Skip to content
COOEY
LIVE FEED
1853 events · 13 sources · newest first
2026-07-14 NVD CVE
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and...
audience-checkauthenticationclaim-verificationcve-2026-45069expiry-checksissuer-checksjwtnvd-cve
2026-07-14 NVD CVE
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
adobearbitrary-code-executioncve-2026-48334illustratorimproper-input-validationmalicious-filesnvd-cvesecurity
2026-07-14 NVD CVE
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope...
arbitrary-code-executioncoldfusioncve-2026-48327exploitincorrect-authorizationnvd-cvesecurityvulnerability
2026-07-14 NVD CVE
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
arbitrary-code-executioncoldfusioncritical-functionscve-2026-48325exploitmissing-authenticationnvd-cvesecurity
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncoldfusioncve-2026-48324exploitationimproper-neutralizationnvd-cvescope-changesspecial-elements
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does...
arbitrary-code-executioncode-injectioncoldfusioncve-2026-48322exploitnvd-cvescope-changessecurity
2026-07-14 NVD CVE
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of...
coldfusioncve-2026-48321exploitincorrect-authorizationnvd-cveprivileges-escalationsecurityunauthorized-access
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescve-2026-48319directories-traversalexploitnvd-cve
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to...
access-controlarbitrary-file-readscoldfusioncve-2026-48318directories-traversalexploitfile-system-readnvd-cve
2026-07-14 NVD CVE
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....
arbitrary-code-executioncoldfusioncve-2026-48284exploitimproper-input-validationinput-validationnvd-cvesecurity
2026-07-14 NVD CVE
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A...
adobe-experience-managersarbitrary-code-executioncve-2026-48359elevated-accessno-user-interaction-requiresnvd-cvesensitive-file-readingsession-control
2026-07-14 NVD CVE
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
adobe-commercearbitrary-code-executioncode-executioncve-2026-48358improper-encodingimproper-escapingnvd-cvesecurities-risks
2026-07-14 NVD CVE
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this...
adobe-commercearbitrary-code-executioncve-2026-48356elevated-accessmalicious-scriptsnvd-cvesession-controlunrestricted-uploads
2026-07-14 NVD CVE
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage...
adobe-experience-managersarbitrary-code-executioncve-2026-48259elevated-accessno-user-interaction-requiresnvd-cveservers-sides-requests-forgerysession-control
2026-07-14 NVD CVE
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
code-executioncode-execution-vulnerabilitycve-2026-56190networks-attacksnetworks-vulnerabilitiesnvd-cverdpremote-desktop-protocol
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50518dhcp-serverheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50380exploitgdiheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14 NVD CVE
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on...
applications-securitycode-executioncve-2024-50340cve-2026-47767debug-modeenvironment-variablesnvd-cvephp
2026-07-14 NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
attack-vectorscode-executioncve-2026-58644datum-exfiltrationdeserializationexploitmicrosoftmicrosoft-office
2026-07-14 NVD CVE
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
attackercross-site-scriptingcve-2026-55008exchange-serverinputs-neutralizationmicrosoftnetwork-securitynvd-cve
2026-07-14 NVD CVE
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-54990exploitheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14 NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint
2026-07-14 NVD CVE
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
cve-2026-49798freekernel-exploitlocal-attacknvd-cveprivileges-escalationsecurity-bulletinunauthorized-access
2026-07-14 NVD CVE
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14 NVD CVE
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14 NVD CVE
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from...
attackerauthenticationcertificatecve-2026-45063distinguished-namesemail-addressfixnvd-cve
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted...
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(),...
2026-07-14 NVD CVE
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key...
2026-07-14 NVD CVE
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-42990heap-based-buffer-overflowmicrosoftnetworks-attacksnvd-cveodbc-driver
2026-07-14 NVD CVE
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument...
buffer-overflowcooeys-clubcve-2026-15701form-logoutformlogouthtmlighttpdnetworks-devicesnvd-cve
2026-07-14 NVD CVE
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache...
apache-softwaresapaches-kylinapi-vulnerabilitiescommand-injectioncve-2026-62392cybersecuritydata-breaches-preventionincident-response
2026-07-14 NVD CVE
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue...
apaches-kylinapicisacmmccve-2026-62390databasedodnist-800-171
2026-07-14 NVD CVE
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative...
administratives-apisapaches-dori-3-1-0apaches-dorisauthenticationcluster-availabilitycluster-integritycve-2026-58319denial
2026-07-13 NVD CVE
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It...
32-bit-buildcrashes-vulnerabilitiescve-2026-40469do-subgawkheap-overflowinteger-overflownvd-cve
2026-07-13 NVD CVE
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and...
cisacmmc-level-2cve-2026-40468dodfedramp-authorizationgawkheap-metadatainteger-overflow
2026-07-13 NVD CVE
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single...
9routerai-provider-accountapi-key-exposurebilling-fraudcompliance-riskcve-2026-62327information-leakagemissing-authentication-middleware
2026-07-13 NVD CVE
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to...
9routerapi-endpointapi-keyauthentication-middlewarecompliance-riskcredentials-exposurecve-2026-59801denial
◀ PREV PAGE 20 / 47 NEXT ▶