Skip to content
COOEY
LIVE FEED
1845 events · 13 sources · newest first
2026-08-18 NVD CVE
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
cve-2026-60990cvss-31cvss-99network-securitynvd-cveoracleoracle-fusionoracle-identity-manager-connector
2026-08-18 NVD CVE
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
availability-impactcompromiseconfidentiality-impactcve-2026-61258cvss-31cvss-98integrity-impactldap
2026-08-18 NVD CVE
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows...
availabilityconfidentialitycve-2026-61272cvss-31httpintegrityjd-edwardsjd-edwards-enterpriseone-tools
2026-08-18 NVD CVE
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation...
api-keys-theftcorrelationcross-site-scriptingcve-2026-75626event-handlerexternal-datahtml-escapemalicious-html
2026-08-18 NVD CVE
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in...
arbitrary-files-uploadcve-2026-15748executable-filefile-validationfiles-uploadforminatormime-typenvd-cve
2026-08-18 NVD CVE
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers...
administrative-controllerauthentication-bypassbastillioncontrollers-dispatcherscve-2026-75627fleet-controlmanaged-systemsmanagers-accounts
2026-08-18 NVD CVE
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated...
accounts-takeovercredentials-compromisecve-2026-18963email-verification-bypassidentity-and-access-managementkeycloakkeycloak-servicenvd-cve
2026-08-18 NVD CVE
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
browsers-vulnerabilitiescode-executioncve-2026-74936firefoxfirefox-esrfreejavascriptmemory-corruption
2026-08-18 NVD CVE
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74940firefoxfirefox-esrfreegraphic-text-componentmozillanvd-cvesecurity-patch
2026-08-18 NVD CVE
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74943firefoxfreegraphicimagelibmozillanvd-cvepatch
2026-08-18 NVD CVE
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
cve-2026-60995cvss-31cvss-99network-securitynvd-cveoracleoracle-fusionoracle-identity-manager-connector
2026-08-18 NVD CVE
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
confidentiality-impactcve-2026-61001cvss-31data-modificationhttpintegrity-impactlow-privileged-attackernetwork-access
2026-08-18 NVD CVE
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-61066cvss-31integritylow-privileged-attackernetwork-accessnvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low...
availability-impactcompromiseconfidentiality-impactcve-2026-61206cvss-31cvss-99https-vulnerabilityintegrity-impact
2026-08-18 NVD CVE
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to...
access-controlaccess-fieldsblueprintcore-groupcve-2026-75837delegated-adminsgravgrav-2-0-14
2026-08-18 NVD CVE
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument...
attack-surfacecf-n1-scgi-bincgi-interfacecomfastcve-2026-75094networks-devicesnvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
confidentiality-impactcritical-datacve-2026-62610cvss-31data-compromisehttpintegrity-impactnetwork-access
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low...
2026-08-18 NVD CVE
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and...
api-accessesawxcredentials-theftcve-2026-12564database-credentialsdjangohashicorphashicorp-vault
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62614cvss-31httpintegritynetwork-accessnvd-cve
2026-08-18 NVD CVE
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the...
buffer-overflowcve-2026-75784cybersecurityhttps-header-handlernetwork-securitynginxnvd-cvepublic-exploit
2026-08-18 NVD CVE
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv...
arbitrary-file-writeargument-injectionbashrccode-executioncodewhalecodewhale-tuicve-2026-75913git-show
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availability-impactconfidentiality-impactcorbacve-2026-62634cvss-31cvss-98integrity-impactnetwork-access
2026-08-18 NVD CVE
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74944domdom-corefirefoxfreehtml-componentmozillanvd-cve
2026-08-18 NVD CVE
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
cve-2026-62629data-compromisedata-creationdata-deletiondata-modificationdata-readdosdose-attack
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62630cvss-31integritynetwork-accessnvd-cveoracle-fusion-middleware
2026-08-18 NVD CVE
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with...
cryptographic-securitycryptographic-vulnerabilitiescve-2026-74889entropy-extractionhkdfkey-derivationmulti-targets-attacknvd-cve
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default...
attackercve-2026-74891data-breachesdatabase-credentialsdefault-credentialshardcoded-credentialnetwork-securitynvd-cve
2026-08-17 NVD CVE
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the...
administrative-credentialscertificates-signing-requestcsrcve-2026-66795hub-clustermaliciouses-csrmanagedcluster-import-controllernvd-cve
2026-08-17 NVD CVE
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public...
authentication-bypassauthorization-headerbearer-tokencve-2026-74894keys-enumerationkeys-revocationnvd-cveopenssl
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass...
arbitrary-code-executionast-analyzercve-2026-74886dangerous-moduleencodingimportlibmultiprocessingnvd-cve
2026-08-17 NVD CVE
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem,...
cve-2026-74895default-process-isolationfilesystem-accessesmalicious-pluginsnetwork-accessnvd-cveopensslplugin-execution
2026-08-17 NVD CVE
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements....
acm-search-v2-rhel9arbitrary-code-executionauthenticationcode-executioncommand-injectioncve-2026-71472nvd-cvepostgresql
2026-08-17 NVD CVE
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations....
cloud-securitycluster-resourcecrafted-annotationscve-2026-66792kubernetemanaged-clustermulticloud-operators-subscriptionnamespace
2026-08-17 NVD CVE
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other...
answer-endpointcve-2026-75106data-integritydatum-exfiltrationdefaults-salteditable-submissionshashes-computationshashid
◀ PREV PAGE 05 / 47 NEXT ▶