LIVE FEED
1803 events · 13 sources · newest first
Events in view
1803
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 12:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-07-14
NVD CVE
CVE-2026-48259: Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vul
CRITICAL
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage...
adobe-experience-managersarbitrary-code-executioncve-2026-48259elevated-accessno-user-interaction-requiresnvd-cveservers-sides-requests-forgerysession-control
2026-07-14
NVD CVE
CVE-2026-48356: Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type
CRITICAL
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this...
adobe-commercearbitrary-code-executioncve-2026-48356elevated-accessmalicious-scriptsnvd-cvesession-controlunrestricted-uploads
2026-07-14
NVD CVE
CVE-2026-48358: Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnera
CRITICAL
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
adobe-commercearbitrary-code-executioncode-executioncve-2026-48358improper-encodingimproper-escapingnvd-cvesecurities-risks
2026-07-14
NVD CVE
CVE-2026-48359: Adobe Experience Manager is affected by an Improper Restriction of XML External
CRITICAL
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A...
adobe-experience-managersarbitrary-code-executioncve-2026-48359elevated-accessno-user-interaction-requiresnvd-cvesensitive-file-readingsession-control
2026-07-14
NVD CVE
CVE-2026-48284: ColdFusion is affected by an Improper Input Validation vulnerability that could
CRITICAL
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....
arbitrary-code-executioncoldfusioncve-2026-48284exploitimproper-input-validationinput-validationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48318: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CRITICAL
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to...
access-controlarbitrary-file-readscoldfusioncve-2026-48318directories-traversalexploitfile-system-readnvd-cve
2026-07-14
NVD CVE
CVE-2026-48319: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CRITICAL
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescve-2026-48319directories-traversalexploitnvd-cve
2026-07-14
NVD CVE
CVE-2026-48321: ColdFusion is affected by an Incorrect Authorization vulnerability that could re
CRITICAL
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of...
coldfusioncve-2026-48321exploitincorrect-authorizationnvd-cveprivileges-escalationsecurityunauthorized-access
2026-07-14
NVD CVE
CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized
HIGH
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
2026-07-14
NVD CVE
CVE-2026-48322: ColdFusion is affected by an Improper Control of Generation of Code ('Code Injec
CRITICAL
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does...
arbitrary-code-executioncode-injectioncoldfusioncve-2026-48322exploitnvd-cvescope-changessecurity
2026-07-14
NVD CVE
CVE-2026-48324: ColdFusion is affected by an Improper Neutralization of Special Elements used in
CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncoldfusioncve-2026-48324exploitationimproper-neutralizationnvd-cvescope-changesspecial-elements
2026-07-14
NVD CVE
CVE-2026-48325: ColdFusion is affected by a Missing Authentication for Critical Function vulnera
CRITICAL
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require...
arbitrary-code-executioncoldfusioncritical-functionscve-2026-48325exploitmissing-authenticationnvd-cvesecurity
2026-07-14
NVD CVE
CVE-2026-48334: Illustrator is affected by an Improper Input Validation vulnerability that could
CRITICAL
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
adobearbitrary-code-executioncve-2026-48334illustratorimproper-input-validationmalicious-filesnvd-cvesecurity
2026-07-13
NVD CVE
CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression match
CRITICAL
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.
When such branches are...
access-controlcve-2026-13221false-negativefalse-positivesfilteringnvd-cveoverflowperl
2026-07-13
NVD CVE
CVE-2026-59801: 9Router through version 0.4.41 contains an unauthenticated access vulnerability
CRITICAL
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to...
9routerapi-endpointapi-keyauthentication-middlewarecompliance-riskcredentials-exposurecve-2026-59801denial
2026-07-13
NVD CVE
CVE-2026-61500: Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the
CRITICAL
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote...
administrative-accessauthenticationconfigurations-featurescve-2026-61500login-responsesnon-cryptographic-generatornvd-cverejetto
2026-07-13
NVD CVE
CVE-2026-57830: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrar
CRITICAL
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
arbitrary-file-deletioncve-2026-57830extensionfile-deletionhelixes-ultimatesjoomlanvd-cvesecurity
2026-07-13
NVD CVE
CVE-2026-4769: Certain devices in the WAGO System I/O Field series activate an internal diagnos
CRITICAL
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without...
cisacmmc-level-2cve-2026-4769defense-industrial-basedevices-compromisefedramp-authorizationincident-responseinternal-diagnostic
2026-07-13
NVD CVE
CVE-2026-40468: Integer overflow vulnerability has been found in "builtin.c" program file of gaw
CRITICAL
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and...
cisacmmc-level-2cve-2026-40468dodfedramp-authorizationgawkheap-metadatainteger-overflow
2026-07-13
NVD CVE
CVE-2026-62327: 9Router through version 0.4.41 contain an unauthenticated information disclosure
CRITICAL
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single...
9routerai-provider-accountapi-key-exposurebilling-fraudcompliance-riskcve-2026-62327information-leakagemissing-authentication-middleware
2026-07-13
NVD CVE
CVE-2026-61498: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerabi
CRITICAL
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying...
cmmc-level-2command-injectioncve-2026-61498graph-generationinput-sanitizationnist-800-171nvd-cveos-command-execution
2026-07-13
NVD CVE
CVE-2026-40469: Integer overflow vulnerability has been found in "builtin.c" program file of gaw
CRITICAL
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It...
32-bit-buildcrashes-vulnerabilitiescve-2026-40469do-subgawkheap-overflowinteger-overflownvd-cve
2026-07-12
NVD CVE
CVE-2026-56271: Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded
CRITICAL
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise...
api-securityauthentication-bypassauthentication-middlewarecve-2026-56271default-credentialsflowisehardcoded-secretimpersonation
2026-07-12
NVD CVE
CVE-2026-10666: parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for string
HIGH
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a...
2026-07-12
NVD CVE
CVE-2026-56260: Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Dock
CRITICAL
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation,...
api-serverarbitrary-file-writecrawl4aicve-2026-56260denialdockerdocker-apusendpoint-security
2026-07-12
NVD CVE
CVE-2026-15511: A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected
CRITICAL
A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This...
cf-wr631axcomfastcommand-injectioncve-2026-15511fastcgi-backendsfile-path-manipulationnvd-cveos-command-injection
2026-07-11
NVD CVE
CVE-2026-56372: ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the
LOW
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds...
bound-readcmmccve-2026-56372defense-industrial-basedenialdodfedrampheap-buffer-overflow
2026-07-11
NVD CVE
CVE-2026-57827: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file
CRITICAL
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
arbitrary-files-uploadcve-2026-57827files-uploadjoomlanvd-cveremote-code-executionrsfilesecurity
2026-07-11
NVD CVE
CVE-2026-61447: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAg
CRITICAL
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement....
arbitrary-code-executioncodeagentcve-2026-61447cybersecuritydatum-exfiltrationenvironment-secretslarge-language-modelllm
2026-07-11
NVD CVE
CVE-2026-61445: PraisonAI before 4.6.78 contains arbitrary file write and command execution vuln
CRITICAL
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject...
aicoder-componentarbitrary-file-writecommand-executioncommands-sanitizationcve-2026-61445cybersecurityinformation-securityllms-tool
2026-07-11
NVD CVE
CVE-2026-60090: PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argume
CRITICAL
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name...
cassandracql-injectioncreate-tablescve-2026-60090cybersecuritydata-validationdatabase-securityddl-injections
2026-07-10
NVD CVE
CVE-2026-15378: A flaw was found in the `guardrails-detectors` component. This vulnerability all
CRITICAL
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition...
cloud-metadata-servicescredentials-theftcve-2026-15378file-readsguardrail-detectorsinternal-networkkubernete-apiminio
2026-07-10
NVD CVE
CVE-2026-14894: The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CRITICAL
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type...
ajaxarbitrary-files-uploadcve-2026-14894cybersecurityfile-type-validationnoncenoprivnvd-cve
2026-07-10
NVD CVE
CVE-2026-61459: MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability
CRITICAL
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security...
api-serverargument-injectionbearer-tokencluster-compromisecve-2026-61459cybersecuritydefense-industrial-baseincident-response
2026-07-10
NVD CVE
CVE-2026-59792: In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path trav
CRITICAL
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID handling was possible
code-executioncve-2026-59792cybersecuritydfar-252-204-7012incident-responseintellij-ideajetbrainnist-800-171
2026-07-10
NVD CVE
CVE-2026-57158: FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 bef
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in...
buffer-overflowcmmc-level-2compliancecve-2026-23530cve-2026-57158dodfedrampfreerdp
2026-07-10
NVD CVE
CVE-2026-57211: RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windo
MEDIUM
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to...
cve-2026-57211dns-exfiltrationdns-smberlangmanagement-pluginsnetwork-securitynvd-cveoutbound-requests
2026-07-10
NVD CVE
CVE-2026-57216: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11,
MEDIUM
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect...
amqp-protocolauthentication-bypasscve-2026-57216guests-usersloopback-restrictionmessaging-brokernetwork-securitynvd-cve
2026-07-10
NVD CVE
CVE-2026-61444: PraisonAI versions before 4.6.78 contain a code injection vulnerability in deplo
CRITICAL
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary...
apicode-injectioncve-2026-61444cybersecuritydeploymentnvd-cvepraiseaipython
2026-07-10
NVD CVE
CVE-2026-57156: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying...
32-bit-buildcve-2026-57156cve-disclosuresfreerdpheap-buffer-overflowheap-buffers-undersizeheap-overflowinteger-overflow