LIVE FEED
1601 events · 13 sources · newest first
Events in view
1601
all sources
Critical
0
severity
Active sources
13
collectors
Last sync
2026-08-28 12:00
UTC
All sources
NVD CVE · 1794CISA KEV · 1686News · 424CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-27
NVD CVE
CVE-2026-45623: PostCSS takes a CSS file and provides an API to analyze and modify its rules by
HIGH
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH...
2026-07-27
CISA KEV
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may...
aristaavailabilitycisa-kevcommand-injectionconfidentialitycve-2026-16812data-compromiseintegrity
2026-07-27
NVD CVE
CVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal reque
HIGH
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
access-controlauthentication-weaknessescompliance-riskcve-2026-66014internal-requests-processingjfrog-artifactorynvd-cveprivileges-escalation
2026-07-23
NVD CVE
CVE-2026-64815: In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible v
HIGH
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
arbitrary-code-injectioncode-injectioncve-2026-64815cybersecuritydevelopers-toolsform-fileintellij-ideajetbrain
2026-07-23
NVD CVE
CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in
HIGH
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd-cve
2026-07-23
NVD CVE
CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue a
HIGH
Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
authentication-bypasscisacmmc-level-2cve-2026-10697datum-exfiltrationdodfedramp-authorizationimproper-authentication
2026-07-23
NVD CVE
CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s
HIGH
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
2026-07-23
NVD CVE
CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This
HIGH
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
cisacmmc-level-2compliancecve-2026-15967defense-industrial-basedodfedramp-authorizationincident-response
2026-07-22
CISA KEV
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...
administrative-privilegescheck-pointcisa-kevcve-2026-16232improper-authentication-vulnerabilityremote-attacks
2026-07-22
CISA KEV
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
code-executioncve-2026-50522deserializationmicrosoftmicrosoft-officenetwork-securitynvd-cvesharepoint
2026-07-21
NVD CVE
CVE-2026-56820: Netty is a network application framework for development of protocol servers and
HIGH
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the...
2026-07-21
CISA KEV
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain...
cisa-kevcve-2026-60137cve-2026-63030cybersecurityinformation-securityplugins-vulnerabilitiesremote-code-executionsoftware-vulnerabilities
2026-07-21
CISA KEV
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
buffer-overflowcisa-kevcode-executioncve-2021-27137cybersecuritydd-wrtinformation-securitynetworks-devices
2026-07-21
CISA KEV
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
arbitrary-code-executioncisa-kevcve-2026-0770cybersecurityfunctionalityinclusionlangflowremote-attacks
2026-07-21
CISA KEV
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
cisa-kevcve-2026-60137cve-2026-63030cybersecurityremote-code-executionsoftware-vulnerabilitiessql-injectionvulnerability
2026-07-20
NVD CVE
CVE-2026-41521: xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer
HIGH
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send...
2026-07-20
NVD CVE
CVE-2026-12341: This vulnerability
impacts all versions of IdentityIQ and allows an unauthentica
HIGH
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
2026-07-20
NVD CVE
CVE-2026-28220: Wazuh is a free and open source platform used for threat prevention, detection,
HIGH
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to...
2026-07-18
NVD CVE
CVE-2026-15631: Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail
HIGH
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
2026-07-18
NVD CVE
CVE-2026-16158: Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 b
HIGH
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source...
2026-07-17
NVD CVE
CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
HIGH
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems...
agent-componentapi-v1code-act-agentcsv-agentcve-2026-13448denialflow-idibm
2026-07-17
NVD CVE
CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
HIGH
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker...
2026-07-16
CISA KEV
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
cisa-kevcommand-injectioncve-2026-39808fortinetfortisandboxhttps-requestsos-command-injectionsecurity-vulnerability
2026-07-16
CISA KEV
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
cisa-kevcloud-platformcloud-securitycommand-injectioncrafted-requestscve-2026-25089fortinetfortisandbox
2026-07-16
CISA KEV
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
attack-vectorscode-executioncve-2026-58644datum-exfiltrationdeserializationexploitmicrosoftmicrosoft-office
2026-07-15
CISA KEV
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...
cisa-kevcompromisecve-2026-46817e-business-suitehttpimproper-privileges-managementnetwork-accessoracle
2026-07-15
NVD CVE
CVE-2026-56398: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in
HIGH
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header,...
accounts-takeoverauthentication-token-theftcontent-typescross-site-scriptingcve-2026-56398datum-urifile-extensioninline-disposition
2026-07-15
NVD CVE
CVE-2026-20157: As part of Cisco's ongoing commitment to proactive security and product quality,
HIGH
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-15
CISA KEV
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security...
account-lockoutattackerbcuses-keycisa-kevcve-2023-4346device-purgeknx-protocolknxes-association
2026-07-15
NVD CVE
CVE-2026-56400: open-webui before 0.3.14 contains a cross-origin resource sharing misconfigurati
HIGH
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute...
admins-usersapi-endpointarbitrary-code-executionattackers-controlled-websitesauthenticate-requestscross-origin-resources-sharingcross-site-requestcve-2026-56400
2026-07-15
NVD CVE
CVE-2026-20156: As part of Cisco's ongoing commitment to proactive security and product quality,
HIGH
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-14
CISA KEV
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
appliancecisa-kevcve-2026-15409cybersecuritydatum-exfiltrationfirewalls-vulnerabilitiesnetwork-securityremote-code-execution
2026-07-14
NVD CVE
CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unautho
HIGH
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-48320: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
HIGH
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control...
coldfusioncross-site-scriptingcve-2026-48320elevated-accessmalicious-scriptsnvd-cvereflecteds-xsssession-control
2026-07-14
NVD CVE
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14
NVD CVE
CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized
HIGH
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
2026-07-14
NVD CVE
CVE-2026-47988: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
HIGH
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47988exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14
NVD CVE
CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau
HIGH
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to
HIGH
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-58617: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized
HIGH
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.