LIVE FEED
1803 events · 13 sources · newest first
Events in view
1803
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 12:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-07-14
NVD CVE
CVE-2026-15701: A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affect
CRITICAL
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument...
buffer-overflowcooeys-clubcve-2026-15701form-logoutformlogouthtmlighttpdnetworks-devicesnvd-cve
2026-07-14
NVD CVE
CVE-2026-62392: Improper Neutralization of Special Elements used in an OS Command ('OS Command I
CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.
This issue affects Apache...
apache-softwaresapaches-kylinapi-vulnerabilitiescommand-injectioncve-2026-62392cybersecuritydata-breaches-preventionincident-response
2026-07-14
NVD CVE
CVE-2026-62390: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.
This issue...
apaches-kylinapicisacmmccve-2026-62390databasedodnist-800-171
2026-07-14
NVD CVE
CVE-2026-58319: Certain Apache Doris FE HTTP REST administrative APIs were accessible without pr
CRITICAL
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative...
administratives-apisapaches-dori-3-1-0apaches-dorisauthenticationcluster-availabilitycluster-integritycve-2026-58319denial
2026-07-14
NVD CVE
CVE-2026-56451: A vulnerability has been identified in Opcenter X (All versions < V2604). Affect
CRITICAL
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
This could allow an...
access-controlapplications-securityauthentication-bypasscve-2026-56451cve-trackingsimpersonationjson-web-tokenjwt-forges
2026-07-14
NVD CVE
CVE-2026-44761: SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented
CRITICAL
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an...
apus-exploitationscompliance-riskconfidentiality-impactcredentials-exposurecve-2026-44761data-integrityhelp-portalnvd-cve
2026-07-14
NVD CVE
CVE-2026-44747: SAP NetWeaver Application Server ABAP allows an authenticated attacker to levera
CRITICAL
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system...
abapauthenticate-attackeravailabilitycmmcconfidentialitycve-2026-44747data-accessdefense-industrial-base
2026-07-14
NVD CVE
CVE-2026-27690: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthentica
CRITICAL
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the...
availability-impactconfidentiality-impactcve-2026-27690https-requests-smugglingnvd-cverequests-responses-desynchronizationsap-approutersecurity-vulnerability
2026-07-14
NVD CVE
CVE-2026-54117: Deserialization of untrusted data in SQL Server allows an unauthorized attacker
CRITICAL
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-50487: Use after free in Microsoft Windows DNS allows an unauthorized attacker to eleva
HIGH
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-50439: Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized
HIGH
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-54058: Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncomp
CRITICAL
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller...
2026-07-14
NVD CVE
CVE-2026-50330: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac
HIGH
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unautho
HIGH
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-49181: Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthor
HIGH
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14
NVD CVE
CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized
HIGH
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
2026-07-14
NVD CVE
CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut
HIGH
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allow
HIGH
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-48807: Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() c
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators,...
2026-07-14
NVD CVE
CVE-2026-48806: Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not g
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key...
2026-07-14
NVD CVE
CVE-2026-48805: Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappe
CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(),...
2026-07-14
NVD CVE
CVE-2026-58617: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized
HIGH
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to
HIGH
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-14
NVD CVE
CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau
HIGH
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unautho
HIGH
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-46634: Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_stri
CRITICAL
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox...
2026-07-14
NVD CVE
CVE-2026-46633: Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does no
CRITICAL
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted...
2026-07-14
NVD CVE
CVE-2026-48320: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
HIGH
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control...
coldfusioncross-site-scriptingcve-2026-48320elevated-accessmalicious-scriptsnvd-cvereflecteds-xsssession-control
2026-07-14
NVD CVE
CVE-2026-47988: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
HIGH
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47988exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14
NVD CVE
CVE-2026-47984: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
HIGH
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47984exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14
NVD CVE
CVE-2026-47767: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on...
applications-securitycode-executioncve-2024-50340cve-2026-47767debug-modeenvironment-variablesnvd-cvephp
2026-07-14
NVD CVE
CVE-2026-45069: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and...
audience-checkauthenticationclaim-verificationcve-2026-45069expiry-checksissuer-checksjwtnvd-cve
2026-07-14
NVD CVE
CVE-2026-45063: Symfony is a PHP framework for web and console applications and a set of reusabl
CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from...
attackerauthenticationcertificatecve-2026-45063distinguished-namesemail-addressfixnvd-cve
2026-07-14
NVD CVE
CVE-2026-54118: Deserialization of untrusted data in SQL Server allows an unauthorized attacker
CRITICAL
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-48334: Illustrator is affected by an Improper Input Validation vulnerability that could
CRITICAL
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
adobearbitrary-code-executioncve-2026-48334illustratorimproper-input-validationmalicious-filesnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48327: ColdFusion is affected by an Incorrect Authorization vulnerability that could re
CRITICAL
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope...
arbitrary-code-executioncoldfusioncve-2026-48327exploitincorrect-authorizationnvd-cvesecurityvulnerability
2026-07-14
NVD CVE
CVE-2026-48325: ColdFusion is affected by a Missing Authentication for Critical Function vulnera
CRITICAL
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
arbitrary-code-executioncoldfusioncritical-functionscve-2026-48325exploitmissing-authenticationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48324: ColdFusion is affected by an Improper Neutralization of Special Elements used in
CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncoldfusioncve-2026-48324exploitationimproper-neutralizationnvd-cvescope-changesspecial-elements