LIVE FEED
1518 events · 13 sources · newest first
Events in view
1518
all sources
Critical
1518
severity
Active sources
13
collectors
Last sync
2026-08-28 18:00
UTC
All sources
NVD CVE · 1796CISA KEV · 1686News · 435CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-11
NVD CVE
CVE-2026-62893: Use after free in Windows Deployment Services allows an unauthorized attacker to
CRITICAL
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-62893freeincident-responsenetworks-attacksnvd-cvepatch-managementremote-code-execution
2026-08-11
NVD CVE
CVE-2026-62878: Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to ex
CRITICAL
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-62878dns-securityexploitnetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-08-11
NVD CVE
CVE-2026-71398: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to...
adobeadobe-campaign-classicarbitrary-code-executioncve-2026-71398incorrect-authorizationnvd-cvesecurityvulnerability
2026-08-11
NVD CVE
CVE-2026-62815: Use after free in Microsoft QUIC allows an unauthorized attacker to execute code
CRITICAL
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
attackercode-executioncve-2026-62815exploitfreemicrosoftnetwork-securitynvd-cve
2026-08-11
NVD CVE
CVE-2026-70306: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcve-2026-70306inputs-neutralizationmicrosoftnetwork-securitynvd-cvesharepointspoofing
2026-08-11
NVD CVE
CVE-2026-10579: A flaw was found in Picketlink Federation SAML; the unsolcited response handler
CRITICAL
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in...
access-controlauthentication-bypassauthorizationcve-2026-10579federationforged-assertionsidentity-managementinformation-disclosure
2026-08-11
NVD CVE
CVE-2026-58115: A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the...
arbitrary-code-executionauthenticationcve-2026-58115https-interfaceindustrial-osindustrials-iotmalicious-flowsnodes-red
2026-08-11
NVD CVE
CVE-2026-58231: SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authent
CRITICAL
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially crafted
input to certain functions lacking sufficient validation. Successful
exploitation could...
arbitrary-code-executionauthentication-bypassavailabilityconfidentialitycve-2026-58231default-authentication-clienthigh-impactinput-validation
2026-08-11
NVD CVE
CVE-2026-48362: ColdFusion is affected by an Improper Neutralization of Special Elements used in
CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescommand-injectioncve-2026-48362exploitnvd-cve
2026-08-11
NVD CVE
CVE-2026-44758: SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig
CRITICAL
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation....
arbitrary-code-executionavailabilityconfidentialitycve-2026-44758high-privilegeinput-validationintegritymanufacturing-integration-and-intelligence
2026-08-11
NVD CVE
CVE-2026-34265: SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl
CRITICAL
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive...
abapavailabilityconfidentialitycve-2026-34265diagnostic-protocolsintegritymemory-corruptionnvd-cve
2026-08-11
NVD CVE
CVE-2026-19425: Travel Agency Management System developed by Win Men Intermational has a SQL Inj
CRITICAL
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
code-injectioncve-2026-19425data-deletiondata-modificationdatabases-compromisesdatum-exfiltrationnvd-cvepatch-management
2026-08-11
NVD CVE
CVE-2026-50516: Missing authentication for critical function in Microsoft Azure Kubernetes Servi
CRITICAL
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
azurecloud-securitycve-2026-50516incident-responsekubernetemicrosoftmissing-authenticationnetwork-security
2026-08-11
NVD CVE
CVE-2026-59124: Deserialization of untrusted data in Microsoft High Performance Computing (HPC)
CRITICAL
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-59124deserializationhigh-performance-computinghpcmicrosoftnetworks-attacksnvd-cve
2026-08-11
NVD CVE
CVE-2026-65791: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize
CRITICAL
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-65791exploitheap-based-buffer-overflowiscsinetworks-attacksnvd-cve
2026-08-10
NVD CVE
CVE-2026-18948: A flaw was found in Feast. The system improperly deserializes user-defined funct
CRITICAL
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious...
arbitrary-code-executioncross-tenant-data-accesscve-2026-18948deserializationdillfeastlateral-movementnvd-cve
2026-08-10
NVD CVE
CVE-2026-14450: A flaw was found in the MaaS API. This vulnerability allows any pod within the c
CRITICAL
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are...
api-keycve-2026-14450first-parties-authenticationforged-headershttps-headerskuadrant-authpolicykubernetemaas-apus
2026-08-10
NVD CVE
CVE-2026-13206: Improper neutralization of special elements used in an OS command ('OS command i
CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection.
This issue affects WAH7601: through 20072026.
command-injectioncve-2026-13206cybersecuritynetwork-adapternetwork-securitynetwork-security-vulnerabilitynetworks-devicesnetworks-devices-vulnerabilities
2026-08-10
NVD CVE
CVE-2026-63106: ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil
CRITICAL
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause...
administrator-passwords-hashescve-2026-63106database-contentfile-system-accessincident-responsemysqlnvd-cveproduct-controller
2026-08-09
NVD CVE
CVE-2026-19348: A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea
CRITICAL
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1....
add-actcommand-injectioncve-2026-19348enable-1exploitm300-wi-fi-repeaternet-smacfilter-confnvd-cve
2026-08-09
NVD CVE
CVE-2026-71993: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71990: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the...
axe6600command-injectioncve-2026-71990firmwaremsinvd-cveradixremote-attacks
2026-08-09
NVD CVE
CVE-2026-71986: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71986dmzfirmwaremalicious-commandsmsi
2026-08-09
NVD CVE
CVE-2026-71985: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71987: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71991: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71992: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71992firmwarefirmware-vulnerabilitiesmacfiltermsi
2026-08-09
NVD CVE
CVE-2026-71984: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71984firmwaremalicious-commandsmsinvd-cve
2026-08-09
NVD CVE
CVE-2026-71988: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71989: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71958: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71957: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71983: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71955: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71956: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71949: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71948: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71950: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71946: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71945: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can...
nvd-cve