LIVE FEED
1853 events · 13 sources · newest first
Events in view
1853
all sources
Critical
1853
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-14
NVD CVE
CVE-2026-45069: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and...
audience-checkauthenticationclaim-verificationcve-2026-45069expiry-checksissuer-checksjwtnvd-cve
2026-07-14
NVD CVE
CVE-2026-48334: Illustrator is affected by an Improper Input Validation vulnerability that could
CRITICAL
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
adobearbitrary-code-executioncve-2026-48334illustratorimproper-input-validationmalicious-filesnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48327: ColdFusion is affected by an Incorrect Authorization vulnerability that could re
CRITICAL
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope...
arbitrary-code-executioncoldfusioncve-2026-48327exploitincorrect-authorizationnvd-cvesecurityvulnerability
2026-07-14
NVD CVE
CVE-2026-48325: ColdFusion is affected by a Missing Authentication for Critical Function vulnera
CRITICAL
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
arbitrary-code-executioncoldfusioncritical-functionscve-2026-48325exploitmissing-authenticationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48324: ColdFusion is affected by an Improper Neutralization of Special Elements used in
CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncoldfusioncve-2026-48324exploitationimproper-neutralizationnvd-cvescope-changesspecial-elements
2026-07-14
NVD CVE
CVE-2026-48322: ColdFusion is affected by an Improper Control of Generation of Code ('Code Injec
CRITICAL
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does...
arbitrary-code-executioncode-injectioncoldfusioncve-2026-48322exploitnvd-cvescope-changessecurity
2026-07-14
NVD CVE
CVE-2026-48321: ColdFusion is affected by an Incorrect Authorization vulnerability that could re
CRITICAL
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of...
coldfusioncve-2026-48321exploitincorrect-authorizationnvd-cveprivileges-escalationsecurityunauthorized-access
2026-07-14
NVD CVE
CVE-2026-48319: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CRITICAL
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescve-2026-48319directories-traversalexploitnvd-cve
2026-07-14
NVD CVE
CVE-2026-48318: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CRITICAL
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to...
access-controlarbitrary-file-readscoldfusioncve-2026-48318directories-traversalexploitfile-system-readnvd-cve
2026-07-14
NVD CVE
CVE-2026-48284: ColdFusion is affected by an Improper Input Validation vulnerability that could
CRITICAL
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....
arbitrary-code-executioncoldfusioncve-2026-48284exploitimproper-input-validationinput-validationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48359: Adobe Experience Manager is affected by an Improper Restriction of XML External
CRITICAL
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A...
adobe-experience-managersarbitrary-code-executioncve-2026-48359elevated-accessno-user-interaction-requiresnvd-cvesensitive-file-readingsession-control
2026-07-14
NVD CVE
CVE-2026-48358: Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnera
CRITICAL
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
adobe-commercearbitrary-code-executioncode-executioncve-2026-48358improper-encodingimproper-escapingnvd-cvesecurities-risks
2026-07-14
NVD CVE
CVE-2026-48356: Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type
CRITICAL
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this...
adobe-commercearbitrary-code-executioncve-2026-48356elevated-accessmalicious-scriptsnvd-cvesession-controlunrestricted-uploads
2026-07-14
NVD CVE
CVE-2026-48259: Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vul
CRITICAL
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage...
adobe-experience-managersarbitrary-code-executioncve-2026-48259elevated-accessno-user-interaction-requiresnvd-cveservers-sides-requests-forgerysession-control
2026-07-14
NVD CVE
CVE-2026-56190: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to
CRITICAL
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
code-executioncode-execution-vulnerabilitycve-2026-56190networks-attacksnetworks-vulnerabilitiesnvd-cverdpremote-desktop-protocol
2026-07-14
NVD CVE
CVE-2026-50518: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke
CRITICAL
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50518dhcp-serverheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14
NVD CVE
CVE-2026-50380: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to ex
CRITICAL
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50380exploitgdiheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14
NVD CVE
CVE-2026-47767: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on...
applications-securitycode-executioncve-2024-50340cve-2026-47767debug-modeenvironment-variablesnvd-cvephp
2026-07-14
NVD CVE
CVE-2026-58644: Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
attack-vectorscode-executioncve-2026-58644datum-exfiltrationdeserializationexploitmicrosoftmicrosoft-office
2026-07-14
NVD CVE
CVE-2026-55008: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
attackercross-site-scriptingcve-2026-55008exchange-serverinputs-neutralizationmicrosoftnetwork-securitynvd-cve
2026-07-14
NVD CVE
CVE-2026-54990: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac
CRITICAL
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-54990exploitheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14
NVD CVE
CVE-2026-50522: Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint
2026-07-14
NVD CVE
CVE-2026-49798: Use after free in Windows Kernel allows an unauthorized attacker to elevate priv
CRITICAL
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
cve-2026-49798freekernel-exploitlocal-attacknvd-cveprivileges-escalationsecurity-bulletinunauthorized-access
2026-07-14
NVD CVE
CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacke
CRITICAL
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14
NVD CVE
CVE-2026-48561: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14
NVD CVE
CVE-2026-45063: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from...
attackerauthenticationcertificatecve-2026-45063distinguished-namesemail-addressfixnvd-cve
2026-07-14
NVD CVE
CVE-2026-48807: Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() c
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
2026-07-14
NVD CVE
CVE-2026-46633: Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does no
CRITICAL
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted...
2026-07-14
NVD CVE
CVE-2026-48805: Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappe
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(),...
2026-07-14
NVD CVE
CVE-2026-48806: Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not g
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key...
2026-07-14
NVD CVE
CVE-2026-54118: Deserialization of untrusted data in SQL Server allows an unauthorized attacker
CRITICAL
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-42990: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized atta
CRITICAL
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-42990heap-based-buffer-overflowmicrosoftnetworks-attacksnvd-cveodbc-driver
2026-07-14
NVD CVE
CVE-2026-15701: A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affect
CRITICAL
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument...
buffer-overflowcooeys-clubcve-2026-15701form-logoutformlogouthtmlighttpdnetworks-devicesnvd-cve
2026-07-14
NVD CVE
CVE-2026-62392: Improper Neutralization of Special Elements used in an OS Command ('OS Command I
CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.
This issue affects Apache...
apache-softwaresapaches-kylinapi-vulnerabilitiescommand-injectioncve-2026-62392cybersecuritydata-breaches-preventionincident-response
2026-07-14
NVD CVE
CVE-2026-62390: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.
This issue...
apaches-kylinapicisacmmccve-2026-62390databasedodnist-800-171
2026-07-14
NVD CVE
CVE-2026-58319: Certain Apache Doris FE HTTP REST administrative APIs were accessible without pr
CRITICAL
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative...
administratives-apisapaches-dori-3-1-0apaches-dorisauthenticationcluster-availabilitycluster-integritycve-2026-58319denial
2026-07-13
NVD CVE
CVE-2026-40469: Integer overflow vulnerability has been found in "builtin.c" program file of gaw
CRITICAL
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It...
32-bit-buildcrashes-vulnerabilitiescve-2026-40469do-subgawkheap-overflowinteger-overflownvd-cve
2026-07-13
NVD CVE
CVE-2026-40468: Integer overflow vulnerability has been found in "builtin.c" program file of gaw
CRITICAL
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and...
cisacmmc-level-2cve-2026-40468dodfedramp-authorizationgawkheap-metadatainteger-overflow
2026-07-13
NVD CVE
CVE-2026-62327: 9Router through version 0.4.41 contain an unauthenticated information disclosure
CRITICAL
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single...
9routerai-provider-accountapi-key-exposurebilling-fraudcompliance-riskcve-2026-62327information-leakagemissing-authentication-middleware
2026-07-13
NVD CVE
CVE-2026-59801: 9Router through version 0.4.41 contains an unauthenticated access vulnerability
CRITICAL
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to...
9routerapi-endpointapi-keyauthentication-middlewarecompliance-riskcredentials-exposurecve-2026-59801denial