LIVE FEED
1803 events · 13 sources · newest first
Events in view
1803
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-29
NVD CVE
CVE-2026-14900: The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Cod
CRITICAL
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the...
authentication-bypasscode-injectioncve-2026-14900eval-exploitnonce-checksnvd-cvephp-evalplugins-vulnerabilities
2026-07-29
NVD CVE
CVE-2026-65890: Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
2026-07-29
NVD CVE
CVE-2026-33267: Improper Input Validation vulnerability in Apache Traffic Server.
This issue af
CRITICAL
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15...
2026-07-29
NVD CVE
CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CRITICAL
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature...
applications-securitycve-2026-14529cybersecuritydefense-industrial-basedfar-252-204-7012ibmnist-800-171nvd-cve
2026-07-29
NVD CVE
CVE-2026-14488: The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via
CRITICAL
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the...
arbitrary-deletionauthorization-bypasscisaciscocve-2026-14488frontend-submissionmeta-boxmissing-authorization
2026-07-29
NVD CVE
CVE-2026-65883: Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca
CRITICAL
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
2026-07-29
NVD CVE
CVE-2026-58163: Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corr
HIGH
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apacheapache-traffic-serverscache-corruptioncve-2026-58163data-integritydata-lossesincident-responsenvd-cve
2026-07-29
NVD CVE
CVE-2026-13697: undici's cache interceptor mishandles malformed Cache-Control private directives
HIGH
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such...
cache-controlcaches-interceptorscve-2026-13697errors-handlinghttps-headersinformation-disclosuremalformed-headersnvd-cve
2026-07-29
NVD CVE
CVE-2026-58179: The Apache Traffic Server regex_remap plugin overflows the stack and integers fr
HIGH
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apache-traffic-serverscve-2026-58179cve-disclosuresinteger-overflownvd-cveregex-remap-pluginssecurity-patchsoftware
2026-07-29
NVD CVE
CVE-2026-58185: The Apache Traffic Server intercept plugin has a use-after-free.
This issue aff
MEDIUM
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to...
apache-softwaresapache-traffic-serverscritical-vulnerabilitycve-2026-58185freeintercept-pluginmemory-safetynvd-cve
2026-07-29
NVD CVE
CVE-2026-58177: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traver
HIGH
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade...
apache-traffic-serversbound-writecmmccritical-patchescve-2026-58177defense-industrial-basefedrampfree
2026-07-29
NVD CVE
CVE-2026-41939: Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability
CRITICAL
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by...
administrative-accesscares-everywhere-gatewayscmmccompliance-riskcve-2026-41939defense-industrial-basedeployment-interfacesend
2026-07-29
NVD CVE
CVE-2026-60113: AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 c
CRITICAL
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network...
ammoapi-exposureauthentication-vulnerabilitycisacve-2026-60113deep-space-networkdefense-industrial-basehttps-requests
2026-07-29
NVD CVE
CVE-2026-60112: AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authenticatio
CRITICAL
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by...
ammo-instrument-toolkitarbitrary-command-executionauthentication-bypasscommand-buscommand-injectioncve-2026-60112defensives-mitigationsmissing-authentication
2026-07-28
NVD CVE
CVE-2026-14973: IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil
CRITICAL
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
asperacve-2026-14973cybersecuritydata-integritydata-lossesdesktop-applicationsdownloads-destinationfile-integrity
2026-07-28
NVD CVE
CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b
HIGH
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
applications-securityauthentication-bypasscve-2026-16184cybersecuritydata-protectiondefense-industrial-baseibmnist-800-171
2026-07-28
NVD CVE
CVE-2026-14512: IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-a
CRITICAL
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
applications-securityauthentication-bypasscve-2026-14512cybersecuritydata-protectiondefense-industrial-basedfar-252-204-7012ibm
2026-07-28
NVD CVE
CVE-2026-14959: IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated at
CRITICAL
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
asperaauthenticationcve-2026-14959cybersecurityfaspexibmnvd-cvepatch-management
2026-07-28
NVD CVE
CVE-2026-14958: IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated at
CRITICAL
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
asperaauthenticationcve-2026-14958cybersecurityfaspexibmnvd-cvepatch-management
2026-07-28
NVD CVE
CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
2026-07-28
NVD CVE
CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a
HIGH
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
2026-07-28
NVD CVE
CVE-2026-16462: In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a
CRITICAL
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
arbitrary-code-executioncritical-infrastructurecve-2026-16462cybersecuritydata-breachesendpoint-securityindustrial-control-systemnvd-cve
2026-07-28
NVD CVE
CVE-2026-15014: The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart
CRITICAL
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including,...
accounts-takeoverauthenticationauthentication-bypassbilling-phonecve-2026-15014cybersecuritydefense-industrial-basedfar-252-204-7012
2026-07-28
NVD CVE
CVE-2026-14446: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access con
CRITICAL
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
administrative-consolebroken-access-controlcve-2026-14446cybersecuritydefense-industrial-basedfar-252-204-7012ibmincident-response
2026-07-27
NVD CVE
CVE-2026-45623: PostCSS takes a CSS file and provides an API to analyze and modify its rules by
HIGH
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH...
2026-07-27
NVD CVE
CVE-2026-48144: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th
CRITICAL
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes...
apacheapache-thriftc-glibcertificate-validationcve-2026-48144cybersecurityhost-mismatchinformation-security
2026-07-27
NVD CVE
CVE-2026-55971: Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This is
CRITICAL
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
apache-thriftbuffer-overflowccve-2026-55971cyber-securitydfar-252-204-7012heap-based-buffer-overflowincident-response
2026-07-27
NVD CVE
CVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal reque
HIGH
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
access-controlauthentication-weaknessescompliance-riskcve-2026-66014internal-requests-processingjfrog-artifactorynvd-cveprivileges-escalation
2026-07-27
NVD CVE
CVE-2026-58023: Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue a
CRITICAL
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
apache-thriftbound-readc-glib-bindingscve-2026-58023cybersecuritydfar-252-204-7012incident-responsenist-800-171
2026-07-27
NVD CVE
CVE-2026-58662: Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerabi
CRITICAL
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version...
apache-thriftbound-readccve-2026-58662cyber-securitydefense-industrial-basedod-supply-chainimproper-input-validation
2026-07-25
NVD CVE
CVE-2026-66012: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST
CRITICAL
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This...
accesses-auth-codeadministrators-takeoveradmins-role-enforcementapi-tokenarbitrary-files-writingconf-conf-jsoncontext-isolationcookie-keys-plaintext
2026-07-24
NVD CVE
CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to
CRITICAL
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
azure-app-serviceazure-security-vulnerabilityimproper-access-controlnetworks-attacksnvd-cveunauthorized-privileges-escalation
2026-07-24
NVD CVE
CVE-2026-58275: Missing authorization in Azure DNS allows an unauthorized attacker to elevate pr
CRITICAL
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
azure-dnscve-2026-58275missing-authorizationnetworks-compromisenvd-cveprivileges-elevationunauthorized-attacks
2026-07-24
NVD CVE
CVE-2026-62825: Improper authentication in Azure Key Vault allows an unauthorized attacker to el
CRITICAL
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
azure-keys-vaultcybersecurityimproper-authenticationnetworks-attacksnvd-cveprivileges-escalationunauthorized-accessvulnerability
2026-07-24
NVD CVE
CVE-2026-56160: Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att
CRITICAL
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
authorize-attackersazure-red-hat-openshiftimproper-authorizationnetworknvd-cveprivileges-elevationvulnerability
2026-07-24
NVD CVE
CVE-2026-56165: Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker
CRITICAL
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
buffer-overflowcve-2026-56165malware-attacksmicrosoft-accountsnetwork-executionnvd-cveunauthorized-access
2026-07-24
NVD CVE
CVE-2026-54120: Improper input validation in Microsoft Surface allows an authorized attacker to
CRITICAL
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
authorize-attackersexecutable-codeimproper-input-validationmicrosoft-surfacenetworknvd-cvevulnerability
2026-07-24
NVD CVE
CVE-2026-56191: Improper authentication in Microsoft Exchange Online allows an unauthorized atta
CRITICAL
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
cve-2026-56191improper-authenticationmicrosoft-exchange-onlinenetworks-tamperingnvd-cveunauthorized-access
2026-07-24
NVD CVE
CVE-2026-50517: Deserialization of untrusted data in M365 Copilot allows an authorized attacker
CRITICAL
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
authorize-attackerscode-executioncve-2026-50517deserializationm365-copilotnetworknvd-cveuntrusted-data
2026-07-24
NVD CVE
CVE-2026-62835: Improper authorization in Azure Portal allows an unauthorized attacker to disclo
CRITICAL
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
azure-portalscve-2026-62835improper-authorizationinformation-disclosurenetworknvd-cveunauthorized-access