Skip to content
COOEY
LIVE FEED
1516 events · 13 sources · newest first
2026-08-24 NVD CVE
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper...
attackcve-2026-78167efmhttpcon-check-session-urlimproper-authenticationiptimenvd-cvepublic-exploit
2026-08-24 NVD CVE
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command...
nvd-cve
2026-08-24 NVD CVE
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper...
cve-2026-78168efmhttpcon-check-session-urlimproper-authenticationiptimenvd-cveremote-attackssecurities-disclosures
2026-08-24 NVD CVE
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is...
api-tokenapp-codeapp-idauthentication-bypasscaches-keyingcve-2026-67602databases-rows-identifiersinsecure-cache
2026-08-24 NVD CVE
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed...
cell-notecve-2026-78207deepmergeexcelj-hardenedexcelj-vulnerabilityjson-parsingmalicious-codenvd-cve
2026-08-24 NVD CVE
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter,...
4mosan4mosan-security-technologyadodbarbitrary-command-executioncve-2026-78211gcbs-doctormalicious-command-injectionnvd-cve
2026-08-24 NVD CVE
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded...
base64-decoderbin-netis-cgiboa-web-servercgicve-2026-76070firmwarelogin-handlernc63
2026-08-23 NVD CVE
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The...
cross-site-scriptingcve-2026-7808dom-manipulationsforeign-contents-bypasshtml-sanitizationjusthtmlmathml-injectionsnamespaces-mislabeling
2026-08-23 NVD CVE
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom...
active-htmlcustoms-sanitizationcve-2026-5388encoded-urlshtml-commenthtml-serializationjavascript-injectionjusthtml
2026-08-23 NVD CVE
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set...
code-executioncross-site-scriptingcve-2026-8445html-escapinginput-validationjusthtmlmarkdownnvd-cve
2026-08-23 NVD CVE
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation...
cf-n1-scgi-bincomfastcve-2026-78050ntp-timezonenvd-cveremote-exploitsecurity-bulletin
2026-08-22 NVD CVE
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission...
code-executioncve-2026-4703deserializationfile-deletionnvd-cvephp-object-injectionsecurity-bulletinsensitive-data-exposure
2026-08-22 NVD CVE
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler....
apply-timecgibuffer-overflowcgi-bincve-2026-77946exploitnetwork-trafficntpnvd-cve
2026-08-22 NVD CVE
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the...
administrator-accounts-takeoverapi-keycve-2026-78003email-forwardinginput-validationmailgunnvd-cvepassword-reset
2026-08-21 NVD CVE
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr...
argumentcf-n1-scgi-bincomfastcommand-injectioncve-2026-77683exploitfile-system
2026-08-21 NVD CVE
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and...
allowlistauthenticationauthorizationcve-2026-77776datum-planedocker-composesheaders-injectionidentity-management
2026-08-21 NVD CVE
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers...
arbitrary-file-writeauthenticate-administratorauthenticates-accessesbazaarcode-executioncve-2026-77086directories-deletiondirectories-traversal
2026-08-20 NVD CVE
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-69836deserializationentra-ididentity-managementmicrosoftmicrosofts-entrasnetworks-attacks
2026-08-20 NVD CVE
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
attackerazure-arcscve-2026-69555elevate-privilegeincorrect-authorizationmicrosoftnetwork-securitynvd-cve
2026-08-20 NVD CVE
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
attackerauthorized-accessazureazure-active-directorycloud-securitycve-2026-69851identity-managementmicrosoft
2026-08-20 NVD CVE
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
attackerauthorize-attackersazure-sql-databasecve-2026-68789database-securityelevate-privilegeimproper-neutralizationnetwork
2026-08-20 NVD CVE
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
authorize-attackersazureazure-sql-databasecve-2026-68782database-securitymicrosoftnetwork-securityneutralization
2026-08-20 NVD CVE
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
attackerazureazure-logic-appscve-2026-69400improper-limitationnetwork-securitynvd-cvepath-traversal
2026-08-20 NVD CVE
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next()...
access-controlaccounts-takeoverapi-securityauthentication-bypasscustomer-datacve-2026-72843evershopmiddleware
2026-08-20 NVD CVE
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
cve-2026-65801exchange-onlinemicrosoftmicrosoft-exchange-onlinenetwork-securitynvd-cveprivileges-escalationservers-sides-requests-forgery
2026-08-20 NVD CVE
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
azureazure-arcscve-2026-65816incident-responsemicrosoftnetwork-securitynvd-cveprivileges-escalation
2026-08-20 NVD CVE
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
authorize-attackerscve-2026-63509elevate-privilegefabricmicrosoftnetwork-securitynvd-cveprivileges-escalation
2026-08-20 NVD CVE
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
azure-data-factorycloud-securitycryptographic-signaturescve-2026-62834improper-verificationmicrosoftnetwork-securitynvd-cve
2026-08-20 NVD CVE
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
apache-cassandraargument-injectionazureazure-managed-instancecisacmmccode-executioncve-2026-65770
2026-08-20 NVD CVE
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
access-controlauthorize-attackersazureazure-sql-databasecisacloud-securitycve-2026-66309database-security
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
aixarbitrary-code-executioncve-2026-17157ibmnvd-cvepowervmremote-attackerssecurity-bulletin
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17141ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
aixcve-2026-17136format-string-vulnerabilityibmibm-aixibm-powervmnvd-cvepowervm
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.
aixarbitrary-code-executioncommand-executioncve-2026-17142ibmimproper-authenticationnvd-cvepowervm
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
aixarbitrary-code-executioncve-2026-17160ibminteger-overflownvd-cvepowervmremote-attackers
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17040ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
aixarbitrary-code-executioncve-2026-17145ibmnvd-cvepowervmprivileges-managementremote-code-execution
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17152ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20 NVD CVE
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The...
cluster-compromisecluster-securitycustom-resourcecve-2026-67567helm-charthelmreleasemulticloud-operators-subscriptionnvd-cve
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
aixarbitrary-code-executioncve-2026-17118freeibmnvd-cvepowervmremote-attackers
◀ PREV PAGE 02 / 38 NEXT ▶