsnvd-cve
2026-08-27
NVD CVE
CVE-2026-81700: openssl_encrypt versions before 1.4.9 contain a signature verification vulnerabi
CRITICAL
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG,...
cryptographic-vulnerabilitiescve-2026-81700expired-keysgpggpgs-runnerhost-processmalicious-pluginsnvd-cve
2026-08-27
NVD CVE
CVE-2026-81702: openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when l
CRITICAL
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate...
attackcve-2026-81702encryptionencryption-vulnerabilitiesfingerprint-validationidentity-managementidentityjsonkey-management
2026-08-26
NVD CVE
CVE-2026-18431: The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi
CRITICAL
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is...
arbitrary-file-writeauthorization-weaknessesavadas-themecve-2026-18431fusion-builderinput-validation-weaknessesnvd-cvephp-execution
2026-08-26
NVD CVE
CVE-2026-80203: The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope
CRITICAL
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses...
2faapi-keyapi-key-scopeauthenticationauthorizationcve-2026-80203gravgrav-plugin-api
2026-08-26
NVD CVE
CVE-2026-80428: ILIAS deserialises stored session data for an unauthenticated caller. The Shibbo
CRITICAL
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts...
applications-vulnerabilitiesauthentication-bypasscode-executioncve-2026-80428deserializationfile-writeilialtus-authentication
2026-08-26
NVD CVE
CVE-2026-81032: NebulaGraph exposes its runtime configuration over an unauthenticated HTTP servi
CRITICAL
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and...
certificate-exposurecve-2026-81032daemongflagincident-responsenebulagraphnvd-cvepassword-file-exposure
2026-08-26
NVD CVE
CVE-2026-75896: Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technolog
CRITICAL
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.
This issue affects Liderahenk: before 3.5.5.
authentication-vulnerabilitybefore-3-5-5credentials-vulnerabilitycve-2026-75896default-credentialsdefault-usernamehard-coded-credentialsliderahenk
2026-08-26
NVD CVE
CVE-2026-19632: The TranslatePress – Translate Multilingual sites with AI Translation plugin for
CRITICAL
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the...
administrator-accounts-takeoverajax-actionautomatic-strings-savingcve-2026-19632login-parameternvd-cvepassword-resetplaintext-reset-keys
2026-08-25
NVD CVE
CVE-2026-79911: A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210
CRITICAL
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such...
buffer-overflowcgi-handlercstecgicgicve-2026-79911exploit-disclosurefirmware-vulnerabilitiesiots-securityn600r
2026-08-25
NVD CVE
CVE-2026-76195: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of...
adobeadobe-campaign-classicarbitrary-code-executioncvecve-2026-76195nvd-cveos-command-injectionsecurity
2026-08-25
NVD CVE
CVE-2026-80104: DB-GPT builds the destination path for an uploaded skill from the multipart file
CRITICAL
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in...
application-packagecode-executioncve-2026-80104db-gptdirectories-traversalfiles-uploadmodule-replacementmultipart-file
2026-08-25
NVD CVE
CVE-2024-58378: Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged
CRITICAL
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies...
crubycve-2024-25062cve-2024-58378freejrubylibxml2nokogirinvd-cve
2026-08-25
NVD CVE
CVE-2026-63586: The web-based management interface uses a modified uhttpd server with CGI shell
CRITICAL
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a...
arbitrary-command-executioncgicommand-injectioncooeys-clubcve-2026-63586http-basic-authenticationnvd-cveroot-privileges-escalation
2026-08-25
NVD CVE
CVE-2026-78570: The Total Donations plugin for WordPress is vulnerable to Privilege Escalation i
CRITICAL
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of...
cve-2026-78570nvd-cveplugins-securityplugins-vulnerabilitiesprivileges-escalationsecurity-vulnerabilitytotals-donationsunauthenticated-attacks
2026-08-25
NVD CVE
CVE-2026-79675: NLTK before 3.10.3 fails to validate JVM options passed through the per-call opt
CRITICAL
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like...
agentpatharbitrary-code-executionargfilecode-injectioncve-2026-79675javajavaagentjvm
2026-08-25
NVD CVE
CVE-2026-16286: Unrestricted upload of file with dangerous type vulnerability in TRtek Technolog
CRITICAL
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to...
cve-2026-16286dangerous-files-typesfiles-uploadnvd-cverepository-managementsecurity-vulnerabilitysoftware-repository-managementsoftware-vulnerabilities
2026-08-25
NVD CVE
CVE-2022-51000: Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored lib
CRITICAL
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML...
code-executioncrubycve-2021-30560cve-2022-23308cve-2022-51000deniallibxml2libxslt
2026-08-25
NVD CVE
CVE-2026-78676: GitPython before 3.1.59 fails to safely re-serialize multi-line git-config value
CRITICAL
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config...
arbitrary-code-executioncode-injectionconfigs-corruptionscve-2026-78676directivegitgit-configgitpython
2026-08-25
NVD CVE
CVE-2026-76193: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)
CRITICAL
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this...
adobeadobe-campaign-classicarbitrary-code-executioncve-2026-76193nvd-cvesecurityservers-sides-requests-forgeryssrf
2026-08-25
NVD CVE
CVE-2026-79787: Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in it
CRITICAL
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned...
alluxioauthorization-headerawaw-signature-versions-4cve-2026-79787data-accessdata-deletiondata-modification
2026-08-25
NVD CVE
CVE-2026-76197: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of...
adobeadobe-campaign-classicarbitrary-code-executioncvecve-2026-76197nvd-cveos-command-injectionsecurity
2026-08-25
NVD CVE
CVE-2026-56710: Grav Login plugin versions before 1.0.16 fail to validate the target account's p
CRITICAL
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout...
accounts-securitiesadmin-super-accountapi-user-writeauthenticationbrute-force-protectioncve-2026-56710gravgrav-login-plugin
2026-08-25
NVD CVE
CVE-2026-78683: NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deseria
CRITICAL
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the...
arbitrary-code-executioncve-2026-78683deserializations-attacknltknvd-cvepickle-deserializationpickle-gadgetpython
2026-08-25
NVD CVE
CVE-2026-56705: Adminer before 5.4.3 fails to sanitize the server field before constructing a PD
CRITICAL
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn...
adminercode-executioncve-2026-56705nvd-cveodbcpdophpremote-code-execution
2026-08-25
NVD CVE
CVE-2026-78568: The Total Donations plugin for WordPress is vulnerable to SQL Injection in all v
CRITICAL
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
cve-2026-78568database-securitydatum-exfiltrationinsufficient-escapingnvd-cveplugins-vulnerabilitiesquery-preparationsql-injection
2026-08-25
NVD CVE
CVE-2026-80138: ClipBucket V5's web installer fails to properly validate or escape the php_cli_f
CRITICAL
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer...
arbitrary-code-executionclipbucketcommand-injectioncrafted-post-requestcve-2026-80138malicious-requestsnvd-cvephp-cli
2026-08-25
NVD CVE
CVE-2026-78477: The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versio
CRITICAL
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
administrator-privilegescve-2026-78477jawn-themenvd-cveprivileges-escalationsecurity-bulletinthemes-vulnerabilityunauthenticated-attacks
2026-08-24
NVD CVE
CVE-2026-78211: 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injec
CRITICAL
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter,...
4mosan4mosan-security-technologyadodbarbitrary-command-executioncve-2026-78211gcbs-doctormalicious-command-injectionnvd-cve
2026-08-24
NVD CVE
CVE-2026-71933: Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabiliti
CRITICAL
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these...
nvd-cve
2026-08-24
NVD CVE
CVE-2026-77915: rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that
CRITICAL
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes()...
administrator-privilegesapi-token-issuanceauthentication-bypasscve-2026-77915nvd-cverconfigregistration-controllerroles-default
2026-08-24
NVD CVE
CVE-2026-71921: Multiple DrayTek VigorSwitch models contain a pre-authentication command injecti
CRITICAL
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command...
nvd-cve