LIVE FEED
1803 events · 13 sources · newest first
Events in view
1803
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-23
NVD CVE
CVE-2026-15981: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen
CRITICAL
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose...
authentication-bypasscve-2026-15981nvd-cveopenssl-verifysaml-ssovulnerabilitywordpress-plugin
2026-07-23
NVD CVE
CVE-2024-58354: cal.com (calcom repository, later renamed cal.diy) is affected by a repository t
CRITICAL
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's...
arbitrary-commandscalcomcheck-typesymldangerous-git-checkoutgithub-actionsgithub-tokennvd-cvepull-request
2026-07-23
NVD CVE
CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in
HIGH
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd-cve
2026-07-23
NVD CVE
CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This
HIGH
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
cisacmmc-level-2compliancecve-2026-15967defense-industrial-basedodfedramp-authorizationincident-response
2026-07-23
NVD CVE
CVE-2026-64815: In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible v
HIGH
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
arbitrary-code-injectioncode-injectioncve-2026-64815cybersecuritydevelopers-toolsform-fileintellij-ideajetbrain
2026-07-23
NVD CVE
CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue a
HIGH
Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
authentication-bypasscisacmmc-level-2cve-2026-10697datum-exfiltrationdodfedramp-authorizationimproper-authentication
2026-07-23
NVD CVE
CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s
HIGH
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
2026-07-23
NVD CVE
CVE-2026-15011: The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable
CRITICAL
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on...
code-injectioncve-2026-15011nvd-cvesensitive-information-exposuresite-functionalityunauthenticated-attacksvulnerabilitywordpress-plugin
2026-07-23
NVD CVE
CVE-2026-65689: Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepa
CRITICAL
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the...
cve-2026-65689file-readingnvd-cvepath-traversalserver-filesystemunauthenticated-accessesvulnerability
2026-07-23
NVD CVE
CVE-2026-15015: The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable t
CRITICAL
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is...
administrator-equivalent-accessauthorization-bypasscve-2026-15015nvd-cveoauth-bearer-tokenunauthenticated-accessesvulnerabilitywordpress-content
2026-07-23
NVD CVE
CVE-2026-14282: The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folde
CRITICAL
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This...
arbitrary-files-uploadcve-2026-14282nvd-cveremote-code-executionunauthenticated-attacksvulnerabilitywordpresswpform
2026-07-23
NVD CVE
CVE-2025-71389: Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote co
CRITICAL
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes...
attack-controlled-inputcalcomcve-2025-55182cve-2025-71389dependencynextjnvd-cverce
2026-07-23
NVD CVE
CVE-2026-44210: Kata Containers is an open source project focusing on a standard implementation
CRITICAL
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that...
2026-07-23
NVD CVE
CVE-2026-65700: h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compa
CRITICAL
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process...
021cve-2026-65700file-apih2ogptnvd-cveopenai-compatiblepath-traversalremote-code-execution
2026-07-23
NVD CVE
CVE-2026-63732: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcode
CRITICAL
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host...
9routercode-executiondefault-passwordhost-operating-systemsmalicious-pluginsnetworks-gatesnvd-cvespoofing
2026-07-22
NVD CVE
CVE-2026-60366: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily...
basis-score-100centralizes-thirdparty-jarconfidentiality-integrity-availabilitycve-2026-60366cvss-31httpimpactjava
2026-07-22
NVD CVE
CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login pro
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...
administrative-privilegescheck-pointcisa-kevcve-2026-16232improper-authentication-vulnerabilityremote-attacks
2026-07-22
NVD CVE
CVE-2026-60372: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily...
availabilitybasis-score-98centralizes-thirdparty-jarconfidentialitycvss-31httpimpactintegrity
2026-07-22
NVD CVE
CVE-2026-50252: In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is rand
CRITICAL
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies...
cve-2026-50252dns-caches-poisoning-attacksdns-caches-poisoningsdns-transactionentropyload-balancing-policiesmalicious-actorsnvd-cve
2026-07-22
NVD CVE
CVE-2026-60367: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily...
ac-lbasis-score-98c-hcentralizes-thirdparty-jarconfidentiality-integrity-availabilitycvas-ncvss-31h
2026-07-22
NVD CVE
CVE-2026-2395: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection.
This issue affects No Code...
cyber-attackscyber-securitydata-breachesimproper-neutralizationinformation-securityno-code-platformnvd-cvesecurities-risks
2026-07-22
NVD CVE
CVE-2026-60369: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily...
availabilitybasis-score-99centralizes-thirdparty-jarconfidentialitycve-2026-60369cvss-31httpimpact
2026-07-22
NVD CVE
CVE-2026-65590: n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restri
CRITICAL
n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool...
computer-use-packagecve-2026-65590cybersecurityfilesystem-accessesincident-responselinuxmacon8n
2026-07-21
NVD CVE
CVE-2026-13439: The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unaut
CRITICAL
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow...
administrators-accesscve-2026-13439cybersecuritydata-exposureeasy-form-buildernonce-refreshesnvd-cvepassword-reset
2026-07-21
NVD CVE
CVE-2026-61242: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low...
2026-07-21
NVD CVE
CVE-2026-61245: Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of O
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60358: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (
CRITICAL
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-61244: Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product o
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-61178: Vulnerability in the Oracle Agile Product Lifecycle Management for Process produ
CRITICAL
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-61239: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-61183: Vulnerability in the Oracle Agile Product Lifecycle Management for Process produ
CRITICAL
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-61237: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-62546: Vulnerability in the Oracle Applications Framework product of Oracle E-Business
CRITICAL
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high...
2026-07-21
NVD CVE
CVE-2026-60438: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (com
CRITICAL
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60361: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-61175: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply
CRITICAL
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60380: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-61174: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply
CRITICAL
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-61238: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60773: Vulnerability in the Oracle Application Object Library product of Oracle E-Busin
CRITICAL
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low...