LIVE FEED
1518 events · 13 sources · newest first
Events in view
1518
all sources
Critical
1518
severity
Active sources
13
collectors
Last sync
2026-08-28 18:00
UTC
All sources
NVD CVE · 1796CISA KEV · 1686News · 435CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-31
NVD CVE
CVE-2026-68771: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai
CRITICAL
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and...
ai-model-toolarbitrary-code-executioncomfyuicve-2026-68771cve-disclosuresimages-uploadnvd-cvepickle-vulnerability
2026-07-30
NVD CVE
CVE-2026-44108: Due to a flaw in the execution order of scripts during shutdown, the firewall is
CRITICAL
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally...
cisacmmc-level-2cve-2026-44108dodfirewallincident-responseinternal-servicesnetwork-security
2026-07-30
NVD CVE
CVE-2026-44101: Due to missing authentication the CHARX OCPP Agent service allows an unauthentic
CRITICAL
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to...
authenticationbackends-reconfigurationscharging-station-securitycharxcompliance-riskcve-2026-44101data-disclosuredenial
2026-07-30
NVD CVE
CVE-2026-44100: The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig
CRITICAL
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
charging-infrastructurecharging-pointcharxcve-2026-44100denialfiles-tamperingjupicorenvd-cve
2026-07-30
NVD CVE
CVE-2026-44092: An unauthenticated remote attacker can inject malicious input into the ModbusSer
CRITICAL
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
availability-losscve-2026-44092input-injectioninput-validationintegrity-lossmodbus-servermqttnvd-cve
2026-07-30
NVD CVE
CVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for
CRITICAL
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
82x-befores-823383x-befores-833384x-befores-842485x-befores-859cve-2026-17543nvd-cvephp-vulnerabilitiessql-injection
2026-07-30
NVD CVE
CVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with s
CRITICAL
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
2026-07-30
NVD CVE
CVE-2026-44091: An unauthenticated remote attacker can post a malicious ID to the MQTT Broker re
CRITICAL
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.
cmmcconfiguration-integritycve-2026-44091defense-industrial-basefedrampincident-responsemalicious-idmqtt-broker
2026-07-30
NVD CVE
CVE-2026-7849: Due to improper neutralization of special elements, an unauthenticated remote at
CRITICAL
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
cmmccommand-injectionconfigurations-vulnerabilitiescve-2026-7849defense-industrial-baseneutralization-failurenist-800-171nvd-cve
2026-07-30
NVD CVE
CVE-2026-13379: The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remot
CRITICAL
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process
2026-07-30
NVD CVE
CVE-2026-44104: The firmware update process for the basemodule of the charging controller only v
CRITICAL
The firmware update process for the basemodule of the charging controller only validates the
CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a...
charging-controllercmmc-level-2crc32-checksumcryptographic-signatures-verificationcve-2026-44104defense-industrial-basefedramp-authorizationfirmware
2026-07-30
NVD CVE
CVE-2026-66756: Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue
CRITICAL
Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
2026-07-30
NVD CVE
CVE-2026-44090: Due to missing authentication, an unauthenticated remote attacker may access the
CRITICAL
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.
authentication-bypassbrokers-exploitationcve-2026-44090devices-compromisefirewall-bypassiots-securitymissing-authenticationmqtt-broker
2026-07-30
NVD CVE
CVE-2026-48449: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user...
adobe-campaign-classicarbitrary-code-executioncisacode-executioncve-2026-48449defense-industrial-basedodincorrect-authorization
2026-07-30
NVD CVE
CVE-2026-66421: OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all
CRITICAL
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup...
admins-endpointsagents-transcriptscooeycross-site-scriptingcve-2026-66421html-injectionjavascript-executionnvd-cve
2026-07-30
NVD CVE
CVE-2026-67594: Spikster through commit e1cdf8c contains a missing authentication vulnerability
CRITICAL
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is...
api-enumerationapi-vulnerabilitiesauthentication-bypasscapiauth-middlewarecommit-e1cdf8ccve-2026-67594database-user-creationfile-write
2026-07-30
NVD CVE
CVE-2026-66418: OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t
CRITICAL
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed...
audit-logsauthentication-bypassconfiguration-changescontents-security-policycross-site-scriptingcve-2026-66418endpoint-accessesfailed-login
2026-07-30
NVD CVE
CVE-2026-28323: SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass
CRITICAL
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
authentication-bypasscisacmmc-level-2compliancecve-2026-28323defense-industrial-basedodfedramp-authorization
2026-07-30
NVD CVE
CVE-2026-4978: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection.
This issue affects Traffic Analysis System: from 30 before 34.
cisacmmccompliance-riskcve-2026-4978defense-industrial-basedodincident-responsenist-800-171
2026-07-30
NVD CVE
CVE-2026-12940: IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in...
code-executioncve-2026-12940environment-variable-injectionibm-langflowmcp-stdo-launchermodel-context-protocolnvd-cveopen-source-software
2026-07-30
NVD CVE
CVE-2026-15435: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
CRITICAL
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request...
compliance-riskcve-2026-15435directories-traversalfile-writeibm-apps-connect-enterprisenvd-cveremote-code-executionsecurity-patch
2026-07-30
NVD CVE
CVE-2026-16610: The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to
CRITICAL
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save...
admin-and-sites-enhancementauthentication-bypasscode-executioncve-2026-16610cve-disclosureseval-exploitnvd-cveplugins-vulnerabilities
2026-07-30
NVD CVE
CVE-2026-12118: IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated
CRITICAL
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
arbitrary-code-executioncode-executioncve-2026-12118deserializationdeserialization-vulnerabilitiesibmintegration-softwarenvd-cve
2026-07-30
NVD CVE
CVE-2026-67208: Juggle through 1.6.0 contains a remote code execution vulnerability that allows
CRITICAL
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default...
compliance-riskcve-2026-67208default-credentialsdockerh2-databaseincident-responsejugglenvd-cve
2026-07-29
NVD CVE
CVE-2026-18191: VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allo
CRITICAL
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.
administrator-credentialscisacmmc-level-2compliance-riskcve-2026-18191devices-vulnerabilitiesdfar-252-204-7012dod
2026-07-29
NVD CVE
CVE-2026-65884: Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The
CRITICAL
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative...
2026-07-29
NVD CVE
CVE-2026-65887: Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gri
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding...
2026-07-29
NVD CVE
CVE-2026-65883: Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca
CRITICAL
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
2026-07-29
NVD CVE
CVE-2026-65890: Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
2026-07-29
NVD CVE
CVE-2026-65888: Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.2
CRITICAL
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
2026-07-29
NVD CVE
CVE-2026-60113: AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 c
CRITICAL
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network...
ammoapi-exposureauthentication-vulnerabilitycisacve-2026-60113deep-space-networkdefense-industrial-basehttps-requests
2026-07-29
NVD CVE
CVE-2026-60112: AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authenticatio
CRITICAL
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by...
ammo-instrument-toolkitarbitrary-command-executionauthentication-bypasscommand-buscommand-injectioncve-2026-60112defensives-mitigationsmissing-authentication
2026-07-29
NVD CVE
CVE-2026-18072: The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick
CRITICAL
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists...
administrator-privilegesadvanced-responsive-video-embedderauthentication-bypasscve-2026-18072cybersecuritydeveloper-account-compromisehardcoded-credentialkick
2026-07-29
NVD CVE
CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CRITICAL
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature...
applications-securitycve-2026-14529cybersecuritydefense-industrial-basedfar-252-204-7012ibmnist-800-171nvd-cve
2026-07-29
NVD CVE
CVE-2025-10656: The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin f
CRITICAL
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes...
admin-account-creationcve-2025-10656cve-disclosurese-commercelights-pluginmissing-authorizationnvd-cveplugins-vulnerabilities
2026-07-29
NVD CVE
CVE-2026-33267: Improper Input Validation vulnerability in Apache Traffic Server.
This issue af
CRITICAL
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15...
2026-07-29
NVD CVE
CVE-2026-14900: The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Cod
CRITICAL
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the...
authentication-bypasscode-injectioncve-2026-14900eval-exploitnonce-checksnvd-cvephp-evalplugins-vulnerabilities
2026-07-29
NVD CVE
CVE-2026-14488: The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via
CRITICAL
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the...
arbitrary-deletionauthorization-bypasscisaciscocve-2026-14488frontend-submissionmeta-boxmissing-authorization
2026-07-29
NVD CVE
CVE-2026-41939: Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability
CRITICAL
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by...
administrative-accesscares-everywhere-gatewayscmmccompliance-riskcve-2026-41939defense-industrial-basedeployment-interfacesend
2026-07-28
NVD CVE
CVE-2026-14973: IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil
CRITICAL
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
asperacve-2026-14973cybersecuritydata-integritydata-lossesdesktop-applicationsdownloads-destinationfile-integrity