LIVE FEED
1524 events · 13 sources · newest first
Events in view
1524
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-14
NVD CVE
CVE-2026-44761: SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented
CRITICAL
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an...
apus-exploitationscompliance-riskconfidentiality-impactcredentials-exposurecve-2026-44761data-integrityhelp-portalnvd-cve
2026-07-14
NVD CVE
CVE-2026-44747: SAP NetWeaver Application Server ABAP allows an authenticated attacker to levera
CRITICAL
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system...
abapauthenticate-attackeravailabilitycmmcconfidentialitycve-2026-44747data-accessdefense-industrial-base
2026-07-14
NVD CVE
CVE-2026-27690: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthentica
CRITICAL
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the...
availability-impactconfidentiality-impactcve-2026-27690https-requests-smugglingnvd-cverequests-responses-desynchronizationsap-approutersecurity-vulnerability
2026-07-14
NVD CVE
CVE-2026-48807: Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() c
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
2026-07-14
NVD CVE
CVE-2026-48806: Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not g
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key...
2026-07-14
NVD CVE
CVE-2026-48805: Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappe
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(),...
2026-07-14
NVD CVE
CVE-2026-48284: ColdFusion is affected by an Improper Input Validation vulnerability that could
CRITICAL
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....
arbitrary-code-executioncoldfusioncve-2026-48284exploitimproper-input-validationinput-validationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48318: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CRITICAL
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to...
access-controlarbitrary-file-readscoldfusioncve-2026-48318directories-traversalexploitfile-system-readnvd-cve
2026-07-14
NVD CVE
CVE-2026-48319: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CRITICAL
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescve-2026-48319directories-traversalexploitnvd-cve
2026-07-14
NVD CVE
CVE-2026-48321: ColdFusion is affected by an Incorrect Authorization vulnerability that could re
CRITICAL
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of...
coldfusioncve-2026-48321exploitincorrect-authorizationnvd-cveprivileges-escalationsecurityunauthorized-access
2026-07-14
NVD CVE
CVE-2026-48322: ColdFusion is affected by an Improper Control of Generation of Code ('Code Injec
CRITICAL
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does...
arbitrary-code-executioncode-injectioncoldfusioncve-2026-48322exploitnvd-cvescope-changessecurity
2026-07-14
NVD CVE
CVE-2026-48324: ColdFusion is affected by an Improper Neutralization of Special Elements used in
CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncoldfusioncve-2026-48324exploitationimproper-neutralizationnvd-cvescope-changesspecial-elements
2026-07-14
NVD CVE
CVE-2026-48325: ColdFusion is affected by a Missing Authentication for Critical Function vulnera
CRITICAL
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
arbitrary-code-executioncoldfusioncritical-functionscve-2026-48325exploitmissing-authenticationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48327: ColdFusion is affected by an Incorrect Authorization vulnerability that could re
CRITICAL
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope...
arbitrary-code-executioncoldfusioncve-2026-48327exploitincorrect-authorizationnvd-cvesecurityvulnerability
2026-07-14
NVD CVE
CVE-2026-62422: In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.
CRITICAL
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
2026-07-14
NVD CVE
CVE-2026-46634: Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_stri
CRITICAL
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox...
2026-07-14
NVD CVE
CVE-2026-46633: Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does no
CRITICAL
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted...
2026-07-14
NVD CVE
CVE-2026-58319: Certain Apache Doris FE HTTP REST administrative APIs were accessible without pr
CRITICAL
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative...
administratives-apisapaches-dori-3-1-0apaches-dorisauthenticationcluster-availabilitycluster-integritycve-2026-58319denial
2026-07-14
NVD CVE
CVE-2026-47767: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on...
applications-securitycode-executioncve-2024-50340cve-2026-47767debug-modeenvironment-variablesnvd-cvephp
2026-07-14
NVD CVE
CVE-2026-45069: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and...
audience-checkauthenticationclaim-verificationcve-2026-45069expiry-checksissuer-checksjwtnvd-cve
2026-07-14
NVD CVE
CVE-2026-45063: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from...
attackerauthenticationcertificatecve-2026-45063distinguished-namesemail-addressfixnvd-cve
2026-07-14
NVD CVE
CVE-2026-54058: Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncomp
CRITICAL
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller...
2026-07-14
NVD CVE
CVE-2026-48561: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
ai-vulnerabilitycode-executioncommand-injectioncopilotcve-2026-48561microsoftnetwork-securityneutralization
2026-07-14
NVD CVE
CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacke
CRITICAL
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-49172exploitftpheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14
NVD CVE
CVE-2026-49798: Use after free in Windows Kernel allows an unauthorized attacker to elevate priv
CRITICAL
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
cve-2026-49798freekernel-exploitlocal-attacknvd-cveprivileges-escalationsecurity-bulletinunauthorized-access
2026-07-14
NVD CVE
CVE-2026-50522: Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint
2026-07-14
NVD CVE
CVE-2026-54990: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac
CRITICAL
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-54990exploitheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14
NVD CVE
CVE-2026-55008: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
attackercross-site-scriptingcve-2026-55008exchange-serverinputs-neutralizationmicrosoftnetwork-securitynvd-cve
2026-07-14
NVD CVE
CVE-2026-58644: Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
attack-vectorscode-executioncve-2026-58644datum-exfiltrationdeserializationexploitmicrosoftmicrosoft-office
2026-07-14
NVD CVE
CVE-2026-50380: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to ex
CRITICAL
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50380exploitgdiheap-based-buffer-overflownetworks-attacksnvd-cve
2026-07-14
NVD CVE
CVE-2026-50518: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke
CRITICAL
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-50518dhcp-serverheap-based-buffer-overflownetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-07-14
NVD CVE
CVE-2026-56190: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to
CRITICAL
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
code-executioncode-execution-vulnerabilitycve-2026-56190networks-attacksnetworks-vulnerabilitiesnvd-cverdpremote-desktop-protocol
2026-07-14
NVD CVE
CVE-2026-48259: Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vul
CRITICAL
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage...
adobe-experience-managersarbitrary-code-executioncve-2026-48259elevated-accessno-user-interaction-requiresnvd-cveservers-sides-requests-forgerysession-control
2026-07-14
NVD CVE
CVE-2026-48356: Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type
CRITICAL
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this...
adobe-commercearbitrary-code-executioncve-2026-48356elevated-accessmalicious-scriptsnvd-cvesession-controlunrestricted-uploads
2026-07-14
NVD CVE
CVE-2026-48358: Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnera
CRITICAL
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
adobe-commercearbitrary-code-executioncode-executioncve-2026-48358improper-encodingimproper-escapingnvd-cvesecurities-risks
2026-07-14
NVD CVE
CVE-2026-48359: Adobe Experience Manager is affected by an Improper Restriction of XML External
CRITICAL
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A...
adobe-experience-managersarbitrary-code-executioncve-2026-48359elevated-accessno-user-interaction-requiresnvd-cvesensitive-file-readingsession-control
2026-07-13
NVD CVE
CVE-2026-61498: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerabi
CRITICAL
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying...
cmmc-level-2command-injectioncve-2026-61498graph-generationinput-sanitizationnist-800-171nvd-cveos-command-execution
2026-07-13
NVD CVE
CVE-2026-61500: Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the
CRITICAL
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote...
administrative-accessauthenticationconfigurations-featurescve-2026-61500login-responsesnon-cryptographic-generatornvd-cverejetto
2026-07-13
NVD CVE
CVE-2026-4769: Certain devices in the WAGO System I/O Field series activate an internal diagnos
CRITICAL
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without...
cisacmmc-level-2cve-2026-4769defense-industrial-basedevices-compromisefedramp-authorizationincident-responseinternal-diagnostic
2026-07-13
NVD CVE
CVE-2026-59801: 9Router through version 0.4.41 contains an unauthenticated access vulnerability
CRITICAL
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to...
9routerapi-endpointapi-keyauthentication-middlewarecompliance-riskcredentials-exposurecve-2026-59801denial