LIVE FEED
1853 events · 13 sources · newest first
Events in view
1853
all sources
Critical
1853
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-13
NVD CVE
CVE-2026-61500: Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the
CRITICAL
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote...
administrative-accessauthenticationconfigurations-featurescve-2026-61500login-responsesnon-cryptographic-generatornvd-cverejetto
2026-07-13
NVD CVE
CVE-2026-61498: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerabi
CRITICAL
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying...
cmmc-level-2command-injectioncve-2026-61498graph-generationinput-sanitizationnist-800-171nvd-cveos-command-execution
2026-07-13
NVD CVE
CVE-2026-4769: Certain devices in the WAGO System I/O Field series activate an internal diagnos
CRITICAL
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without...
cisacmmc-level-2cve-2026-4769defense-industrial-basedevices-compromisefedramp-authorizationincident-responseinternal-diagnostic
2026-07-13
NVD CVE
CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression match
CRITICAL
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.
When such branches are...
access-controlcve-2026-13221false-negativefalse-positivesfilteringnvd-cveoverflowperl
2026-07-13
NVD CVE
CVE-2026-57830: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrar
CRITICAL
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
arbitrary-file-deletioncve-2026-57830extensionfile-deletionhelixes-ultimatesjoomlanvd-cvesecurity
2026-07-12
NVD CVE
CVE-2026-15511: A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected
CRITICAL
A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This...
cf-wr631axcomfastcommand-injectioncve-2026-15511fastcgi-backendsfile-path-manipulationnvd-cveos-command-injection
2026-07-12
NVD CVE
CVE-2026-56271: Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded
CRITICAL
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise...
api-securityauthentication-bypassauthentication-middlewarecve-2026-56271default-credentialsflowisehardcoded-secretimpersonation
2026-07-12
NVD CVE
CVE-2026-56260: Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Dock
CRITICAL
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation,...
api-serverarbitrary-file-writecrawl4aicve-2026-56260denialdockerdocker-apusendpoint-security
2026-07-11
NVD CVE
CVE-2026-61447: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAg
CRITICAL
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement....
arbitrary-code-executioncodeagentcve-2026-61447cybersecuritydatum-exfiltrationenvironment-secretslarge-language-modelllm
2026-07-11
NVD CVE
CVE-2026-61445: PraisonAI before 4.6.78 contains arbitrary file write and command execution vuln
CRITICAL
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject...
aicoder-componentarbitrary-file-writecommand-executioncommands-sanitizationcve-2026-61445cybersecurityinformation-securityllms-tool
2026-07-11
NVD CVE
CVE-2026-60090: PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argume
CRITICAL
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name...
cassandracql-injectioncreate-tablescve-2026-60090cybersecuritydata-validationdatabase-securityddl-injections
2026-07-11
NVD CVE
CVE-2026-57827: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file
CRITICAL
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadcve-2026-57827files-uploadjoomlanvd-cveremote-code-executionrsfilesecurity
2026-07-10
NVD CVE
CVE-2026-57156: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying...
32-bit-buildcve-2026-57156cve-disclosuresfreerdpheap-buffer-overflowheap-buffers-undersizeheap-overflowinteger-overflow
2026-07-10
NVD CVE
CVE-2026-57158: FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 bef
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in...
buffer-overflowcmmc-level-2compliancecve-2026-23530cve-2026-57158dodfedrampfreerdp
2026-07-10
NVD CVE
CVE-2026-12761: The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) pl
CRITICAL
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due...
accounts-takeoveradministrators-accessauthentication-bypasscve-2026-12761cybersecuritydata-compromiseemail-address-verificationminiorange
2026-07-10
NVD CVE
CVE-2026-61459: MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability
CRITICAL
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security...
api-serverargument-injectionbearer-tokencluster-compromisecve-2026-61459cybersecuritydefense-industrial-baseincident-response
2026-07-10
NVD CVE
CVE-2026-59792: In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path trav
CRITICAL
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID handling was possible
code-executioncve-2026-59792cybersecuritydfar-252-204-7012incident-responseintellij-ideajetbrainnist-800-171
2026-07-10
NVD CVE
CVE-2026-61444: PraisonAI versions before 4.6.78 contain a code injection vulnerability in deplo
CRITICAL
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary...
apicode-injectioncve-2026-61444cybersecuritydeploymentnvd-cvepraiseaipython
2026-07-10
NVD CVE
CVE-2026-15378: A flaw was found in the `guardrails-detectors` component. This vulnerability all
CRITICAL
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition...
cloud-metadata-servicescredentials-theftcve-2026-15378file-readsguardrail-detectorsinternal-networkkubernete-apiminio
2026-07-10
NVD CVE
CVE-2026-15300: The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'dist
CRITICAL
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via...
cve-2026-15300cybersecurityescape-functiongeo-my-wp-plugininformation-securitynumeric-validationnvd-cvephp
2026-07-10
NVD CVE
CVE-2026-15282: The Instant Appointment plugin for WordPress is vulnerable to arbitrary file upl
CRITICAL
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2....
arbitrary-files-uploadcve-2026-15282cybersecurityfile-type-validationinformation-securityinstant-appointmentnvd-cveplugin
2026-07-10
NVD CVE
CVE-2026-14894: The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CRITICAL
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type...
ajaxarbitrary-files-uploadcve-2026-14894cybersecurityfile-type-validationnoncenoprivnvd-cve
2026-07-09
NVD CVE
CVE-2026-0284: An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of P
CRITICAL
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially...
cloud-ngfwcve-2026-0284data-corruptioninformation-disclosurelsvpnmalicious-contentsnetwork-accessnot-impacted
2026-07-09
NVD CVE
CVE-2026-47826: The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an at
CRITICAL
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.
Affected versions: BOSH CLI tool versions prior to v7.10.4.
arbitrary-file-writeblob-ymlbosh-clicli-toolcloud-foundrycodecve-2026-47826datum-exfiltration
2026-07-09
NVD CVE
CVE-2026-56291: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary
CRITICAL
◈ 2 sources · orig. NVD CVE
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadbalbooon-formcybersecurityfiles-uploadjoomlanvd-cverceremote-code-execution
2026-07-09
NVD CVE
CVE-2026-58123: Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution v
CRITICAL
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without...
api-endpointcommand-executioncybersecuritydefense-industrial-basehermes-webuihttps-requestsincident-responsenvd-cve
2026-07-09
NVD CVE
CVE-2026-58122: Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability tha
CRITICAL
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed...
accesses-tokenapi-keyauthentication-bypasscloud-metadata-endpointcve-2026-58122device-code-flowheaderhermes-webui
2026-07-09
NVD CVE
CVE-2026-5955: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection.
This issue affects BiEticaret: before v3.3.57.
applications-securitybieticaretcve-2026-5955cybersecuritydata-securityinrove-softwarenvd-cvesoftware-vulnerabilities
2026-07-09
NVD CVE
CVE-2026-2342: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS.
This issue affects ValeApp: through...
cross-site-scriptingcybersecuritydisclosureinput-validationnvd-cveoceanicsoftsoftware-vulnerabilitiesstoreds-xss
2026-07-09
NVD CVE
CVE-2026-15158: The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Uploa
CRITICAL
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering...
arbitrary-files-uploadblocksy-companionblocksy-companion-procustom-fontscve-2026-15158file-extensionmime-validationnvd-cve
2026-07-09
NVD CVE
CVE-2026-14245: The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPres
CRITICAL
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is...
accounts-takeoveradministrator-accounts-takeoverauthentication-bypasscve-2026-14245form-noncejavascriptminiorangenonce
2026-07-09
NVD CVE
CVE-2026-47646: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcustomer-voicecve-2026-47646cybersecuritydynamics-365information-securityinput-validationmicrosoft
2026-07-08
NVD CVE
CVE-2026-55471: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CRITICAL
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare...
2026-07-08
NVD CVE
CVE-2026-54527: JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, t
CRITICAL
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history,...
2026-07-08
NVD CVE
CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains
CRITICAL
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
api-connectcve-2026-9074cybersecuritydata-securitydefense-industrial-baseibmincident-responsenist-800-171
2026-07-08
NVD CVE
CVE-2026-58480: Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthentic
CRITICAL
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the...
blocksy-companion-pro-plugincustom-fonts-extensionscve-2026-58480cybersecurityextension-validationfiles-uploadnvd-cvephp
2026-07-08
NVD CVE
CVE-2026-8307: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection.
This issue affects Mediküm Web: through 08072026. NOTE: The...
cve-2026-8307cybersecuritydatabase-securityimproper-neutralizationmedikum-webnvd-cvesecurity-flawsql-injection
2026-07-08
NVD CVE
CVE-2026-12153: The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass
CRITICAL
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an...
arbitrary-code-executionauthorization-bypasscve-2026-12153cybersecuritynvd-cveplugin-activationplugin-installationplugins-vulnerabilities
2026-07-08
NVD CVE
CVE-2026-9701: The Eventer plugin for WordPress is vulnerable to an insecure password reset mec
CRITICAL
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the...
cve-2026-9700cve-2026-9701eventer-pluginnvd-cvepassword-resetphpphp-74plaintext
2026-07-08
NVD CVE
CVE-2026-14487: The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file de
CRITICAL
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes...
arbitrary-file-deletionauthenticationauthorizationcve-2026-14487cybersecurityfile-path-validationfile-removalhash-checks