LIVE FEED
1853 events · 13 sources · newest first
Events in view
1853
all sources
Critical
1853
severity
Active sources
13
collectors
Last sync
2026-08-29 12:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-03-31
NVD CVE
CVE-2026-34162: FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT
CRITICAL
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP...
2026-03-31
NVD CVE
CVE-2026-34400: Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API
CRITICAL
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search...
2026-03-31
NVD CVE
CVE-2026-34156: NocoBase is an AI-powered no-code/low-code platform for building business applic
CRITICAL
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a...
2026-03-31
NVD CVE
CVE-2026-34361: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CRITICAL
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that...
2026-03-31
NVD CVE
CVE-2026-34221: MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and
CRITICAL
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used...
2026-03-31
NVD CVE
CVE-2026-34532: Parse Server is an open source backend that can be deployed to any infrastructur
CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by...
2026-03-31
NVD CVE
CVE-2026-34235: PJSIP is a free and open source multimedia communication library written in C. P
CRITICAL
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted...
2026-03-31
NVD CVE
CVE-2026-32916: OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vuln
CRITICAL
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes....
2026-03-30
NVD CVE
CVE-2025-15379: A command injection vulnerability exists in MLflow's model serving container ini
CRITICAL
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`,...
2026-03-30
NVD CVE
CVE-2025-15036: A path traversal vulnerability exists in the `extract_archive_to_dir` function w
CRITICAL
A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions...
2026-03-27
NVD CVE
CVE-2026-33701: OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation a
CRITICAL
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that...
2026-03-26
NVD CVE
CVE-2026-26213: thingino-firmware versions up to the firmware-2026-03-16 release contains an una
CRITICAL
thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive portal CGI script that allows remote attackers to execute arbitrary...
2026-03-24
NVD CVE
CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f
CRITICAL
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-33211: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style
CRITICAL
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is...
2026-03-24
NVD CVE
CVE-2026-33195: Active Storage allows users to attach cloud and local files in Rails application
CRITICAL
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved...
2026-03-24
NVD CVE
CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th
CRITICAL
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC
CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability
CRITICAL
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f
CRITICAL
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CRITICAL
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe
CRITICAL
Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-23
NVD CVE
CVE-2026-31848: Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_p
CRITICAL
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is...
2026-03-20
NVD CVE
CVE-2026-33210: Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versi
CRITICAL
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information...
2026-03-20
NVD CVE
CVE-2026-33228: flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function
CRITICAL
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are...
2026-03-20
NVD CVE
CVE-2025-15608: This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient i
CRITICAL
This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that...
2026-03-19
NVD CVE
CVE-2006-10003: XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflo
CRITICAL
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.
In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at...
2026-03-19
CISA KEV
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that...
2026-03-18
NVD CVE
CVE-2025-15031: A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file
CRITICAL
A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables...
2026-03-18
NVD CVE
CVE-2026-27459: pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22
CRITICAL
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256...
2026-03-16
NVD CVE
CVE-2026-32640: SimpleEval is a library for adding evaluatable expressions into python projects.
CRITICAL
SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modules through to direct access inside the sandbox. If the objects...
2026-03-13
NVD CVE
CVE-2026-23941: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab
CRITICAL
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling.
This vulnerability is associated with program files...
2026-03-13
NVD CVE
CVE-2026-31806: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using...
2026-03-11
NVD CVE
CVE-2026-29515: MiCode FileExplorer contains an authentication bypass vulnerability in the embed
CRITICAL
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username...
2026-03-11
NVD CVE
CVE-2026-1524: An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to
CRITICAL
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions:
If a neo4j admin configures two or more OIDC providers...
2026-03-09
NVD CVE
CVE-2026-3823: EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Ov
CRITICAL
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
2026-03-06
NVD CVE
CVE-2026-28802: Authlib is a Python library which builds OAuth and OpenID Connect servers. From
CRITICAL
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was...
2026-03-06
NVD CVE
CVE-2026-29063: Immutable.js provides many Persistent Immutable data structures. Prior to versio
CRITICAL
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and...
2026-03-05
NVD CVE
CVE-2026-24457: An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0
CRITICAL
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the...
2026-03-04
NVD CVE
CVE-2025-66024: The XWiki blog application allows users of the XWiki platform to create and mana
CRITICAL
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post...
2026-03-04
NVD CVE
CVE-2026-27446: Missing Authentication for Critical Function (CWE-306) vulnerability in Apache A
CRITICAL
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an...