LIVE FEED
1803 events · 13 sources · newest first
Events in view
1803
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 12:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-07-04
NVD CVE
CVE-2026-14535: In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImports
HIGH
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the...
2026-07-03
NVD CVE
CVE-2026-12481: A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code exe
CRITICAL
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()`...
2026-07-03
NVD CVE
CVE-2026-57983: Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized
HIGH
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
2026-07-03
NVD CVE
CVE-2026-47898: Improper Restriction of XML External Entity Reference vulnerability in Apache Lu
CRITICAL
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before...
2026-07-02
NVD CVE
CVE-2026-59092: JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypas
HIGH
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper...
2026-07-02
NVD CVE
CVE-2026-26145: Improper access control in Azure Synapse allows an authorized attacker to elevat
MEDIUM
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
2026-07-02
NVD CVE
CVE-2026-54408: A malicious actor with access to the network could exploit an Improper Access Co
HIGH
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
2026-07-02
NVD CVE
CVE-2026-55116: A malicious actor with access to the network and under certain network configura
CRITICAL
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to...
2026-07-02
NVD CVE
CVE-2026-55115: A malicious actor with access to the network and low privileges could exploit a
CRITICAL
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
2026-07-02
NVD CVE
CVE-2026-41106: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an un
CRITICAL
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
2026-07-01
NVD CVE
CVE-2026-14363: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.
This issue affects Mediawiki - Cargo...
2026-07-01
NVD CVE
CVE-2026-58025: Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik
CRITICAL
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php,...
2026-07-01
NVD CVE
CVE-2026-34100: Guardian language-system passes the id GET parameter directly into an unsanitize
CRITICAL
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id =...
2026-07-01
NVD CVE
CVE-2026-34106: Guardian language-system passes the id GET parameter directly into a PHP exec()
CRITICAL
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\"...
2026-07-01
NVD CVE
CVE-2026-58453: JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a h
CRITICAL
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin...
2026-07-01
NVD CVE
CVE-2026-58521: Improper neutralization of special elements used in an SQL command ('SQL injecti
CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.
This issue affects Mediawiki - Cargo...
2026-07-01
NVD CVE
CVE-2026-50195: containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 a
CRITICAL
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a...
2026-07-01
NVD CVE
CVE-2026-53492: containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.
CRITICAL
containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint...
2026-06-30
NVD CVE
CVE-2026-58016: A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new
HIGH
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element...
2026-06-30
NVD CVE
CVE-2026-13782: Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remo
CRITICAL
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...
2026-06-30
NVD CVE
CVE-2026-13785: Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allow
CRITICAL
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML...
2026-06-30
NVD CVE
CVE-2026-14101: Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.
CRITICAL
Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML...
2026-06-30
NVD CVE
CVE-2026-13781: Insufficient validation of untrusted input in Skia in Google Chrome prior to 150
CRITICAL
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML...
2026-06-30
NVD CVE
CVE-2026-13449: IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable
HIGH
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose...
2026-06-30
NVD CVE
CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome pr
CRITICAL
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security...
2026-06-30
NVD CVE
CVE-2026-13780: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 15
CRITICAL
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted...
2026-06-30
NVD CVE
CVE-2026-13776: Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote
CRITICAL
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...
2026-06-30
NVD CVE
CVE-2026-14106: Insufficient validation of untrusted input in Text in Google Chrome on Android p
CRITICAL
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a...
2026-06-30
NVD CVE
CVE-2026-14109: Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47
CRITICAL
Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page....
2026-06-30
NVD CVE
CVE-2026-13775: Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote a
CRITICAL
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...
2026-06-30
NVD CVE
CVE-2026-11541: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
HIGH
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
2026-06-30
NVD CVE
CVE-2026-7663: IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to ac
CRITICAL
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP...
2026-06-30
NVD CVE
CVE-2026-13773: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated C
MEDIUM
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java...
2026-06-30
NVD CVE
CVE-2026-13772: IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language eng
HIGH
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks...
2026-06-30
NVD CVE
CVE-2026-11714: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
2026-06-30
NVD CVE
CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
2026-06-30
NVD CVE
CVE-2026-10560: IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerabi
HIGH
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a...
2026-06-30
NVD CVE
CVE-2026-14120: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47
CRITICAL
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page....
2026-06-30
NVD CVE
CVE-2026-14241: Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidenc
CRITICAL
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This...
2026-06-30
NVD CVE
CVE-2026-8655: Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway
CRITICAL
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler...