LIVE FEED
1853 events · 13 sources · newest first
Events in view
1853
all sources
Critical
1853
severity
Active sources
13
collectors
Last sync
2026-08-29 12:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-05-13
NVD CVE
CVE-2026-0264: A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo
CRITICAL
A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all...
2026-05-13
NVD CVE
CVE-2026-42557: jupyterlab is an extensible environment for interactive and reproducible computi
CRITICAL
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and...
2026-05-13
NVD CVE
CVE-2026-0258: A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation o
CRITICAL
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended...
2026-05-13
NVD CVE
CVE-2026-0263: A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PA
CRITICAL
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or...
2026-05-10
NVD CVE
CVE-2026-6722: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without...
2026-05-10
NVD CVE
CVE-2026-7261: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via...
2026-05-10
NVD CVE
CVE-2026-6104: In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam
CRITICAL
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that...
2026-05-10
NVD CVE
CVE-2025-14179: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
CRITICAL
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query...
2026-05-09
NVD CVE
CVE-2026-42601: ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6
CRITICAL
ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without...
2026-05-09
NVD CVE
CVE-2026-42257: Net::IMAP implements Internet Message Access Protocol (IMAP) client functionalit
CRITICAL
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the...
2026-05-08
NVD CVE
CVE-2026-42298: Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Re
CRITICAL
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any...
2026-05-08
NVD CVE
CVE-2026-42354: Sentry is an error tracking and performance monitoring tool. From version 21.12.
CRITICAL
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows...
2026-05-08
NVD CVE
CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
CRITICAL
◈ 2 sources · orig. NVD CVE
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key...
2026-05-07
NVD CVE
CVE-2026-42216: OpenEXR provides the specification and reference implementation of the EXR file
CRITICAL
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0...
2026-05-07
NVD CVE
CVE-2026-41586: Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framew
CRITICAL
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes...
2026-05-07
NVD CVE
CVE-2026-7891: A vulnerability has been identified in Mendix Runtime (All versions). Mendix doc
CRITICAL
A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without...
2026-05-05
NVD CVE
CVE-2026-35579: CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QU
CRITICAL
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the...
2026-05-05
NVD CVE
CVE-2026-34084: PhpSpreadsheet is a library for reading and writing spreadsheet files. In versio
CRITICAL
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename...
2026-05-04
NVD CVE
CVE-2026-26332: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, Suppresse
CRITICAL
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
2026-04-30
NVD CVE
CVE-2026-35051: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false...
2026-04-30
NVD CVE
CVE-2026-39858: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3
CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based...
2026-04-30
CISA KEV
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the...
2026-04-28
CISA KEV
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
2026-04-24
CISA KEV
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
2026-04-24
NVD CVE
CVE-2026-41473: CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerabilit
CRITICAL
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending...
2026-04-24
CISA KEV
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute...
2026-04-23
NVD CVE
CVE-2026-25874: LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the as
CRITICAL
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the...
2026-04-23
NVD CVE
CVE-2026-41176: Rclone is a command-line program to sync files and directories to and from diffe
CRITICAL
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime...
2026-04-23
NVD CVE
CVE-2026-41179: Rclone is a command-line program to sync files and directories to and from diffe
CRITICAL
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed...
2026-04-22
CISA KEV
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
2026-04-20
CISA KEV
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
2026-04-20
CISA KEV
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
2026-04-18
NVD CVE
CVE-2026-41242: protobufjs compiles protobuf definitions into JavaScript (JS) functions. In vers
CRITICAL
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute...
2026-04-14
NVD CVE
CVE-2026-35033: Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c
CRITICAL
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter...
2026-04-14
NVD CVE
CVE-2026-27303: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati
CRITICAL
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of...
2026-04-14
NVD CVE
CVE-2026-39907: Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose
CRITICAL
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter,...
2026-04-14
NVD CVE
CVE-2026-27246: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cro
CRITICAL
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page,...
2026-04-14
NVD CVE
CVE-2026-27245: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro
CRITICAL
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page,...
2026-04-14
NVD CVE
CVE-2026-27243: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro
CRITICAL
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page,...
2026-04-14
NVD CVE
CVE-2026-34615: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati
CRITICAL
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could...