LIVE FEED
1516 events · 13 sources · newest first
Events in view
1516
all sources
Critical
1516
severity
Active sources
13
collectors
Last sync
2026-08-28 12:00
UTC
All sources
NVD CVE · 1794CISA KEV · 1686News · 424CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-18
NVD CVE
CVE-2026-60995: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
cve-2026-60995cvss-31cvss-99network-securitynvd-cveoracleoracle-fusionoracle-identity-manager-connector
2026-08-18
NVD CVE
CVE-2026-61272: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards
CRITICAL
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows...
availabilityconfidentialitycve-2026-61272cvss-31httpintegrityjd-edwardsjd-edwards-enterpriseone-tools
2026-08-18
NVD CVE
CVE-2026-62457: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle
CRITICAL
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows...
2026-08-18
NVD CVE
CVE-2026-75626: SpiderFoot fails to HTML-escape correlation titles built from external scan data
CRITICAL
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation...
api-keys-theftcorrelationcross-site-scriptingcve-2026-75626event-handlerexternal-datahtml-escapemalicious-html
2026-08-18
NVD CVE
CVE-2026-75627: Bastillion fails to properly validate request URI paths in its controller dispat
CRITICAL
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers...
administrative-controllerauthentication-bypassbastillioncontrollers-dispatcherscve-2026-75627fleet-controlmanaged-systemsmanagers-accounts
2026-08-18
NVD CVE
CVE-2026-12564: A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The
CRITICAL
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and...
api-accessesawxcredentials-theftcve-2026-12564database-credentialsdjangohashicorphashicorp-vault
2026-08-18
NVD CVE
CVE-2026-74940: Use-after-free in the Graphics: Text component. This vulnerability was fixed in
CRITICAL
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74940firefoxfirefox-esrfreegraphic-text-componentmozillanvd-cvesecurity-patch
2026-08-18
NVD CVE
CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was
CRITICAL
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
browsers-vulnerabilitiescode-executioncve-2026-74936firefoxfirefox-esrfreejavascriptmemory-corruption
2026-08-18
NVD CVE
CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed
CRITICAL
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74943firefoxfreegraphicimagelibmozillanvd-cvepatch
2026-08-18
NVD CVE
CVE-2026-60977: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CRITICAL
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable...
availability-impactconfidentiality-impactcve-2026-60977cvss-31integrity-impactnetwork-accessnvd-cveoracle
2026-08-18
NVD CVE
CVE-2026-61001: Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middle
CRITICAL
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
confidentiality-impactcve-2026-61001cvss-31data-modificationhttpintegrity-impactlow-privileged-attackernetwork-access
2026-08-18
NVD CVE
CVE-2026-61003: Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middl
CRITICAL
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
availability-impactconfidentiality-impactcve-2026-61003cvss-31data-breachesiiop-protocolintegrity-impactnetworks-vulnerabilities
2026-08-18
NVD CVE
CVE-2026-61206: Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyper
CRITICAL
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low...
availability-impactcompromiseconfidentiality-impactcve-2026-61206cvss-31cvss-99https-vulnerabilityintegrity-impact
2026-08-18
NVD CVE
CVE-2026-61241: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa
CRITICAL
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
availability-impactcompromiseconfidentiality-impactcve-2026-61241cvss-100cvss-31integrity-impactldap
2026-08-18
NVD CVE
CVE-2026-75094: A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_
CRITICAL
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument...
attack-surfacecf-n1-scgi-bincgi-interfacecomfastcve-2026-75094networks-devicesnvd-cve
2026-08-18
NVD CVE
CVE-2026-15748: The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload
CRITICAL
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in...
arbitrary-files-uploadcve-2026-15748executable-filefile-validationfiles-uploadforminatormime-typenvd-cve
2026-08-18
NVD CVE
CVE-2026-62539: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle
CRITICAL
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18
NVD CVE
CVE-2026-62541: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle
CRITICAL
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable...
2026-08-18
NVD CVE
CVE-2026-62610: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
confidentiality-impactcritical-datacve-2026-62610cvss-31data-compromisehttpintegrity-impactnetwork-access
2026-08-18
NVD CVE
CVE-2026-62582: Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyper
CRITICAL
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low...
2026-08-18
NVD CVE
CVE-2026-75837: Grav before 2.0.14 fails to guard the access field in the core group blueprint w
CRITICAL
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to...
access-controlaccess-fieldsblueprintcore-groupcve-2026-75837delegated-adminsgravgrav-2-0-14
2026-08-18
NVD CVE
CVE-2026-62609: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-75913: CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an
CRITICAL
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv...
arbitrary-file-writeargument-injectionbashrccode-executioncodewhalecodewhale-tuicve-2026-75913git-show
2026-08-18
NVD CVE
CVE-2026-62614: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62614cvss-31httpintegritynetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-18963: A flaw was found in the reset-credentials flow of the keycloak-services componen
CRITICAL
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated...
accounts-takeovercredentials-compromisecve-2026-18963email-verification-bypassidentity-and-access-managementkeycloakkeycloak-servicenvd-cve
2026-08-18
NVD CVE
CVE-2026-62634: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availability-impactconfidentiality-impactcorbacve-2026-62634cvss-31cvss-98integrity-impactnetwork-access
2026-08-18
NVD CVE
CVE-2026-75784: A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this
CRITICAL
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the...
buffer-overflowcve-2026-75784cybersecurityhttps-header-handlernetwork-securitynginxnvd-cvepublic-exploit
2026-08-18
NVD CVE
CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i
CRITICAL
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
cve-2026-74944domdom-corefirefoxfreehtml-componentmozillanvd-cve
2026-08-18
NVD CVE
CVE-2026-62629: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
cve-2026-62629data-compromisedata-creationdata-deletiondata-modificationdata-readdosdose-attack
2026-08-18
NVD CVE
CVE-2026-62630: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
availabilityconfidentialitycve-2026-62630cvss-31integritynetwork-accessnvd-cveoracle-fusion-middleware
2026-08-18
NVD CVE
CVE-2026-62638: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
2026-08-17
NVD CVE
CVE-2026-74891: openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in
CRITICAL
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default...
attackercve-2026-74891data-breachesdatabase-credentialsdefault-credentialshardcoded-credentialnetwork-securitynvd-cve
2026-08-17
NVD CVE
CVE-2026-66795: A flaw was found in the managedcluster-import-controller. The Certificate Signin
CRITICAL
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the...
administrative-credentialscertificates-signing-requestcsrcve-2026-66795hub-clustermaliciouses-csrmanagedcluster-import-controllernvd-cve
2026-08-17
NVD CVE
CVE-2026-74894: openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in
CRITICAL
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public...
authentication-bypassauthorization-headerbearer-tokencve-2026-74894keys-enumerationkeys-revocationnvd-cveopenssl
2026-08-17
NVD CVE
CVE-2026-74880: openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query paramet
CRITICAL
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP...
attackerbrowser-historycve-2026-74880https-referer-headerskeyservernvd-cveopensslopenssl-encrypt
2026-08-17
NVD CVE
CVE-2026-74889: openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info para
CRITICAL
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with...
cryptographic-securitycryptographic-vulnerabilitiescve-2026-74889entropy-extractionhkdfkey-derivationmulti-targets-attacknvd-cve
2026-08-17
NVD CVE
CVE-2026-74895: openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the
CRITICAL
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem,...
cve-2026-74895default-process-isolationfilesystem-accessesmalicious-pluginsnetwork-accessnvd-cveopensslplugin-execution
2026-08-17
NVD CVE
CVE-2026-71472: A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authentica
CRITICAL
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements....
acm-search-v2-rhel9arbitrary-code-executionauthenticationcode-executioncommand-injectioncve-2026-71472nvd-cvepostgresql
2026-08-17
NVD CVE
CVE-2026-74886: openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerabil
CRITICAL
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass...
arbitrary-code-executionast-analyzercve-2026-74886dangerous-moduleencodingimportlibmultiprocessingnvd-cve
2026-08-17
NVD CVE
CVE-2026-66792: A flaw was found in the multicloud-operators-subscription component. This vulner
CRITICAL
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations....
cloud-securitycluster-resourcecrafted-annotationscve-2026-66792kubernetemanaged-clustermulticloud-operators-subscriptionnamespace