Skip to content
COOEY
LIVE FEED
1796 events · 13 sources · newest first
2026-08-13 NVD CVE
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server...
access-controlcve-2026-72839default-settingsfile-managementfile-systemfilebrowserfiles-accessfiles-downloads
2026-08-13 NVD CVE
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
arbitrary-code-executionbuffer-overflowcve-2026-17206ibmibm-invd-cveoperating-systemsremote-code-execution
2026-08-13 NVD CVE
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers...
authenticate-usercve-2026-72841files-uploadluci-apps-openvpnmalicious-payloadsnvd-cveopenvpnpath-traversal
2026-08-12 NVD CVE
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
cve-2026-17111data-deletiondata-modificationdatabaseibmibm-iibm-i-7-3ibm-i-7-4
2026-08-12 NVD CVE
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide...
cryptographic-validationcve-2026-17616ibmibm-security-verify-accessibm-verify-identity-accessibm-verify-identity-access-containernvd-cvereverse-proxy
2026-08-12 NVD CVE
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
buffer-overflowcve-2026-10534databasedb2ibmixf-import-parsernvd-cvesecurity
2026-08-12 NVD CVE
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
credential-harvestingcve-2026-18847iibmibm-inavigatornvd-cveremote-attacks
2026-08-12 NVD CVE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate...
2026-08-12 NVD CVE
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
cve-2026-17276high-authority-threadibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6improper-authorization
2026-08-12 NVD CVE
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
nvd-cve
2026-08-12 NVD CVE
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the...
nvd-cve
2026-08-12 NVD CVE
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication...
nvd-cve
2026-08-12 NVD CVE
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd-cve
2026-08-12 NVD CVE
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A...
annotation-validationapplications-custom-resourceargos-cdcluster-managementcode-executioncve-2026-72526hub-clustermanifest-synchronization
2026-08-12 NVD CVE
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating...
nvd-cve
2026-08-12 NVD CVE
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is...
nvd-cve
2026-08-12 NVD CVE
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
arbitrary-code-executionauthenticate-attackercve-2026-16860ibmibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5
2026-08-12 NVD CVE
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
2026-08-12 NVD CVE
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster...
argos-cdbearer-tokencloud-securitycve-2026-70398data-disclosuregitopsclustermulticloud-integrationnvd-cve
2026-08-12 NVD CVE
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised...
2026-08-12 NVD CVE
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or...
arbitrary-code-executionbuffer-overflowcve-2025-41769default-configurationdevice-rebootexploitindustrial-control-systemnetworks-vulnerabilities
2026-08-11 NVD CVE
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
2026-08-11 NVD CVE
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
androidandroid-appscode-executioncve-2026-65768exploitmicrosoftmicrosoft-teamnetwork-security
2026-08-11 NVD CVE
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources....
access-controladobeadobe-commercecommercecve-2026-71362exploitincorrect-authorizationnvd-cve
2026-08-11 NVD CVE
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any...
admin-sessionapplication-secretcve-2026-69102forged-tokenhard-coded-secretjwtmaxkeynvd-cve
2026-08-11 NVD CVE
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to...
adobeadobe-campaign-classicarbitrary-code-executioncve-2026-71398incorrect-authorizationnvd-cvesecurityvulnerability
2026-08-11 NVD CVE
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server...
arbitrary-command-executioncommand-injectioncve-2026-5917gitgit-submodulelibgit2libssh2nvd-cve
2026-08-11 NVD CVE
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to...
adobeadobe-campaign-classicarbitrary-code-executioncve-2026-27302incorrect-authorizationnvd-cvesecurityvulnerability
2026-08-11 NVD CVE
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to...
chrome-privilegescve-2026-73032file-readsfile-writejavascriptllmmitmnvd-cve
2026-08-11 NVD CVE
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id...
agent-scriptattackers-controlledcron-directoriescve-2026-73034db-gptdirectories-traversalfiles-uploadhttps-headers
2026-08-11 NVD CVE
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-62893freeincident-responsenetworks-attacksnvd-cvepatch-managementremote-code-execution
2026-08-11 NVD CVE
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-62878dns-securityexploitnetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-08-11 NVD CVE
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcve-2026-70306inputs-neutralizationmicrosoftnetwork-securitynvd-cvesharepointspoofing
2026-08-11 NVD CVE
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-59124deserializationhigh-performance-computinghpcmicrosoftnetworks-attacksnvd-cve
2026-08-11 NVD CVE
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
attackercode-executioncve-2026-62815exploitfreemicrosoftnetwork-securitynvd-cve
2026-08-11 NVD CVE
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write...
access-controladministrative-network-zoneapplications-vulnerabilitiescve-2026-71384cybersecuritydenialexploitincorrect-authorization
2026-08-11 NVD CVE
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the...
arbitrary-code-executionauthenticationcve-2026-58115https-interfaceindustrial-osindustrials-iotmalicious-flowsnodes-red
2026-08-11 NVD CVE
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could...
arbitrary-code-executionauthentication-bypassavailabilityconfidentialitycve-2026-58231default-authentication-clienthigh-impactinput-validation
2026-08-11 NVD CVE
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescommand-injectioncve-2026-48362exploitnvd-cve
2026-08-11 NVD CVE
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
code-injectioncve-2026-19425data-deletiondata-modificationdatabases-compromisesdatum-exfiltrationnvd-cvepatch-management
◀ PREV PAGE 08 / 45 NEXT ▶