LIVE FEED
1803 events · 13 sources · newest first
Events in view
1803
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-21
NVD CVE
CVE-2026-61239: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60225: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60225cvss-31data-compromisehttpintegrity
2026-07-21
NVD CVE
CVE-2026-61244: Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product o
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-61242: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low...
2026-07-21
NVD CVE
CVE-2026-60445: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CRITICAL
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60229: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60229cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-60302: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60555: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability...
2026-07-21
NVD CVE
CVE-2026-60606: Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product
CRITICAL
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60388: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-61097: Vulnerability in the Oracle Banking Trade Finance Process Management product of
CRITICAL
Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60240: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60240cvss-31data-compromiseintegritynetwork-access
2026-07-21
NVD CVE
CVE-2026-60241: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycore-componentcve-2026-60241cvss-31httpintegrity
2026-07-21
NVD CVE
CVE-2026-60242: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycore-componentcve-2026-60242cvss-31httpintegrity
2026-07-21
NVD CVE
CVE-2026-61245: Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of O
CRITICAL
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows...
2026-07-21
NVD CVE
CVE-2026-60355: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (
CRITICAL
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60538: Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
2026-07-21
NVD CVE
CVE-2026-60248: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CRITICAL
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable...
availabilityconfidentialitycore-componentcve-2026-60248cvss-31cvss-basis-scoreinfrastructure-compromiseintegrity
2026-07-20
NVD CVE
CVE-2026-28220: Wazuh is a free and open source platform used for threat prevention, detection,
HIGH
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to...
2026-07-20
NVD CVE
CVE-2026-12341: This vulnerability
impacts all versions of IdentityIQ and allows an unauthentica
HIGH
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
2026-07-20
NVD CVE
CVE-2026-64625: AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync
CRITICAL
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary...
avideocommand-injectioncve-2026-45578cve-2026-64625cybersecuritydefense-industrial-basedfar-252-204-7012escapeshellarg
2026-07-20
NVD CVE
CVE-2026-63767: ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticate
CRITICAL
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to...
arbitrary-command-executioncve-2026-63767cybersecuritydefense-industrial-basedfar-252-204-7012ktraansformernist-800-171nvd-cve
2026-07-20
NVD CVE
CVE-2026-63766: GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability
CRITICAL
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands...
arbitrary-command-executionauthenticationcve-2026-63766cybersecuritygpt-sovitgradioinformation-securitynvd-cve
2026-07-20
NVD CVE
CVE-2026-12701: A path traversal vulnerability was found in pulpcore. The relative_path_validato
CRITICAL
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../"...
administrator-privilegesartifacts-handlingcybersecuritydata-exposurefile-integrityfile-writefilesystem-exportincident-response
2026-07-20
NVD CVE
CVE-2026-64620: FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow
CRITICAL
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output...
authenticationbuffer-overflowcrypto-rsa-commonscve-2026-64620cybersecuritydefense-industrial-basedenialfreerdp
2026-07-20
NVD CVE
CVE-2026-16242: A flaw was found in the Konnectivity proxy-server configuration for hosted contr
CRITICAL
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client...
agent-authenticationclient-certificate-validationconfiguration-errorcontrol-plane-trafficdata-droppingdata-modificationdefense-industrial-basekonnectivity
2026-07-20
NVD CVE
CVE-2026-41521: xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer
HIGH
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send...
2026-07-18
NVD CVE
CVE-2026-16158: Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 b
HIGH
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source...
2026-07-18
NVD CVE
CVE-2026-15631: Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail
HIGH
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
2026-07-17
NVD CVE
CVE-2026-14501: IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacke
MEDIUM
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.
2026-07-17
NVD CVE
CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
HIGH
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker...
2026-07-17
NVD CVE
CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
HIGH
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems...
agent-componentapi-v1code-act-agentcsv-agentcve-2026-13448denialflow-idibm
2026-07-17
NVD CVE
CVE-2026-13446: IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or...
authenticationcve-2026-13446data-encryptionencryptionhard-coded-credentialsibminbound-authenticationinternal-data
2026-07-17
NVD CVE
CVE-2026-8859: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability...
api-requestsarbitrary-file-writecontents-dispositioncve-2026-8859ibmincident-responseinput-validationlangflow
2026-07-17
NVD CVE
CVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with...
arbitrary-code-executionauthenticate-usercve-2026-8635databases-manipulationibmlangflownvd-cveopen-source-software
2026-07-17
NVD CVE
CVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key...
api-keyauthenticationbypassconfigurationcve-2026-8505default-settingsibmlangflow
2026-07-17
NVD CVE
CVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes...
api-endpointauthenticate-usercode-validationcve-2026-8481exec-functionibminput-validationlangflow
2026-07-17
NVD CVE
CVE-2026-8476: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize...
api-manipulationasyncdiskcachecustom-componentscve-2026-8476deserializationfile-system-accessibmlangflow
2026-07-17
NVD CVE
CVE-2026-15091: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to
CRITICAL
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
arbitrary-script-executioncve-2026-15091ibmibm-engineering-ai-hub-1-0-0ibm-engineering-ai-hub-1-1-0ibm-engineering-ai-hub-1-2-0ibm-engineering-ai-hubsimproper-inputs-neutralization
2026-07-17
NVD CVE
CVE-2026-9135: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 9498
CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that...
agentic-mcpsauthenticate-users-attackscode-injectioncross-tenant-attackcve-2026-9135dynamic-code-validationflow-manipulationibm-langflow