LIVE FEED
1796 events · 13 sources · newest first
Events in view
1796
all sources
Critical
1518
severity
Active sources
13
collectors
Last sync
2026-08-28 18:00
UTC
All sources
NVD CVE · 1796CISA KEV · 1686News · 435CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-15
NVD CVE
CVE-2026-15341: The User Session Synchronizer plugin for WordPress is vulnerable to Authenticati
CRITICAL
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on...
accounts-takeoverae-ivaes-256-cbcauthentication-bypasscapabilitycve-2026-15341encryptionmd5
2026-08-15
NVD CVE
CVE-2026-15826: The User Profile Builder plugin for WordPress is vulnerable to Authentication By
CRITICAL
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the...
absintadministrative-takeoverauthentication-bypasscve-2026-15826is-wp-errornoncenvd-cveregistration
2026-08-15
NVD CVE
CVE-2026-73041: SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt
CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the...
code-injectioncve-2026-73041data-validationendpoint-securitymalicious-markupmalware-executionnodejnvd-cve
2026-08-15
NVD CVE
CVE-2026-14484: The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress
CRITICAL
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions...
arbitrary-file-deletioncontact-form-7contact-form-7-pluginscve-2026-14484file-path-validationfiles-uploadnonce-exposuresnvd-cve
2026-08-15
NVD CVE
CVE-2026-15303: The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass
CRITICAL
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on...
6storage-rentalauthentication-bypasscve-2026-15303nvd-cvepluginsecurity-breachunauthenticated-attacksvulnerability
2026-08-15
NVD CVE
CVE-2026-73042: SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int
CRITICAL
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup...
code-executioncve-2026-73042electronhtml-injectionnodenvd-cvescript-executionsecurity-bulletin
2026-08-15
NVD CVE
CVE-2026-73044: SiYuan versions before v3.7.4 fail to validate or escape table column width valu
CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the...
api-injectionarbitrary-code-executioncross-site-scriptingcve-2026-73044electronevent-handlernode-integrationnvd-cve
2026-08-15
NVD CVE
CVE-2026-73046: SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t
CRITICAL
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace...
access-controlapi-securityauthenticationbrute-forcecve-2026-73046http-basic-authenticationkernel-accessesmiddleware
2026-08-15
NVD CVE
CVE-2026-73053: SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th
CRITICAL
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that...
arbitrary-code-executioncode-executioncross-site-scriptingcve-2026-73053document-iconhex-encodingnodenvd-cve
2026-08-15
NVD CVE
CVE-2026-73043: SiYuan versions before v3.7.4 contain a remote code execution vulnerability in t
CRITICAL
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers...
arbitrary-code-executioncve-2026-73043databases-vulnerabilitiesdesktop-clientgo-templatehtml-injectionjavascript-injectionmalicious-code
2026-08-15
NVD CVE
CVE-2026-73050: SiYuan versions before v3.7.4 fail to validate or escape the color field in attr
CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler...
arbitrary-javascriptattributes-viewcolor-fieldcross-site-scriptingcve-2026-73050database-injectionevent-handler-attributejavascript-execution
2026-08-15
NVD CVE
CVE-2026-73052: SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and
CRITICAL
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database...
attributes-viewcode-executioncve-2026-73052databases-fieldsdesktop-applicationsdesktop-clientfields-nameshtml-escaping
2026-08-14
NVD CVE
CVE-2026-17182: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass a
CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
authentication-bypasscve-2026-17182db2ibmimproper-validationnvd-cvepaths-segmentsremote-attackers
2026-08-14
NVD CVE
CVE-2026-17184: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute
CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
arbitrary-code-executioncve-2026-17184db2external-controlfile-path-traversalibmincident-responsenvd-cve
2026-08-14
NVD CVE
CVE-2026-17181: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write fi
CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
arbitrary-locationcve-2026-17181data-protectiondb2file-writeibmmirrornvd-cve
2026-08-14
NVD CVE
CVE-2026-17186: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute
CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
arbitrary-command-executioncl-commandcommand-injectioncve-2026-17186databases-vulnerabilitiesdb2i-seriesibm
2026-08-14
NVD CVE
CVE-2026-72826: The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scop
CRITICAL
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission()...
access-controlapi-keyapi-securityauthentication-bypassconfiguration-writecve-2026-72826grav-plugin-apigrav-plugins
2026-08-14
NVD CVE
CVE-2026-72830: Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in Con
CRITICAL
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can...
api-keyapi-pluginapi-securitycommand-injectionconfigcontrollerconfiguration-managementcve-2026-72830grav
2026-08-14
NVD CVE
CVE-2026-73678: MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated re
CRITICAL
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts...
apiarbitrary-code-executioncredentialcve-2026-73678endpointexecllmmind-platform
2026-08-14
NVD CVE
CVE-2026-12949: The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via I
CRITICAL
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function...
accounts-takeovercve-2026-12949data-authenticityinsufficient-verificationnvd-cveprivileges-escalationsecurity-bulletinunauthenticated-attacks
2026-08-13
NVD CVE
CVE-2026-72839: filebrowser through 2.63.16 fails to properly restrict scope and permissions whe
CRITICAL
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server...
access-controlcve-2026-72839default-settingsfile-managementfile-systemfilebrowserfiles-accessfiles-downloads
2026-08-13
NVD CVE
CVE-2026-72841: luci-app-openvpn fails to properly validate the instance_name2 parameter during
CRITICAL
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers...
authenticate-usercve-2026-72841files-uploadluci-apps-openvpnmalicious-payloadsnvd-cveopenvpnpath-traversal
2026-08-13
NVD CVE
CVE-2026-72842: luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privile
CRITICAL
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit...
acl-inconsistencyauthorization-checkscontainer-managementcve-2026-72842host-side-scriptlow-privileges-authenticate-userlucuses-apps-lxcnetwork-security
2026-08-13
NVD CVE
CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain una
CRITICAL
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
authenticationcve-2026-19297ibmlangflownvd-cveossremote-attackerssecurity
2026-08-13
NVD CVE
CVE-2026-72776: AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution v
CRITICAL
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected...
agenticseekapi-vulnerabilitiesbashinterpretercommand-injectioncors-misconfigurationcvecve-2026-72776host-level-compromise
2026-08-13
NVD CVE
CVE-2026-72851: Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability i
CRITICAL
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to...
automationbudibasecve-2026-72851data-modificationdatasourcedatum-exfiltrationexecutives-queriesjson
2026-08-13
NVD CVE
CVE-2026-19747: A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B
CRITICAL
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE...
attack-vectorscommand-injectioncve-2026-19747cybersecurityexploitnetwork-securitynetworks-devicesnvd-cve
2026-08-13
NVD CVE
CVE-2026-14525: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphe
CRITICAL
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
application-serverauthentication-bypasscve-2026-14525featureibmlibertynvd-cvertcomm-10
2026-08-13
NVD CVE
CVE-2026-17482: IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e
CRITICAL
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
cve-2026-17482documentationfile-pathibmibm-documentation-offlineimproper-controlnvd-cveremote-code-execution
2026-08-13
NVD CVE
CVE-2026-67614: CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the We
CRITICAL
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an...
authenticationcve-2026-67614cyberpanelfastapihard-coded-secretjwtnvd-cveremote-attacks
2026-08-13
NVD CVE
CVE-2026-72850: Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authe
CRITICAL
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .....
arbitrary-file-writeauthenticate-attacksauthenticationbudibasecloud-storagecve-2026-72850exportfile-traversal
2026-08-13
NVD CVE
CVE-2026-53791: rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that all
CRITICAL
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source...
access-controls-bypassallow-deny-rulecve-2026-53791daemonforged-source-addressip-spoofingnetwork-securitynvd-cve
2026-08-13
NVD CVE
CVE-2026-17197: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
client-asserted-identitycve-2026-17197ibmibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6
2026-08-13
NVD CVE
CVE-2026-73532: Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introdu
CRITICAL
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file...
administrator-accountbackdoorcve-2026-73532decommissionedfluent-forms-prosmalicious-codenvd-cvepersistent-file
2026-08-13
NVD CVE
CVE-2026-73533: Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introd
CRITICAL
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file...
administrator-accountbackdoorcve-2026-73533decommissionedmalicious-codeninja-table-pronvd-cvepersistent-file
2026-08-13
NVD CVE
CVE-2026-16815: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
cve-2026-16815denialibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6nvd-cve
2026-08-13
NVD CVE
CVE-2026-16867: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server reso
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
authenticate-userauthenticationcve-2026-16867ibm-iimproper-authenticationntlm-session-negotiationnvd-cveremote-attackers
2026-08-13
NVD CVE
CVE-2026-18249: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.
2026-08-13
NVD CVE
CVE-2026-18193: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
2026-08-13
NVD CVE
CVE-2026-17101: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.