Skip to content
COOEY
LIVE FEED
228 events · 13 sources · newest first
2026-07-30 NVD CVE
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
arbitrary-commandscrlf-character-neutralizationscve-2026-14522ibm-apps-connect-enterprisenvd-cveremote-attacksvulnerability
2026-07-29 NVD CVE
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such...
cache-controlcaches-interceptorscve-2026-13697errors-handlinghttps-headersinformation-disclosuremalformed-headersnvd-cve
2026-07-29 NVD CVE
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apacheapache-traffic-serverscache-corruptioncve-2026-58163data-integritydata-lossesincident-responsenvd-cve
2026-07-29 NVD CVE
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade...
apache-traffic-serversbound-writecmmccritical-patchescve-2026-58177defense-industrial-basefedrampfree
2026-07-29 NVD CVE
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apache-traffic-serverscve-2026-58179cve-disclosuresinteger-overflownvd-cveregex-remap-pluginssecurity-patchsoftware
2026-07-28 NVD CVE
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
applications-securityauthentication-bypasscve-2026-16184cybersecuritydata-protectiondefense-industrial-baseibmnist-800-171
2026-07-28 NVD CVE
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
2026-07-28 NVD CVE
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
2026-07-27 NVD CVE
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH...
2026-07-27 NVD CVE
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
access-controlauthentication-weaknessescompliance-riskcve-2026-66014internal-requests-processingjfrog-artifactorynvd-cveprivileges-escalation
2026-07-23 NVD CVE
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
2026-07-23 NVD CVE
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
arbitrary-code-injectioncode-injectioncve-2026-64815cybersecuritydevelopers-toolsform-fileintellij-ideajetbrain
2026-07-23 NVD CVE
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd-cve
2026-07-23 NVD CVE
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
cisacmmc-level-2compliancecve-2026-15967defense-industrial-basedodfedramp-authorizationincident-response
2026-07-23 NVD CVE
Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
authentication-bypasscisacmmc-level-2cve-2026-10697datum-exfiltrationdodfedramp-authorizationimproper-authentication
2026-07-21 NVD CVE
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the...
2026-07-20 NVD CVE
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
2026-07-20 NVD CVE
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to...
2026-07-20 NVD CVE
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send...
2026-07-18 NVD CVE
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
2026-07-18 NVD CVE
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source...
2026-07-17 NVD CVE
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker...
2026-07-17 NVD CVE
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems...
agent-componentapi-v1code-act-agentcsv-agentcve-2026-13448denialflow-idibm
2026-07-15 NVD CVE
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute...
admins-usersapi-endpointarbitrary-code-executionattackers-controlled-websitesauthenticate-requestscross-origin-resources-sharingcross-site-requestcve-2026-56400
2026-07-15 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-15 NVD CVE
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header,...
accounts-takeoverauthentication-token-theftcontent-typescross-site-scriptingcve-2026-56398datum-urifile-extensioninline-disposition
2026-07-15 NVD CVE
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-14 NVD CVE
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47988exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14 NVD CVE
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14 NVD CVE
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri,...
2026-07-14 NVD CVE
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14 NVD CVE
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14 NVD CVE
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-14 NVD CVE
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
◀ PREV PAGE 02 / 06 NEXT ▶