Skip to content
COOEY
LIVE FEED
1796 events · 13 sources · newest first
2026-08-11 NVD CVE
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in...
access-controlauthentication-bypassauthorizationcve-2026-10579federationforged-assertionsidentity-managementinformation-disclosure
2026-08-11 NVD CVE
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to...
chrome-privilegescve-2026-73032file-readsfile-writejavascriptllmmitmnvd-cve
2026-08-11 NVD CVE
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
attackercode-executioncve-2026-62815exploitfreemicrosoftnetwork-securitynvd-cve
2026-08-11 NVD CVE
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-62878dns-securityexploitnetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-08-11 NVD CVE
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcve-2026-70306inputs-neutralizationmicrosoftnetwork-securitynvd-cvesharepointspoofing
2026-08-10 NVD CVE
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to...
2026-08-10 NVD CVE
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious...
arbitrary-code-executioncross-tenant-data-accesscve-2026-18948deserializationdillfeastlateral-movementnvd-cve
2026-08-10 NVD CVE
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are...
api-keycve-2026-14450first-parties-authenticationforged-headershttps-headerskuadrant-authpolicykubernetemaas-apus
2026-08-10 NVD CVE
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.
command-injectioncve-2026-13206cybersecuritynetwork-adapternetwork-securitynetwork-security-vulnerabilitynetworks-devicesnetworks-devices-vulnerabilities
2026-08-10 NVD CVE
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause...
administrator-passwords-hashescve-2026-63106database-contentfile-system-accessincident-responsemysqlnvd-cveproduct-controller
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09 NVD CVE
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1....
add-actcommand-injectioncve-2026-19348enable-1exploitm300-wi-fi-repeaternet-smacfilter-confnvd-cve
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers...
nvd-cve
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71986dmzfirmwaremalicious-commandsmsi
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the...
axe6600command-injectioncve-2026-71990firmwaremsinvd-cveradixremote-attacks
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71984firmwaremalicious-commandsmsinvd-cve
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the...
nvd-cve
2026-08-09 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71992firmwarefirmware-vulnerabilitiesmacfiltermsi
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the...
nvd-cve
2026-08-08 NVD CVE
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can...
nvd-cve
2026-08-08 NVD CVE
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08 NVD CVE
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to...
administrator-accountai-copilotauthorization-bypasscontents-generatorcve-2026-14526frontend-pagejavascriptmalicious-workflow
2026-08-07 NVD CVE
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
azure-sqlimproper-restrictions-communicationsnetworks-vulnerabilitiesnvd-cveprivileges-elevationunauthorized-attacks
2026-08-07 NVD CVE
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,...
cve-2026-56793cybersecuritydelldfar-252-204-7012improper-authenticationincident-responsenist-800-171nvd-cve
◀ PREV PAGE 09 / 45 NEXT ▶