LIVE FEED
1853 events · 13 sources · newest first
Events in view
1853
all sources
Critical
1853
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-20
NVD CVE
CVE-2026-64625: AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync
CRITICAL
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary...
avideocommand-injectioncve-2026-45578cve-2026-64625cybersecuritydefense-industrial-basedfar-252-204-7012escapeshellarg
2026-07-20
NVD CVE
CVE-2026-12701: A path traversal vulnerability was found in pulpcore. The relative_path_validato
CRITICAL
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../"...
administrator-privilegesartifacts-handlingcybersecuritydata-exposurefile-integrityfile-writefilesystem-exportincident-response
2026-07-20
NVD CVE
CVE-2026-16242: A flaw was found in the Konnectivity proxy-server configuration for hosted contr
CRITICAL
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client...
agent-authenticationclient-certificate-validationconfiguration-errorcontrol-plane-trafficdata-droppingdata-modificationdefense-industrial-basekonnectivity
2026-07-20
NVD CVE
CVE-2026-64620: FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow
CRITICAL
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output...
authenticationbuffer-overflowcrypto-rsa-commonscve-2026-64620cybersecuritydefense-industrial-basedenialfreerdp
2026-07-17
NVD CVE
CVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with...
arbitrary-code-executionauthenticate-usercve-2026-8635databases-manipulationibmlangflownvd-cveopen-source-software
2026-07-17
NVD CVE
CVE-2026-8859: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability...
api-requestsarbitrary-file-writecontents-dispositioncve-2026-8859ibmincident-responseinput-validationlangflow
2026-07-17
NVD CVE
CVE-2026-13446: IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or...
authenticationcve-2026-13446data-encryptionencryptionhard-coded-credentialsibminbound-authenticationinternal-data
2026-07-17
NVD CVE
CVE-2026-8297: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management...
applications-securitycode-injectioncve-2026-8297data-breaches-risksdatabase-securitygi-laboratory-management-systemsgis-informatics-engineering-consulting-laboratoryimproper-neutralization
2026-07-17
NVD CVE
CVE-2026-9103: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unau
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer...
administrative-accessauthenticationbearer-tokencorcross-origin-resources-sharingcve-2026-9103ibmimproper-authentication
2026-07-17
NVD CVE
CVE-2026-9135: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 9498
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that...
agentic-mcpsauthenticate-users-attackscode-injectioncross-tenant-attackcve-2026-9135dynamic-code-validationflow-manipulationibm-langflow
2026-07-17
NVD CVE
CVE-2026-12692: Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platf
CRITICAL
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.
This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
authentication-bypasscve-2026-12692enterprise-video-platformnvd-cvepassword-changeunverified-password-changevimesoftvulnerability
2026-07-17
NVD CVE
CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain
CRITICAL
◈ 2 sources · orig. NVD CVE
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve...
api-vulnerabilitiescode-executioncve-2026-9198default-deploymentibmlangflownvd-cveopen-source
2026-07-17
NVD CVE
CVE-2026-14956: The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in al
CRITICAL
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration...
administrator-accountbricksforgecve-2026-14956nvd-cveplugins-vulnerabilitiesprivileges-escalationsecurity-bulletinunauthenticated-attacks
2026-07-17
NVD CVE
CVE-2026-62241: clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT
CRITICAL
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan...
apiattackauthenticationclawvetcve-2026-62241datum-exfiltrationhard-codedjwt
2026-07-17
NVD CVE
CVE-2026-12693: Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc.
CRITICAL
Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Enterprise Video...
access-control-listaclauthorization-bypasscve-2026-12693enterprise-video-platformnvd-cvesecurity-bugsoftware-vulnerabilities
2026-07-17
NVD CVE
CVE-2026-15091: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to
CRITICAL
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
arbitrary-script-executioncve-2026-15091ibmibm-engineering-ai-hub-1-0-0ibm-engineering-ai-hub-1-1-0ibm-engineering-ai-hub-1-2-0ibm-engineering-ai-hubsimproper-inputs-neutralization
2026-07-17
NVD CVE
CVE-2026-12694: Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform a
CRITICAL
Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
access-controlaclcve-2026-12694enterprise-video-platformmissing-authorizationnvd-cvesecurityvimesoft
2026-07-17
NVD CVE
CVE-2026-8476: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize...
api-manipulationasyncdiskcachecustom-componentscve-2026-8476deserializationfile-system-accessibmlangflow
2026-07-17
NVD CVE
CVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes...
api-endpointauthenticate-usercode-validationcve-2026-8481exec-functionibminput-validationlangflow
2026-07-17
NVD CVE
CVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key...
api-keyauthenticationbypassconfigurationcve-2026-8505default-settingsibmlangflow
2026-07-16
NVD CVE
CVE-2026-54526: Argo Workflows is an open source container-native workflow engine for orchestrat
CRITICAL
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because...
2026-07-16
NVD CVE
CVE-2026-44182: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distr
CRITICAL
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates untrusted...
2026-07-16
NVD CVE
CVE-2026-44181: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distr
CRITICAL
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment...
2026-07-16
NVD CVE
CVE-2026-63089: WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographic
CRITICAL
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer...
brute-forcecredentials-theftcryptographic-weaknessescve-2026-63089impersonationnvd-cveone-time-linkpreshared-key
2026-07-16
NVD CVE
CVE-2026-63087: Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability
CRITICAL
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using...
admins-usersapi-endpointapi-tokencve-2026-63087grafanagrafana-urlnvd-cveoncall
2026-07-16
NVD CVE
CVE-2026-15013: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen
CRITICAL
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because...
authentication-bypasscve-2026-15013nvd-cvesamlsaml-signatures-algorithms-confusionsingle-signssowordpress
2026-07-16
NVD CVE
CVE-2023-49899: An unauthenticated remote attacker can execute any command on the affected devic
CRITICAL
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
command-executioncommunications-channelscve-2023-49899nvd-cveorigin-verificationremote-attackerssecurityunauthenticate
2026-07-16
NVD CVE
CVE-2023-49900: An unauthenticated remote attacker is able to perform remote code execution due
CRITICAL
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
cve-2023-49900exploitincorrectly-sanitize-inputsnvd-cveremote-attackersremote-code-executionsecurity-bulletinsetparameter-command
2026-07-16
NVD CVE
CVE-2026-45568: zrok is software for sharing web services, files, and network resources. Prior t
CRITICAL
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to...
cve-2026-45568cybersecurityflaskincident-responseinformation-disclosurenetwork-resourcesnvd-cveproxy
2026-07-15
NVD CVE
CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. Fr
CRITICAL
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a...
2026-07-15
NVD CVE
CVE-2026-54052: n8n-MCP is an MCP server that provides AI assistants access to n8n node document
CRITICAL
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's...
ai-assistantauthorization-headercredentials-exposurecve-2026-54052data-breacheshttps-modemcp-servermulti-tenancy
2026-07-15
NVD CVE
CVE-2026-53512: Better Auth is an authentication and authorization library for TypeScript. Prior
CRITICAL
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession...
accesses-tokenauthenticationauthorizationbetters-authsclient-idclients-secretscve-2026-53512mcp-plugins
2026-07-14
NVD CVE
CVE-2026-54118: Deserialization of untrusted data in SQL Server allows an unauthorized attacker
CRITICAL
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-54117: Deserialization of untrusted data in SQL Server allows an unauthorized attacker
CRITICAL
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-56451: A vulnerability has been identified in Opcenter X (All versions < V2604). Affect
CRITICAL
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
This could allow an...
access-controlapplications-securityauthentication-bypasscve-2026-56451cve-trackingsimpersonationjson-web-tokenjwt-forges
2026-07-14
NVD CVE
CVE-2026-44761: SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented
CRITICAL
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an...
apus-exploitationscompliance-riskconfidentiality-impactcredentials-exposurecve-2026-44761data-integrityhelp-portalnvd-cve
2026-07-14
NVD CVE
CVE-2026-44747: SAP NetWeaver Application Server ABAP allows an authenticated attacker to levera
CRITICAL
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system...
abapauthenticate-attackeravailabilitycmmcconfidentialitycve-2026-44747data-accessdefense-industrial-base
2026-07-14
NVD CVE
CVE-2026-27690: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthentica
CRITICAL
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the...
availability-impactconfidentiality-impactcve-2026-27690https-requests-smugglingnvd-cverequests-responses-desynchronizationsap-approutersecurity-vulnerability
2026-07-14
NVD CVE
CVE-2026-48334: Illustrator is affected by an Improper Input Validation vulnerability that could
CRITICAL
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
adobearbitrary-code-executioncve-2026-48334illustratorimproper-input-validationmalicious-filesnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48327: ColdFusion is affected by an Incorrect Authorization vulnerability that could re
CRITICAL
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope...
arbitrary-code-executioncoldfusioncve-2026-48327exploitincorrect-authorizationnvd-cvesecurityvulnerability