LIVE FEED
1524 events · 13 sources · newest first
Events in view
1524
all sources
Critical
1524
severity
Active sources
13
collectors
Last sync
2026-08-29 12:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-03-24
NVD CVE
CVE-2026-33211: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style
CRITICAL
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is...
2026-03-24
NVD CVE
CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f
CRITICAL
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f
CRITICAL
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CRITICAL
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe
CRITICAL
Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-33195: Active Storage allows users to attach cloud and local files in Rails application
CRITICAL
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved...
2026-03-24
NVD CVE
CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th
CRITICAL
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC
CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability
CRITICAL
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-23
NVD CVE
CVE-2026-31848: Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_p
CRITICAL
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is...
2026-03-20
NVD CVE
CVE-2026-33228: flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function
CRITICAL
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are...
2026-03-20
NVD CVE
CVE-2025-15608: This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient i
CRITICAL
This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that...
2026-03-20
NVD CVE
CVE-2026-33210: Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versi
CRITICAL
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information...
2026-03-19
NVD CVE
CVE-2006-10003: XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflo
CRITICAL
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.
In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at...
2026-03-18
NVD CVE
CVE-2026-27459: pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22
CRITICAL
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256...
2026-03-18
NVD CVE
CVE-2025-15031: A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file
CRITICAL
A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables...
2026-03-16
NVD CVE
CVE-2026-32640: SimpleEval is a library for adding evaluatable expressions into python projects.
CRITICAL
SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modules through to direct access inside the sandbox. If the objects...
2026-03-13
NVD CVE
CVE-2026-23941: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab
CRITICAL
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling.
This vulnerability is associated with program files...
2026-03-13
NVD CVE
CVE-2026-31806: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using...
2026-03-11
NVD CVE
CVE-2026-29515: MiCode FileExplorer contains an authentication bypass vulnerability in the embed
CRITICAL
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username...
2026-03-11
NVD CVE
CVE-2026-1524: An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to
CRITICAL
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions:
If a neo4j admin configures two or more OIDC providers...
2026-03-09
NVD CVE
CVE-2026-3823: EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Ov
CRITICAL
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
2026-03-06
NVD CVE
CVE-2026-28802: Authlib is a Python library which builds OAuth and OpenID Connect servers. From
CRITICAL
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was...
2026-03-06
NVD CVE
CVE-2026-29063: Immutable.js provides many Persistent Immutable data structures. Prior to versio
CRITICAL
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and...
2026-03-05
NVD CVE
CVE-2026-24457: An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0
CRITICAL
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the...
2026-03-04
NVD CVE
CVE-2026-27446: Missing Authentication for Critical Function (CWE-306) vulnerability in Apache A
CRITICAL
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an...
2026-03-04
NVD CVE
CVE-2025-66024: The XWiki blog application allows users of the XWiki platform to create and mana
CRITICAL
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post...
2026-03-02
NVD CVE
CVE-2026-23600: A remote authentication bypass vulnerability
exists in HPE AutoPass License S
CRITICAL
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
2026-02-27
NVD CVE
CVE-2026-2293: A NestJS application using @nestjs/platform-fastify can allow bypass of authenti
CRITICAL
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled.
This issue affects nest.Js: 11.1.13.
2026-02-27
NVD CVE
CVE-2026-21660: A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext
CRITICAL
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of...
2026-02-27
NVD CVE
CVE-2026-28517: openDCIM version 23.04, through commit 4467e9c4, contains an OS command injectio
CRITICAL
openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it...
2026-02-25
NVD CVE
CVE-2026-27577: n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.
CRITICAL
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An...
2026-02-25
NVD CVE
CVE-2026-27727: mchange-commons-java, a library that provides Java utilities, includes code that
CRITICAL
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be...
2026-02-25
NVD CVE
CVE-2026-27606: Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and
CRITICAL
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path...
2026-02-25
NVD CVE
CVE-2026-27148: Storybook is a frontend workshop for building user interface components and page
CRITICAL
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to...
2026-02-24
NVD CVE
CVE-2026-2797: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
CRITICAL
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was f
CRITICAL
Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component i
CRITICAL
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixe
CRITICAL
Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2774: Integer overflow in the Audio/Video component. This vulnerability was fixed in F
CRITICAL
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.