LIVE FEED
1809 events · 13 sources · newest first
Events in view
1809
all sources
Critical
1530
severity
Active sources
13
collectors
Last sync
2026-08-29 18:00
UTC
All sources
NVD CVE · 1809CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-04-08
NVD CVE
CVE-2025-52221: Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm f
CRITICAL
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.
2026-04-08
NVD CVE
CVE-2026-39888: PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in pra
CRITICAL
PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted...
2026-04-08
NVD CVE
CVE-2026-39892: cryptography is a package designed to expose cryptographic primitives and recipe
CRITICAL
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g....
2026-04-08
NVD CVE
CVE-2026-31017: A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format fu
CRITICAL
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered...
2026-04-07
NVD CVE
CVE-2026-34582: Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implem
CRITICAL
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to...
2026-04-07
NVD CVE
CVE-2026-31789: Issue summary: Converting an excessively large OCTET STRING value to
a hexadecim
CRITICAL
Issue summary: Converting an excessively large OCTET STRING value to
a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.
Impact summary: A heap buffer overflow may lead to a crash or...
2026-04-07
NVD CVE
CVE-2026-39397: @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual
CRITICAL
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with...
2026-04-07
NVD CVE
CVE-2026-33439: Open Access Management (OpenAM) is an access management solution. Prior to 16.0.
CRITICAL
Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the...
2026-04-07
NVD CVE
CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t
CRITICAL
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run...
2026-04-07
NVD CVE
CVE-2026-34045: Podman Desktop is a graphical tool for developing on containers and Kubernetes.
HIGH
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger...
2026-04-07
NVD CVE
CVE-2026-28808: Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unaut
CRITICAL
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias.
When script_alias maps a URL prefix to a...
2026-04-07
NVD CVE
CVE-2026-39351: Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0,
CRITICAL
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.
2026-04-07
NVD CVE
CVE-2026-34078: Flatpak is a Linux application sandboxing and distribution framework. Prior to 1
CRITICAL
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths....
2026-04-07
NVD CVE
CVE-2026-39846: SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious no
CRITICAL
SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption...
2026-04-07
NVD CVE
CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire
CRITICAL
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some...
2026-04-06
NVD CVE
CVE-2026-35184: EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQ
CRITICAL
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.
2026-04-06
NVD CVE
CVE-2026-35459: pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.
CRITICAL
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to...
2026-04-06
NVD CVE
CVE-2026-35408: Directus is a real-time API and App dashboard for managing SQL database content.
HIGH
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without...
2026-04-06
NVD CVE
CVE-2026-34444: Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier,
CRITICAL
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This...
2026-04-06
NVD CVE
CVE-2026-35178: Workbench is a suite of tools for administrators and developers to interact with
CRITICAL
Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerability in the...
2026-04-06
NVD CVE
CVE-2026-35197: dye is a portable and respectful color library for shell scripts. Prior to 1.1.1
MEDIUM
dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and...
2026-04-05
NVD CVE
CVE-2019-25680: Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that
HIGH
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers...
2026-04-05
NVD CVE
CVE-2019-25700: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL...
2026-04-05
NVD CVE
CVE-2019-25698: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with...
2026-04-05
NVD CVE
A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipulation of the argument cwd can lead to unrestricted upload. The...
2026-04-05
NVD CVE
CVE-2019-25696: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements...
2026-04-05
NVD CVE
CVE-2026-5574: A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0
MEDIUM
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to...
2026-04-05
NVD CVE
CVE-2019-25688: Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted...
2026-04-05
NVD CVE
CVE-2019-25694: Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted...
2026-04-05
NVD CVE
CVE-2019-25692: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with...
2026-04-05
NVD CVE
CVE-2026-5584: A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the func
HIGH
A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py of the component query Endpoint. Such manipulation leads to code...
2026-04-05
NVD CVE
A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible...
2026-04-05
NVD CVE
CVE-2019-25674: CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated
HIGH
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php...
2026-04-05
NVD CVE
CVE-2026-5562: A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts t
HIGH
A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code...
2026-04-05
NVD CVE
CVE-2019-25676: Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerab
HIGH
Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags...
2026-04-05
NVD CVE
CVE-2026-5569: A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impac
HIGH
A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls....
2026-04-05
NVD CVE
CVE-2019-25704: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. Attackers can send crafted requests with...
2026-04-05
NVD CVE
CVE-2019-25702: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with...
2026-04-04
NVD CVE
CVE-2026-5526: A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/
HIGH
A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper...
2026-04-04
NVD CVE
CVE-2026-34955: PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSand
HIGH
PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.run() with shell=True and relies solely on string-pattern matching...