LIVE FEED
1853 events · 13 sources · newest first
Events in view
1853
all sources
Critical
1853
severity
Active sources
13
collectors
Last sync
2026-08-29 12:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-05-29
NVD CVE
CVE-2026-49199: Crafted MQTT messages can trigger command injection, resulting in root-level cod
CRITICAL
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
2026-05-29
NVD CVE
CVE-2026-45700: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c,...
2026-05-29
NVD CVE
CVE-2026-49201: The upload.cgi binary, responsible for processing device backups, contains a har
CRITICAL
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
2026-05-29
NVD CVE
CVE-2026-49197: Web endpoints intended for the Acer Connect app improperly validate the HTTP Aut
CRITICAL
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.
2026-05-28
NVD CVE
CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote
CRITICAL
Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
2026-05-28
NVD CVE
CVE-2026-4408: A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S
CRITICAL
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u...
2026-05-28
NVD CVE
CVE-2026-44477: CloudNativePG is a platform designed to manage PostgreSQL databases within Kuber
CRITICAL
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres...
2026-05-28
NVD CVE
CVE-2026-44881: Portainer Community Edition is a lightweight service delivery platform for conta
CRITICAL
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2,...
2026-05-27
CISA KEV
TanStack Unspecified Vulnerability
CRITICAL
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
2026-05-27
CISA KEV
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials...
2026-05-26
NVD CVE
CVE-2026-48691: FastNetMon Community Edition through 1.2.9 contains an integer overflow in the B
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as...
2026-05-26
NVD CVE
CVE-2026-40383: An improper validation of user-supplied input leads to a local file inclusion vu
CRITICAL
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
2026-05-26
NVD CVE
CVE-2026-48689: FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buf
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer,...
2026-05-26
NVD CVE
CVE-2026-48904: An improper access check allows privelege escalation through the com_users group
CRITICAL
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
2026-05-26
NVD CVE
CVE-2026-48899: An improper access check allows privilege escalation through the com_users batch
CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
2026-05-26
NVD CVE
CVE-2026-48898: An improper access check allows privilege escalation through the com_users batch
CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
2026-05-26
NVD CVE
CVE-2026-35221: Improperly built filter clauses lead to a SQL injection vulnerability in the sea
CRITICAL
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
2026-05-26
NVD CVE
CVE-2026-48686: FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflo
CRITICAL
FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() in...
2026-05-26
NVD CVE
CVE-2026-35223: An improper access check allows unauthorized access to com_config webservice end
CRITICAL
An improper access check allows unauthorized access to com_config webservice endpoints.
2026-05-26
NVD CVE
CVE-2026-35222: Improperly validated order clauses lead to a SQL injection vulnerability in com_
CRITICAL
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
2026-05-26
NVD CVE
CVE-2026-48687: FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln
CRITICAL
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118)...
2026-05-26
NVD CVE
CVE-2026-8376: Perl versions through 5.43.10 have a heap buffer overflow when compiling regular
CRITICAL
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the joined...
2026-05-26
NVD CVE
CVE-2026-44985: Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSo
CRITICAL
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade...
2026-05-26
NVD CVE
CVE-2026-42496: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker contro
CRITICAL
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() without validating it...
2026-05-22
NVD CVE
CVE-2026-23652: Improper neutralization of special elements used in a command ('command injectio
CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
2026-05-22
NVD CVE
CVE-2026-40412: Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows a
CRITICAL
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
2026-05-22
NVD CVE
CVE-2026-44930: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s
CRITICAL
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to...
2026-05-22
NVD CVE
CVE-2026-47280: Improper authentication in Azure Resource Manager (ARM) allows an unauthorized a
CRITICAL
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
2026-05-22
NVD CVE
CVE-2026-33843: Authentication bypass using an alternate path or channel in Microsoft Azure Acti
CRITICAL
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
2026-05-21
NVD CVE
CVE-2026-48172: LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possi
CRITICAL
◈ 2 sources · orig. NVD CVE
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE...
2026-05-20
NVD CVE
CVE-2026-42960: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning
CRITICAL
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used...
2026-05-20
NVD CVE
CVE-2026-20223: A vulnerability in the access validation of internal REST APIs of Cisco Sec
CRITICAL
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin...
2026-05-20
NVD CVE
CVE-2026-8631: A potential security vulnerability has been identified in the HP Linux Imaging a
CRITICAL
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer...
2026-05-20
NVD CVE
CVE-2026-33278: NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability
CRITICAL
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure...
2026-05-19
NVD CVE
CVE-2026-8605: In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al
CRITICAL
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
2026-05-19
NVD CVE
CVE-2026-8603: In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an a
CRITICAL
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
2026-05-19
NVD CVE
CVE-2026-8602: In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnera
CRITICAL
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.
2026-05-19
NVD CVE
CVE-2026-33642: Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the
CRITICAL
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic...
2026-05-15
NVD CVE
CVE-2026-44774: Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, an
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider...
2026-05-14
NVD CVE
CVE-2026-44484: PyTorch Lightning is a deep learning framework to pretrain and finetune AI model
CRITICAL
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.