Skip to content
COOEY
LIVE FEED
4291 events · 13 sources · newest first
2026-08-07 NVD CVE
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that...
authorization-bypassnvd-cvepasswords-manipulationsunauthenticated-attacksuser-accountvulnerabilitywordpress-plugin
2026-08-07 NVD CVE
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the...
accounts-takeovernvd-cvepassword-reset-validationtruebookerunauthenticated-attacksvulnerabilitywordpress-plugin
2026-08-07 NVD CVE
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
microsoftnetworks-spoofingnvd-cveoffice-sharepointssrfvulnerability
2026-08-07 CISA KEV
Progress LoadMaster Command Injection Vulnerability HIGH ◈ 2 sources · orig. NVD CVE
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
appliance-executioncisa-kevcommand-injectionprogress-loadmastersprogress-loadmasters-vulnerabilitiesunauthenticated-attacksunsanitized-inputs
2026-08-07 NVD CVE
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
authenticationcve-2026-63508microsoftnetworks-attacksnvd-cveplanetary-computer-proprivileges-escalationunauthorized-access
2026-08-07 NVD CVE
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
azure-service-busdeserializationexecution-codenetworknvd-cveuntrusted-datavulnerability
2026-08-07 NVD CVE
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
authentication-breachazure-confidential-ledgersincident-responsenist-800-171nvd-cveransomwarevulnerability
2026-08-07 NVD CVE
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
authorized-accessazure-sres-agentsmissing-authorizationnetworks-attacksnvd-cveprivileges-elevation
2026-08-07 CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycommand-injectioncve-2026-8037cverecordcyber-attacksfederal-agencies
2026-08-06 NVD CVE
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this...
active-session-credentialsadministratorauthenticate-usercritical-vulnerabilitycve-2026-54489dell-virtual-storage-integratorimpersonationinformation-disclosure
2026-08-06 NVD CVE
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and...
attack-pathclasspath-shadowscve-2026-70558dinkyfile-transferjvm-startsnvd-cvepath-validation
2026-08-06 NVD CVE
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by...
assistants-metadataauthenticate-attackscve-2026-67622files-uploadinsecure-direct-object-referencenvd-cveopenai-assistantvulnerability
2026-08-06 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-218-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
9akk108472a9037abbability-zenonsbound-writechemicalcisa-advisorycommunicationcritical-infrastructure
2026-08-06 NVD CVE
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated...
arbitrary-data-injectionattackers-controlled-serverscve-2026-53984database-backupdatabase-destructiondisabled-authenticationexec-driver-sqlfull-restore-command
2026-08-06 NVD CVE
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of...
collectorconfidentialitycve-2026-64993delldell-rvtoolimproper-certificate-validationintegrityloss
2026-08-06 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-218-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
addresses-spaces-layout-randomizationaslrboundcisacisa-advisorycontrol-flow-guardcritical-infrastructurecve-2026-17264
2026-08-06 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-218-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
cisacisa-advisorycommercial-facilitycritical-infrastructurecritical-manufacturingcryptographic-algorithmscve-2026-27871cybersecurity
2026-08-06 NIST
<p>This NIST Cybersecurity White Paper describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections...
4g-to-5g-securities5g-cybersecurities5g-network-security5g-privacy-capabilities5g-standardcybersecurity-testbedsinitial-na-message-securitymen
DCSA
cmmccontracts-managementcybersecuritydcsadefense-acquisitionsdefense-industrial-basedissadod
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software...
catalyst-sd-wanciscocve-2026-20304cwe-284improper-access-controlnvd-cvesecurity-reviewsoftwares-hardening
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20303cwes-20input-validationnvd-cvesoftwares-hardeningvulnerability
2026-08-05 CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycve-2026-63077cybersecuritydeserialization-vulnerabilitiesfederal-agenciesfederal-enterprises
2026-08-05 NVD CVE
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
applications-gateways-operatorscustom-resourcecve-2026-17617ibmnvd-cvesecurityservers-sides-requests-forgeryssrf
2026-08-05 NVD CVE
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server...
application-serverarbitrary-code-executionclass-loadingcve-2026-8400ibmibm-sdkiiopjava
2026-08-05 NVD CVE
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under...
api-keyauthentication-tokencve-2026-8470deterministic-rngencryption-keysfernet-encryptionsibm-langflownvd-cve
2026-08-05 NVD CVE
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH...
authenticate-userboringproxycleartext-credentiallow-privilegednewline-injectionnvd-cvepersistent-shell-accessssh-authorized-key
2026-08-05 NVD CVE
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
cryptographiccve-2026-9205ibmkey-derivationlangflownvd-cvevulnerabilityweak-key
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20267cwes-pillar-cwe-284improper-access-controlnvd-cveproduct-qualitysecurity-reviewsoftwares-hardening
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20272cwes-74nvd-cvesoftwares-hardeningvulnerability
2026-08-05 NVD CVE
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event...
authenticationcve-2026-10025event-processingibminjectioninterim-fixesnvd-cveport-514
2026-08-05 NVD CVE
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the...
attachment-idcsrfcve-2026-5581cybersecuritydata-lossesgravity-formjavascriptmedia-deletion
2026-08-05 NVD CVE
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator....
access-controlcluster-controlclustercuratorcybersecuritydefense-industrial-baseinformation-securitykubernetemulticluster-engine
2026-08-05 NVD CVE
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM...
advanced-cluster-managementapplication-subscription-controllercluster-adminscluster-role-bindingcve-2026-10090helmkubernetenamespaces-scoped-privilege
2026-08-05 NVD CVE
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package...
c2cleartext-communicationscommands-and-controlcve-2026-66747endlessdoorfirmwareimplantnvd-cve
2026-08-05 NVD CVE
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is...
ajaxauthenticationauthorizationcve-2026-4431cybersecuritydata-integritydata-modificationnvd-cve
2026-08-05 NVD CVE
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0....
accounts-takeovercve-2026-9273cybersecurityemails-spoofinginformation-securitykadence-membershipnoncenvd-cve
2026-08-05 CISA KEV
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
agents-pollingcisa-kevdeserializationjetbrainremote-code-executionteamcityuntrusted-datavulnerability
2026-08-05 NVD CVE
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage...
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software...
catalyst-sd-wanciscocve-2026-20310cwes-59files-accesslink-resolutionnvd-cvesecurity-review
2026-08-05 NVD CVE
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata...
authenticationcve-2026-16443forgeryidentity-brokeridentity-providerkeycloakmetadata-importnvd-cve
◀ PREV PAGE 18 / 108 NEXT ▶