Skip to content
COOEY
LIVE FEED
1803 events · 13 sources · newest first
2026-07-29 NVD CVE
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the...
authentication-bypasscode-injectioncve-2026-14900eval-exploitnonce-checksnvd-cvephp-evalplugins-vulnerabilities
2026-07-29 NVD CVE
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
2026-07-29 NVD CVE
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15...
2026-07-29 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature...
applications-securitycve-2026-14529cybersecuritydefense-industrial-basedfar-252-204-7012ibmnist-800-171nvd-cve
2026-07-29 NVD CVE
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the...
arbitrary-deletionauthorization-bypasscisaciscocve-2026-14488frontend-submissionmeta-boxmissing-authorization
2026-07-29 NVD CVE
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
2026-07-29 NVD CVE
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apacheapache-traffic-serverscache-corruptioncve-2026-58163data-integritydata-lossesincident-responsenvd-cve
2026-07-29 NVD CVE
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such...
cache-controlcaches-interceptorscve-2026-13697errors-handlinghttps-headersinformation-disclosuremalformed-headersnvd-cve
2026-07-29 NVD CVE
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apache-traffic-serverscve-2026-58179cve-disclosuresinteger-overflownvd-cveregex-remap-pluginssecurity-patchsoftware
2026-07-29 NVD CVE
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to...
apache-softwaresapache-traffic-serverscritical-vulnerabilitycve-2026-58185freeintercept-pluginmemory-safetynvd-cve
2026-07-29 NVD CVE
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade...
apache-traffic-serversbound-writecmmccritical-patchescve-2026-58177defense-industrial-basefedrampfree
2026-07-29 NVD CVE
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by...
administrative-accesscares-everywhere-gatewayscmmccompliance-riskcve-2026-41939defense-industrial-basedeployment-interfacesend
2026-07-29 NVD CVE
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network...
ammoapi-exposureauthentication-vulnerabilitycisacve-2026-60113deep-space-networkdefense-industrial-basehttps-requests
2026-07-29 NVD CVE
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by...
ammo-instrument-toolkitarbitrary-command-executionauthentication-bypasscommand-buscommand-injectioncve-2026-60112defensives-mitigationsmissing-authentication
2026-07-28 NVD CVE
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
asperacve-2026-14973cybersecuritydata-integritydata-lossesdesktop-applicationsdownloads-destinationfile-integrity
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
applications-securityauthentication-bypasscve-2026-16184cybersecuritydata-protectiondefense-industrial-baseibmnist-800-171
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
applications-securityauthentication-bypasscve-2026-14512cybersecuritydata-protectiondefense-industrial-basedfar-252-204-7012ibm
2026-07-28 NVD CVE
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
asperaauthenticationcve-2026-14959cybersecurityfaspexibmnvd-cvepatch-management
2026-07-28 NVD CVE
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
asperaauthenticationcve-2026-14958cybersecurityfaspexibmnvd-cvepatch-management
2026-07-28 NVD CVE
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
2026-07-28 NVD CVE
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
2026-07-28 NVD CVE
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
arbitrary-code-executioncritical-infrastructurecve-2026-16462cybersecuritydata-breachesendpoint-securityindustrial-control-systemnvd-cve
2026-07-28 NVD CVE
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including,...
accounts-takeoverauthenticationauthentication-bypassbilling-phonecve-2026-15014cybersecuritydefense-industrial-basedfar-252-204-7012
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
administrative-consolebroken-access-controlcve-2026-14446cybersecuritydefense-industrial-basedfar-252-204-7012ibmincident-response
2026-07-27 NVD CVE
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH...
2026-07-27 NVD CVE
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes...
apacheapache-thriftc-glibcertificate-validationcve-2026-48144cybersecurityhost-mismatchinformation-security
2026-07-27 NVD CVE
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
apache-thriftbuffer-overflowccve-2026-55971cyber-securitydfar-252-204-7012heap-based-buffer-overflowincident-response
2026-07-27 NVD CVE
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
access-controlauthentication-weaknessescompliance-riskcve-2026-66014internal-requests-processingjfrog-artifactorynvd-cveprivileges-escalation
2026-07-27 NVD CVE
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
apache-thriftbound-readc-glib-bindingscve-2026-58023cybersecuritydfar-252-204-7012incident-responsenist-800-171
2026-07-27 NVD CVE
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version...
apache-thriftbound-readccve-2026-58662cyber-securitydefense-industrial-basedod-supply-chainimproper-input-validation
2026-07-25 NVD CVE
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This...
accesses-auth-codeadministrators-takeoveradmins-role-enforcementapi-tokenarbitrary-files-writingconf-conf-jsoncontext-isolationcookie-keys-plaintext
2026-07-24 NVD CVE
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
azure-app-serviceazure-security-vulnerabilityimproper-access-controlnetworks-attacksnvd-cveunauthorized-privileges-escalation
2026-07-24 NVD CVE
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
azure-dnscve-2026-58275missing-authorizationnetworks-compromisenvd-cveprivileges-elevationunauthorized-attacks
2026-07-24 NVD CVE
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
azure-keys-vaultcybersecurityimproper-authenticationnetworks-attacksnvd-cveprivileges-escalationunauthorized-accessvulnerability
2026-07-24 NVD CVE
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
authorize-attackersazure-red-hat-openshiftimproper-authorizationnetworknvd-cveprivileges-elevationvulnerability
2026-07-24 NVD CVE
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
buffer-overflowcve-2026-56165malware-attacksmicrosoft-accountsnetwork-executionnvd-cveunauthorized-access
2026-07-24 NVD CVE
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
authorize-attackersexecutable-codeimproper-input-validationmicrosoft-surfacenetworknvd-cvevulnerability
2026-07-24 NVD CVE
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
cve-2026-56191improper-authenticationmicrosoft-exchange-onlinenetworks-tamperingnvd-cveunauthorized-access
2026-07-24 NVD CVE
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
authorize-attackerscode-executioncve-2026-50517deserializationm365-copilotnetworknvd-cveuntrusted-data
2026-07-24 NVD CVE
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
azure-portalscve-2026-62835improper-authorizationinformation-disclosurenetworknvd-cveunauthorized-access
◀ PREV PAGE 13 / 46 NEXT ▶