LIVE FEED
1853 events · 13 sources · newest first
Events in view
1853
all sources
Critical
1853
severity
Active sources
13
collectors
Last sync
2026-08-29 12:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-04-14
NVD CVE
CVE-2026-39906: Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose
CRITICAL
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a...
2026-04-13
CISA KEV
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
2026-04-13
NVD CVE
CVE-2026-0234: An improper verification of cryptographic signature vulnerability exists in Cort
CRITICAL
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify...
2026-04-09
NVD CVE
CVE-2026-34184: AlanWeb SCADA does not enforce authorization for some directories. This allows a
CRITICAL
AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP...
2026-04-09
NVD CVE
CVE-2025-62718: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.
CRITICAL
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like...
2026-04-08
NVD CVE
CVE-2026-27143: Arithmetic over induction variables in loops were not correctly checked for unde
CRITICAL
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
2026-04-08
NVD CVE
CVE-2025-52221: Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm f
CRITICAL
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.
2026-04-08
NVD CVE
CVE-2026-39888: PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in pra
CRITICAL
PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted...
2026-04-08
NVD CVE
CVE-2026-33088: Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability
CRITICAL
Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.
2026-04-08
NVD CVE
CVE-2026-39892: cryptography is a package designed to expose cryptographic primitives and recipe
CRITICAL
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g....
2026-04-08
NVD CVE
CVE-2026-31017: A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format fu
CRITICAL
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered...
2026-04-07
NVD CVE
CVE-2026-34582: Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implem
CRITICAL
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to...
2026-04-07
NVD CVE
CVE-2026-28808: Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unaut
CRITICAL
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias.
When script_alias maps a URL prefix to a...
2026-04-07
NVD CVE
CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire
CRITICAL
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some...
2026-04-07
NVD CVE
CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t
CRITICAL
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run...
2026-04-07
NVD CVE
CVE-2026-39846: SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious no
CRITICAL
SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption...
2026-04-07
NVD CVE
CVE-2026-34078: Flatpak is a Linux application sandboxing and distribution framework. Prior to 1
CRITICAL
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths....
2026-04-07
NVD CVE
CVE-2026-39351: Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0,
CRITICAL
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.
2026-04-07
NVD CVE
CVE-2026-33439: Open Access Management (OpenAM) is an access management solution. Prior to 16.0.
CRITICAL
Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the...
2026-04-07
NVD CVE
CVE-2026-39397: @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual
CRITICAL
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with...
2026-04-07
NVD CVE
CVE-2026-31789: Issue summary: Converting an excessively large OCTET STRING value to
a hexadecim
CRITICAL
Issue summary: Converting an excessively large OCTET STRING value to
a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.
Impact summary: A heap buffer overflow may lead to a crash or...
2026-04-06
NVD CVE
CVE-2026-35178: Workbench is a suite of tools for administrators and developers to interact with
CRITICAL
Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerability in the...
2026-04-06
NVD CVE
CVE-2026-34444: Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier,
CRITICAL
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This...
2026-04-06
NVD CVE
CVE-2026-35184: EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQ
CRITICAL
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.
2026-04-06
NVD CVE
CVE-2026-35459: pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.
CRITICAL
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to...
2026-04-03
NVD CVE
CVE-2026-33107: Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized at
CRITICAL
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-34612: Kestra is an open-source, event-driven orchestration platform. Prior to version
CRITICAL
Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in...
2026-04-03
NVD CVE
CVE-2026-27634: Piwigo is an open source photo gallery application for the web. Prior to version
CRITICAL
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in...
2026-04-03
NVD CVE
CVE-2026-28798: ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 syst
CRITICAL
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an...
2026-04-03
NVD CVE
CVE-2026-32186: Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized atta
CRITICAL
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-31818: Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-
CRITICAL
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP...
2026-04-03
NVD CVE
CVE-2026-0545: In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not
CRITICAL
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the...
2026-04-03
NVD CVE
CVE-2026-33105: Improper authorization in Microsoft Azure Kubernetes Service allows an unauthori
CRITICAL
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-32213: Improper authorization in Azure AI Foundry allows an unauthorized attacker to el
CRITICAL
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2017-20235: ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an
CRITICAL
ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative...
2026-04-02
NVD CVE
CVE-2026-35002: Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability
CRITICAL
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed...
2026-04-02
NVD CVE
CVE-2026-35053: OneUptime is an open-source monitoring and observability platform. Prior to vers
CRITICAL
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST...
2026-04-02
NVD CVE
CVE-2026-34932: hoppscotch is an open source API development ecosystem. Prior to version 2026.3.
CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.
2026-04-02
NVD CVE
CVE-2026-34931: hoppscotch is an open source API development ecosystem. Prior to version 2026.3.
CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim...
2026-04-02
NVD CVE
CVE-2026-32871: FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2
CRITICAL
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is...