LIVE FEED
228 events · 13 sources · newest first
Events in view
228
all sources
Critical
0
severity
Active sources
13
collectors
Last sync
2026-08-28 12:00
UTC
All sources
NVD CVE · 1794CISA KEV · 1686News · 424CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-06-09
NVD CVE
CVE-2026-47929: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Aut
HIGH
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker...
2026-06-04
NVD CVE
CVE-2026-50292: In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unesca
HIGH
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
2026-06-02
NVD CVE
CVE-2026-35482: alf.io is an open source ticket reservation system for conferences, trade shows,
HIGH
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an...
2026-06-01
NVD CVE
CVE-2026-44825: Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab
HIGH
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster...
2026-06-01
NVD CVE
CVE-2026-49121: AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated rem
HIGH
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote...
2026-05-29
NVD CVE
CVE-2026-10063: A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this
HIGH
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer...
2026-05-29
NVD CVE
CVE-2026-10062: A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this
HIGH
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes...
2026-05-29
NVD CVE
CVE-2026-48501: GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub
HIGH
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh...
2026-05-26
NVD CVE
CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
HIGH
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
2026-05-26
NVD CVE
CVE-2026-24212: NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive infor
HIGH
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,...
2026-05-26
NVD CVE
CVE-2026-44966: Velocity.js is a JavaScript implementation of the Apache Velocity template engin
HIGH
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of...
2026-05-26
NVD CVE
CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
HIGH
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
2026-05-21
NVD CVE
CVE-2026-4858: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.
HIGH
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API...
2026-05-20
NVD CVE
CVE-2026-24163: NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where a
HIGH
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of...
2026-05-20
NVD CVE
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1.
BIND 9 versions...
2026-05-20
NVD CVE
CVE-2026-24425: Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerabi
HIGH
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to...
2026-05-20
NVD CVE
CVE-2026-24213: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher
HIGH
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data...
2026-05-20
NVD CVE
CVE-2025-33255: NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an
HIGH
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of...
2026-05-20
NVD CVE
CVE-2026-24214: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher
HIGH
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering,...
2026-05-20
NVD CVE
CVE-2026-24206: NVIDIA Triton Inference Server contains a vulnerability where an attacker could
HIGH
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or...
2026-05-19
NVD CVE
CVE-2026-47311: Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows
HIGH
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
2026-05-19
NVD CVE
CVE-2026-47314: Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflo
HIGH
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
2026-05-19
NVD CVE
CVE-2026-47310: Use after free vulnerability in Samsung Open Source Escargot allows Pointer Mani
HIGH
Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
2026-05-19
NVD CVE
CVE-2026-8711: NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is config
HIGH
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the...
2026-05-13
NVD CVE
CVE-2026-42584: Netty is an asynchronous, event-driven network application framework. Prior to 4
HIGH
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response,...
2026-05-13
NVD CVE
CVE-2026-42579: Netty is an asynchronous, event-driven network application framework. Prior to 4
HIGH
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding....
2026-05-12
NVD CVE
CVE-2026-27851: When safe filter is used with variable expansion, all following pipelines on the
HIGH
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks...
2026-05-11
NVD CVE
CVE-2026-43639: Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerabili
HIGH
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST...
2026-05-09
NVD CVE
CVE-2026-6665: The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strl
HIGH
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM...
2026-05-08
NVD CVE
CVE-2026-42264: Axios is a promise based HTTP client for the browser and Node.js. From version 1
HIGH
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP...
2026-05-08
NVD CVE
CVE-2026-42556: Postiz is an AI social media scheduling tool. From version 2.21.6 to before vers
HIGH
Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request...
2026-05-07
NVD CVE
CVE-2026-42010: A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adlem
HIGH
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit...
2026-04-30
NVD CVE
CVE-2026-33845: A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero len
HIGH
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is...
2026-04-24
NVD CVE
CVE-2026-42043: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.
HIGH
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than...
2026-04-17
NVD CVE
CVE-2026-40518: ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary
HIGH
ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply...
2026-04-14
NVD CVE
CVE-2026-2332: In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when ch
HIGH
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
* https://w4ke.info/2025/06/18/funky-chunks.html
...
2026-04-14
NVD CVE
CVE-2026-35589: nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site
HIGH
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete...
2026-04-13
NVD CVE
CVE-2026-5936: An attacker can control a server-side HTTP request by supplying a crafted URL, c
HIGH
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services,...
2026-04-12
NVD CVE
CVE-2026-40393: In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occu
HIGH
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
2026-04-10
NVD CVE
CVE-2026-5483: A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in
HIGH
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a...