LIVE FEED
1847 events · 13 sources · newest first
Events in view
1847
all sources
Critical
1847
severity
Active sources
13
collectors
Last sync
2026-08-28 18:00
UTC
All sources
NVD CVE · 1796CISA KEV · 1686News · 435CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-08
NVD CVE
CVE-2026-71945: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71946: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71955: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71947: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori
CRITICAL
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to...
administrator-accountai-copilotauthorization-bypasscontents-generatorcve-2026-14526frontend-pagejavascriptmalicious-workflow
2026-08-08
NVD CVE
CVE-2026-71952: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71944: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can...
nvd-cve
2026-08-07
NVD CVE
CVE-2026-14365: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CRITICAL
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that...
authorization-bypassnvd-cvepasswords-manipulationsunauthenticated-attacksuser-accountvulnerabilitywordpress-plugin
2026-08-07
NVD CVE
CVE-2026-70332: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unau
CRITICAL
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
microsoftnetworks-spoofingnvd-cveoffice-sharepointssrfvulnerability
2026-08-07
NVD CVE
CVE-2026-14364: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CRITICAL
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the...
accounts-takeovernvd-cvepassword-reset-validationtruebookerunauthenticated-attacksvulnerabilitywordpress-plugin
2026-08-07
NVD CVE
CVE-2026-62830: Missing authorization in Azure SRE Agent allows an authorized attacker to elevat
CRITICAL
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
authorized-accessazure-sres-agentsmissing-authorizationnetworks-attacksnvd-cveprivileges-elevation
2026-08-07
NVD CVE
CVE-2026-50515: Deserialization of untrusted data in Azure Service Bus allows an authorized atta
CRITICAL
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
azure-service-busdeserializationexecution-codenetworknvd-cveuntrusted-datavulnerability
2026-08-07
NVD CVE
CVE-2026-63508: Missing authentication for critical function in Microsoft Planetary Computer Pro
CRITICAL
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
authenticationcve-2026-63508microsoftnetworks-attacksnvd-cveplanetary-computer-proprivileges-escalationunauthorized-access
2026-08-07
NVD CVE
CVE-2026-68823: Exposed dangerous method or function in Azure Confidential Ledger allows an auth
CRITICAL
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
authentication-breachazure-confidential-ledgersincident-responsenist-800-171nvd-cveransomwarevulnerability
2026-08-06
NVD CVE
CVE-2026-54489: Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.
CRITICAL
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this...
active-session-credentialsadministratorauthenticate-usercritical-vulnerabilitycve-2026-54489dell-virtual-storage-integratorimpersonationinformation-disclosure
2026-08-06
NVD CVE
CVE-2026-70558: Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied pa
CRITICAL
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and...
attack-pathclasspath-shadowscve-2026-70558dinkyfile-transferjvm-startsnvd-cvepath-validation
2026-08-06
NVD CVE
CVE-2026-53984: Ground Station prior to 0.6.0 contains an unauthenticated database-destruction a
CRITICAL
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated...
arbitrary-data-injectionattackers-controlled-serverscve-2026-53984database-backupdatabase-destructiondisabled-authenticationexec-driver-sqlfull-restore-command
2026-08-06
NVD CVE
CVE-2026-67622: Flowise through 3.1.4 contains an insecure direct object reference vulnerability
CRITICAL
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by...
assistants-metadataauthenticate-attackscve-2026-67622files-uploadinsecure-direct-object-referencenvd-cveopenai-assistantvulnerability
2026-08-05
NVD CVE
CVE-2026-20267: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20267cwes-pillar-cwe-284improper-access-controlnvd-cveproduct-qualitysecurity-reviewsoftwares-hardening
2026-08-05
NVD CVE
CVE-2026-20303: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20303cwes-20input-validationnvd-cvesoftwares-hardeningvulnerability
2026-08-05
NVD CVE
CVE-2026-66747: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS,
CRITICAL
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package...
c2cleartext-communicationscommands-and-controlcve-2026-66747endlessdoorfirmwareimplantnvd-cve
2026-08-05
NVD CVE
CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operat
CRITICAL
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM...
advanced-cluster-managementapplication-subscription-controllercluster-adminscluster-role-bindingcve-2026-10090helmkubernetenamespaces-scoped-privilege
2026-08-05
NVD CVE
CVE-2026-20272: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software...
ciscocve-2026-20272cwes-74nvd-cvesoftwares-hardeningvulnerability
2026-08-05
NVD CVE
CVE-2026-17556: A path traversal vulnerability was identified in GitHub Enterprise Server that a
CRITICAL
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage...
2026-08-05
NVD CVE
CVE-2026-5581: The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unaut
CRITICAL
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the...
attachment-idcsrfcve-2026-5581cybersecuritydata-lossesgravity-formjavascriptmedia-deletion
2026-08-05
NVD CVE
CVE-2026-9273: The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restr
CRITICAL
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0....
accounts-takeovercve-2026-9273cybersecurityemails-spoofinginformation-securitykadence-membershipnoncenvd-cve
2026-08-05
NVD CVE
CVE-2026-10059: A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator contro
CRITICAL
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator....
access-controlcluster-controlclustercuratorcybersecuritydefense-industrial-baseinformation-securitykubernetemulticluster-engine
2026-08-05
NVD CVE
CVE-2026-20304: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software...
catalyst-sd-wanciscocve-2026-20304cwe-284improper-access-controlnvd-cvesecurity-reviewsoftwares-hardening
2026-08-05
NVD CVE
CVE-2026-4431: The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modi
CRITICAL
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is...
ajaxauthenticationauthorizationcve-2026-4431cybersecuritydata-integritydata-modificationnvd-cve
2026-08-05
NVD CVE
CVE-2026-70615: boringproxy through 0.10.0 contains a newline injection vulnerability that allow
CRITICAL
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH...
authenticate-userboringproxycleartext-credentiallow-privilegednewline-injectionnvd-cvepersistent-shell-accessssh-authorized-key
2026-08-05
NVD CVE
CVE-2026-20310: As part of Cisco's ongoing commitment to proactive security and product quality,
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software...
catalyst-sd-wanciscocve-2026-20310cwes-59files-accesslink-resolutionnvd-cvesecurity-review
2026-08-04
NVD CVE
CVE-2026-14175: Unrestricted upload of file with dangerous type vulnerability in Bilin Software
CRITICAL
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue affects...
bilin-softwarecve-2026-14175cybersecurityfiles-uploadhumanists-digital-human-resourcesincident-responseinformatics-consultancynist-800-171
2026-08-04
NVD CVE
CVE-2026-18686: A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem
CRITICAL
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in...
command-injectioncve-2026-18686cybersecuritygl-inetgl-mt3000information-securitynas-websnetworks-devices
2026-08-04
NVD CVE
CVE-2026-70552: MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in
CRITICAL
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and...
admins-gated-endpointajax-dispatcherajax-phpauthentication-bypassbase64-encoded-pathscve-2026-70552dangerous-operationheader
2026-08-04
NVD CVE
CVE-2026-18685: A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Imp
CRITICAL
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It...
command-injectioncve-2026-18685cybersecurityfirmware-vulnerabilitiesgl-inetgl-mt3000incident-responsemodem-so
2026-08-04
NVD CVE
CVE-2026-14804: Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat
CRITICAL
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST...
bilin-softwarecryptographic-keyscve-2026-14804cybersecuritydata-encryptiondfar-252-204-7012executablehard-coded-keys
2026-08-04
NVD CVE
CVE-2026-15721: Cleartext storage of sensitive information vulnerability in Bilin Software and I
CRITICAL
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital Human Resources:...
bilin-softwarecleartext-storagescve-2026-15721data-securityhumanists-digital-human-resourcesinformatics-consultancyinformation-securitynvd-cve
2026-08-04
NVD CVE
CVE-2026-61515: Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated c
CRITICAL
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON...
binary-protocolcommand-injectiondevices-compromisefirmwareip-camerasjson-payloadnetworks-devicesnvd-cve
2026-08-04
NVD CVE
CVE-2026-69098: kotaemon through 0.12.0 contains an insecure deserialization vulnerability in th
CRITICAL
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON...
application-privilegescve-2026-69098cybersecuritydata-protectionendpointinsecure-deserializationjsonkotaemon
2026-08-04
NVD CVE
CVE-2026-70553: MaxSite CMS contains a remote code execution vulnerability that allows unauthent
CRITICAL
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install...
cve-2026-70553nvd-cvephpremote-code-executionvulnerability