LIVE FEED
1809 events · 13 sources · newest first
Events in view
1809
all sources
Critical
1530
severity
Active sources
13
collectors
Last sync
2026-08-29 18:00
UTC
All sources
NVD CVE · 1809CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-06-04
NVD CVE
CVE-2026-48040: The netty incubator codec.bhttp is a java language binary http parser. The libra
CRITICAL
The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses for...
2026-06-04
NVD CVE
CVE-2026-50208: High-risk TrustAllCerts routines disable standard TLS certificate validation. Co
CRITICAL
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
2026-06-04
NVD CVE
CVE-2026-49191: The production build of the M3WebServer hard-codes its backend API keys, which c
CRITICAL
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
2026-06-04
NVD CVE
CVE-2026-49188: The ai_cmd utility executes with full root permissions. It pipes socket inputs d
CRITICAL
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
2026-06-04
NVD CVE
CVE-2026-49186: The local MQTT broker does not enforce topic-level Access Control Lists (ACLs).
CRITICAL
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
2026-06-04
NVD CVE
CVE-2026-49185: The FieldX MDM adb messaging topic passes unverified payloads directly into Runt
CRITICAL
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
2026-06-04
NVD CVE
CVE-2026-48567: Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized atta
CRITICAL
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
2026-06-04
NVD CVE
CVE-2026-50225: The registration path /v1/account/register provides no bot mitigation mechanisms
CRITICAL
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
2026-06-04
NVD CVE
CVE-2026-50214: The /v1/Plan service relies entirely on a shared global API token for full admin
CRITICAL
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
2026-06-04
NVD CVE
CVE-2026-50211: Leftover engineering diagnostics and factory-level diagnostic software remain ex
CRITICAL
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
2026-06-03
NVD CVE
CVE-2026-5241: A vulnerability in the LightGlue model loading path of huggingface/transformers
CRITICAL
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises...
2026-06-02
NVD CVE
CVE-2026-42074: OpenClaude is an open-source coding-agent command line interface for cloud and l
CRITICAL
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema,...
2026-06-02
NVD CVE
CVE-2026-35482: alf.io is an open source ticket reservation system for conferences, trade shows,
HIGH
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an...
2026-06-02
NVD CVE
CVE-2026-10611: An authentication bypass vulnerability exists in MISP when LDAP mixed authentica
CRITICAL
An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users...
2026-06-01
NVD CVE
CVE-2026-44825: Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab
HIGH
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster...
2026-06-01
NVD CVE
CVE-2026-22872: Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsul
CRITICAL
Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this...
2026-06-01
NVD CVE
CVE-2026-49121: AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated rem
HIGH
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote...
2026-05-29
NVD CVE
CVE-2025-41270: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41272: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2026-45700: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c,...
2026-05-29
NVD CVE
CVE-2025-41273: Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Altern
CRITICAL
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote...
2026-05-29
NVD CVE
CVE-2025-41274: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41275: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41276: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2025-41277: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-29
NVD CVE
CVE-2026-10060: A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the
MEDIUM
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection....
2026-05-29
NVD CVE
CVE-2026-10061: A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the functi
MEDIUM
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be...
2026-05-29
NVD CVE
CVE-2026-46376: FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, una
CRITICAL
FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not...
2026-05-29
NVD CVE
CVE-2026-10062: A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this
HIGH
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes...
2026-05-29
NVD CVE
CVE-2026-10063: A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this
HIGH
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer...
2026-05-29
NVD CVE
CVE-2026-49200: The acer_cgi.log file in the device firmware is accessible without authenticatio
CRITICAL
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
2026-05-29
NVD CVE
CVE-2026-49199: Crafted MQTT messages can trigger command injection, resulting in root-level cod
CRITICAL
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
2026-05-29
NVD CVE
CVE-2026-10064: A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects
MEDIUM
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name results in...
2026-05-29
NVD CVE
CVE-2026-48501: GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub
HIGH
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh...
2026-05-29
NVD CVE
CVE-2026-49197: Web endpoints intended for the Acer Connect app improperly validate the HTTP Aut
CRITICAL
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.
2026-05-29
NVD CVE
CVE-2026-49201: The upload.cgi binary, responsible for processing device backups, contains a har
CRITICAL
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
2026-05-29
NVD CVE
CVE-2025-41268: Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Adminis
CRITICAL
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete...
2026-05-29
NVD CVE
CVE-2025-41269: Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CRITICAL
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0...
2026-05-28
NVD CVE
CVE-2026-4408: A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S
CRITICAL
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u...
2026-05-28
NVD CVE
CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote
CRITICAL
Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)