Skip to content
COOEY
LIVE FEED
1516 events · 13 sources · newest first
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
aixauthenticationcommand-injectioncve-2026-18835ibmnvd-cveoperating-systemspowervm
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
aixcve-2026-16926enterprise-softwarefiles-overwriteibminput-validationnvd-cveoperating-systems
2026-08-20 NVD CVE
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The...
cluster-compromisecluster-securitycustom-resourcecve-2026-67567helm-charthelmreleasemulticloud-operators-subscriptionnvd-cve
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
aixbuffer-overflowcve-2026-17040ibmnvd-cvepowervmremote-code-executionsecurity
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
aixarbitrary-code-executioncve-2026-17122ibmnvd-cvepowervmremote-attackerssecurity-bulletin
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
aixcve-2026-17136format-string-vulnerabilityibmibm-aixibm-powervmnvd-cvepowervm
2026-08-20 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
aixarbitrary-code-executioncve-2026-17157ibmnvd-cvepowervmremote-attackerssecurity-bulletin
2026-08-20 NVD CVE
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
azureazure-arcscve-2026-65816incident-responsemicrosoftnetwork-securitynvd-cveprivileges-escalation
2026-08-19 NVD CVE
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes...
buffer-overflowcgi-bincve-2026-75976exploitnetwork-attached-storagenvd-cvenvrremote-attacks
2026-08-19 NVD CVE
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based...
cve-2026-76003nvd-cveremote-attacksstack-based-buffer-overflowstrcpyuttutt-hyper-1200gwutt-hypers
2026-08-19 NVD CVE
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT...
authenticationcudycve-2026-71960firmwarehmacjwtmesh-networkingmosquitto
2026-08-19 NVD CVE
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and...
authentication-bypassauthorization-bypasscluster-compromisecluster-proxy-addoncve-2026-66794information-disclosureinternal-service-accesskubernete
2026-08-19 NVD CVE
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including,...
accounts-takeoverauthorization-bypasscve-2026-18315emails-overwritelost-password-flownvd-cveplugins-vulnerabilitiessecurity-vulnerability
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session...
authorization-boundariescve-2026-76312dispatches-archivesembedded-reportshtml-sourcenvd-cvereport-managementsearch-job-data
2026-08-19 NVD CVE
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack...
buffer-overflowcvecve-2026-76589firmware-vulnerabilitiesnetwork-adapternetwork-securitynvd-cveremote-attacks
2026-08-19 NVD CVE
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument...
cgi-bincve-2026-76590nvd-cvepppoepublicly-available-exploitremote-exploitsecurity-bulletinssi
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed...
authorization-flowcve-2026-76311dispatches-archivesembedded-reportsnvd-cvereport-managementscheduled-reportssecurity-configuration
2026-08-19 NVD CVE
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC)...
certificates-signing-requestcluster-administratorsclusterrolecve-2026-70496excessive-privilegeimpersonationkubernetemanifestwork
2026-08-19 NVD CVE
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
aixarbitrary-code-executioncve-2026-16919ibmimproper-validationnetwork-supplied-pointernvd-cvepowervm
2026-08-19 NVD CVE
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material,...
administrative-actionscve-2026-76310embedded-reportsnvd-cvereport-managementrest-apirole-based-accesssessions-materials
2026-08-18 NVD CVE
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker...
2026-08-18 NVD CVE
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows...
availabilityconfidentialitycve-2026-70954cvss-31cvss-98dynamo-application-frameworkhttpintegrity
2026-08-18 NVD CVE
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
nvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
availability-impactcontent-acquisition-systemscve-2026-70976cvss-31data-creationdata-deletiondata-modificationdos
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-70926cvss-31cvss-98integritynetwork-access
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availability-impactcompromiseconfidentiality-impactcve-2026-62611cvss-31cvss-98iiopintegrity-impact
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
browsers-vulnerabilitiescode-executioncve-2026-74936firefoxfirefox-esrfreejavascriptmemory-corruption
2026-08-18 NVD CVE
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74944domdom-corefirefoxfreehtml-componentmozillanvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
confidentiality-impactcritical-data-accesscve-2026-62613cvss-31data-compromiseintegrity-impactmiddleware-vulnerabilitiesnvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low...
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
confidentiality-impactcritical-datacve-2026-62610cvss-31data-compromisehttpintegrity-impactnetwork-access
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise...
2026-08-18 NVD CVE
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
availability-impactcve-2026-70977cvss-31data-creationdata-deletiondata-modificationdosdose-attack
◀ PREV PAGE 03 / 38 NEXT ▶