Skip to content
COOEY
LIVE FEED
4309 events · 13 sources · newest first
2026-08-05 NVD CVE
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata...
authenticationcve-2026-16443forgeryidentity-brokeridentity-providerkeycloakmetadata-importnvd-cve
2026-08-05 NVD CVE
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event...
authenticationcve-2026-10025event-processingibminjectioninterim-fixesnvd-cveport-514
2026-08-05 NVD CVE
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
applications-gateways-operatorscustom-resourcecve-2026-17617ibmnvd-cvesecurityservers-sides-requests-forgeryssrf
2026-08-05 NVD CVE
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a...
access-controlaccounts-linkingauthenticationcve-2026-16442identity-federationidentity-managementkeycloaklogins-restrictions
2026-08-05 NVD CVE
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server...
application-serverarbitrary-code-executionclass-loadingcve-2026-8400ibmibm-sdkiiopjava
2026-08-05 CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycve-2026-63077cybersecuritydeserialization-vulnerabilitiesfederal-agenciesfederal-enterprises
2026-08-05 NVD CVE
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package...
c2cleartext-communicationscommands-and-controlcve-2026-66747endlessdoorfirmwareimplantnvd-cve
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software...
catalyst-sd-wanciscocve-2026-20310cwes-59files-accesslink-resolutionnvd-cvesecurity-review
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20272cwes-74nvd-cvesoftwares-hardeningvulnerability
2026-08-05 NVD CVE
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator....
access-controlcluster-controlclustercuratorcybersecuritydefense-industrial-baseinformation-securitykubernetemulticluster-engine
2026-08-05 NVD CVE
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under...
api-keyauthentication-tokencve-2026-8470deterministic-rngencryption-keysfernet-encryptionsibm-langflownvd-cve
2026-08-05 NVD CVE
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
cryptographiccve-2026-9205ibmkey-derivationlangflownvd-cvevulnerabilityweak-key
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20303cwes-20input-validationnvd-cvesoftwares-hardeningvulnerability
2026-08-05 NVD CVE
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the...
attachment-idcsrfcve-2026-5581cybersecuritydata-lossesgravity-formjavascriptmedia-deletion
2026-08-05 NVD CVE
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0....
accounts-takeovercve-2026-9273cybersecurityemails-spoofinginformation-securitykadence-membershipnoncenvd-cve
2026-08-05 NVD CVE
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is...
ajaxauthenticationauthorizationcve-2026-4431cybersecuritydata-integritydata-modificationnvd-cve
2026-08-05 NVD CVE
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM...
advanced-cluster-managementapplication-subscription-controllercluster-adminscluster-role-bindingcve-2026-10090helmkubernetenamespaces-scoped-privilege
2026-08-05 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software...
catalyst-sd-wanciscocve-2026-20304cwe-284improper-access-controlnvd-cvesecurity-reviewsoftwares-hardening
2026-08-04 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-216-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
acrisurebluetoothcisacisa-advisorycritical-infrastructurecve-2026-18411cwe-321cybersecurity
2026-08-04 CISA advisory
<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
apachebinding-operational-directivesbod-26-04cisacisa-advisorycvecve-2026-18556cve-2026-34486
2026-08-04 CISA KEV
IBM Langflow Code Injection Vulnerability HIGH ◈ 2 sources · orig. NVD CVE
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
api-vulnerabilitiescode-executioncve-2026-9198default-deploymentibmlangflownvd-cveopen-source
2026-08-04 NVD CVE
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON...
binary-protocolcommand-injectiondevices-compromisefirmwareip-camerasjson-payloadnetworks-devicesnvd-cve
2026-08-04 CISA KEV
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
apache-tomcatbypasscisa-kevcve-2026-34486cybersecuritydata-protectiondfar-252-204-7012encrypt-interceptor
2026-08-04 NVD CVE
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
chromiumcve-2026-66321cybersecuritydefense-industrial-basedfar-252-204-7012information-securitymicrosoftmicrosoft-edge
2026-08-04 NVD CVE
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST...
bilin-softwarecryptographic-keyscve-2026-14804cybersecuritydata-encryptiondfar-252-204-7012executablehard-coded-keys
2026-08-04 NVD CVE
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources:...
bilin-softwarecleartext-storagescve-2026-15721data-securityhumanists-digital-human-resourcesinformatics-consultancyinformation-securitynvd-cve
2026-08-04 NVD CVE
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON...
application-privilegescve-2026-69098cybersecuritydata-protectionendpointinsecure-deserializationjsonkotaemon
2026-08-04 CISA KEV
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
alternate-channelalternate-pathsauthentication-bypasscisa-kevcve-2026-18556cybersecurityinformation-securitymanaged-services-providers
2026-08-04 NVD CVE
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and...
admins-gated-endpointajax-dispatcherajax-phpauthentication-bypassbase64-encoded-pathscve-2026-70552dangerous-operationheader
2026-08-04 NVD CVE
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in...
command-injectioncve-2026-18686cybersecuritygl-inetgl-mt3000information-securitynas-websnetworks-devices
2026-08-04 NVD CVE
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects...
bilin-softwarecve-2026-14175cybersecurityfiles-uploadhumanists-digital-human-resourcesincident-responseinformatics-consultancynist-800-171
2026-08-04 NVD CVE
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and...
authenticationauthorization-headercve-2026-10050cybersecuritydata-integrityeclipse-jettyinformation-securityiso-8859-1
2026-08-04 NVD CVE
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install...
cve-2026-70553nvd-cvephpremote-code-executionvulnerability
2026-08-04 NVD CVE
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It...
command-injectioncve-2026-18685cybersecurityfirmware-vulnerabilitiesgl-inetgl-mt3000incident-responsemodem-so
2026-08-04 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-216-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
access-controlapplied-biosystemschaincisa-advisorycritical-infrastructurecustodycve-2026-17583cwe-353
2026-08-04 NVD CVE
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to...
arbitrary-code-executionmaxsite-cmnvd-cvephp-object-injectionunauthenticated-attacksvulnerability
2026-08-03 CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
actives-exploitationsbinding-operational-directivesbod-26-04cisacisa-advisorycve-2026-18577cyber-attackscyber-security
2026-08-03 NVD CVE
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the...
accadobeadobe-campaign-classicapplications-securityarbitrary-code-executioncontrolcve-2026-48330cybersecurity
2026-08-03 NVD CVE
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
adobeadobe-campaign-classiccve-2026-48331cyber-attacksinformation-securitynvd-cveprivileges-escalationsecurities-risks
2026-08-03 NVD CVE
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change...
apache-nifiauthorization-checkscode-executioncomponent-level-authorizationcve-2026-68979nifi-2110nvd-cveparameters-context
◀ PREV PAGE 19 / 108 NEXT ▶