LIVE FEED
1524 events · 13 sources · newest first
Events in view
1524
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-21
NVD CVE
CVE-2016-20096: Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated S
CRITICAL
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST...
authenticationcredentialcves-2016-20096databasedba-privilegeslinknatlogins-endpointsnvd-cve
2026-07-21
NVD CVE
CVE-2026-60552: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-64825: Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that
CRITICAL
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive...
arbitrary-file-writebackup-archivecve-2026-64825cybersecuritydata-integrityfile-writefilesystem-accesseshome-assistant
2026-07-21
NVD CVE
CVE-2026-60220: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
authenticationconfidentialitycritical-datacve-2026-60220cvss-31data-compromisedata-deletiondata-integrity
2026-07-21
NVD CVE
CVE-2026-60562: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60224: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60224cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-28321: SolarWinds Serv-U is affected by a broken access control vulnerability that coul
CRITICAL
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator...
arbitrary-file-readsarbitrary-file-writebroken-access-controlcode-executioncve-2026-28321cybersecuritydfar-252-204-7012domain-administrator
2026-07-21
NVD CVE
CVE-2026-28317: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
cve-2026-28317cybersecuritydfar-252-204-7012domain-administratoridorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60227: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60227cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-60228: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60228cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-28316: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This...
command-executioncve-2026-28316cybersecuritydfar-252-204-7012idorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60230: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60230cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-28314: SolarWinds Serv-U is affected by an insecure direct object reference vulnerabili
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
accounts-takeovercve-2026-28314cybersecuritydata-compromisedfar-252-204-7012incident-responseinsecure-direct-object-referencenist-800-171
2026-07-21
NVD CVE
CVE-2026-60234: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60234cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-60302: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-28313: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
accounts-takeoverarbitrary-accessescve-2026-28313cybersecuritydata-exposureidorincident-responsenvd-cve
2026-07-21
NVD CVE
CVE-2026-28312: SolarWinds Serv-U is affected by a privilege escalation vulnerability. This woul
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
code-executioncve-2026-28312cybersecuritydefense-industrial-basedfar-252-204-7012incident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60241: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycore-componentcve-2026-60241cvss-31httpintegrity
2026-07-21
NVD CVE
CVE-2026-28310: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
cve-2026-28310cybersecuritydomain-administratornvd-cvepatch-managementprivileges-escalationrisk-managementserv-u
2026-07-21
NVD CVE
CVE-2026-28309: SolarWinds Serv-U is affected by a broken access control vulnerability that allo
CRITICAL
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
broken-access-controlcve-2026-28309cybersecuritydfar-252-204-7012domain-administratorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-28308: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
cve-2026-28308cybersecuritydomain-administratoridorincident-responsenvd-cvepatch-managementremote-code-execution
2026-07-21
NVD CVE
CVE-2026-60247: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycore-componentcve-2026-60247cvss-31httpintegrity
2026-07-21
NVD CVE
CVE-2026-28307: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
administrator-privilegescve-2026-28307cybersecurityincident-responsenetwork-securitynvd-cvepatch-managementprivileges-escalation
2026-07-21
NVD CVE
CVE-2026-60542: Vulnerability in the Oracle Business Process Management Suite product of Oracle
CRITICAL
Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-28306: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
cve-2026-28306cybersecuritydomain-administratornvd-cvepatch-managementprivileges-escalationrisk-managementserv-u
2026-07-21
NVD CVE
CVE-2026-60424: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-28305: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home...
cve-2026-28305cybersecuritydata-exposureidorincident-responsenvd-cvepatch-managementremote-code-execution
2026-07-21
NVD CVE
CVE-2026-28304: SolarWinds Serv-U is affected by a remote code execution vulnerability that, whe
CRITICAL
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
cmmccve-2026-28304cybersecuritydfar-252-204-7012incident-responsenist-800-171nvd-cverce
2026-07-21
NVD CVE
CVE-2026-28302: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vuln
CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The...
cve-2026-28302cybersecuritydfar-252-204-7012groups-administratorsidorincident-responsenist-800-171nvd-cve
2026-07-21
NVD CVE
CVE-2026-60256: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows...
availabilityconfidentialitycore-componentcve-2026-60256cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-60547: Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middl
CRITICAL
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-65008: Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Bl
CRITICAL
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments...
authenticate-accountsblueprint-dynamicdatacalls-user-func-arraycve-2026-65008form-plugingravgrav-blueprintsgrav-common-data
2026-07-21
NVD CVE
CVE-2026-65007: The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize A
CRITICAL
The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL...
access-controlaccounts-managementaccounts-takeoverapi-keyapi-permissionsauthenticationauthorizationcve-2026-65007
2026-07-21
NVD CVE
CVE-2026-60262: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60262cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-8986: Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command
CRITICAL
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that...
2026-07-21
NVD CVE
CVE-2026-60267: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
confidentialitycore-componentcritical-datacvss-31data-accessdata-compromisedata-modificationintegrity
2026-07-21
NVD CVE
CVE-2026-60306: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60272: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilitycompromiseconfidentialitycore-componentcve-2026-60272cvss-31httpintegrity
2026-07-21
NVD CVE
CVE-2026-8985: Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command
CRITICAL
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to...
2026-07-21
NVD CVE
CVE-2026-60564: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...