LIVE FEED
1796 events · 13 sources · newest first
Events in view
1796
all sources
Critical
1518
severity
Active sources
13
collectors
Last sync
2026-08-28 18:00
UTC
All sources
NVD CVE · 1796CISA KEV · 1686News · 435CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-11
NVD CVE
CVE-2026-10579: A flaw was found in Picketlink Federation SAML; the unsolcited response handler
CRITICAL
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in...
access-controlauthentication-bypassauthorizationcve-2026-10579federationforged-assertionsidentity-managementinformation-disclosure
2026-08-11
NVD CVE
CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that a
CRITICAL
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to...
chrome-privilegescve-2026-73032file-readsfile-writejavascriptllmmitmnvd-cve
2026-08-11
NVD CVE
CVE-2026-62815: Use after free in Microsoft QUIC allows an unauthorized attacker to execute code
CRITICAL
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
attackercode-executioncve-2026-62815exploitfreemicrosoftnetwork-securitynvd-cve
2026-08-11
NVD CVE
CVE-2026-62878: Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to ex
CRITICAL
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-62878dns-securityexploitnetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-08-11
NVD CVE
CVE-2026-70306: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcve-2026-70306inputs-neutralizationmicrosoftnetwork-securitynvd-cvesharepointspoofing
2026-08-10
NVD CVE
CVE-2026-59090: A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign
HIGH
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to...
2026-08-10
NVD CVE
CVE-2026-18948: A flaw was found in Feast. The system improperly deserializes user-defined funct
CRITICAL
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious...
arbitrary-code-executioncross-tenant-data-accesscve-2026-18948deserializationdillfeastlateral-movementnvd-cve
2026-08-10
NVD CVE
CVE-2026-14450: A flaw was found in the MaaS API. This vulnerability allows any pod within the c
CRITICAL
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are...
api-keycve-2026-14450first-parties-authenticationforged-headershttps-headerskuadrant-authpolicykubernetemaas-apus
2026-08-10
NVD CVE
CVE-2026-13206: Improper neutralization of special elements used in an OS command ('OS command i
CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection.
This issue affects WAH7601: through 20072026.
command-injectioncve-2026-13206cybersecuritynetwork-adapternetwork-securitynetwork-security-vulnerabilitynetworks-devicesnetworks-devices-vulnerabilities
2026-08-10
NVD CVE
CVE-2026-63106: ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil
CRITICAL
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause...
administrator-passwords-hashescve-2026-63106database-contentfile-system-accessincident-responsemysqlnvd-cveproduct-controller
2026-08-09
NVD CVE
CVE-2026-71993: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-19348: A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea
CRITICAL
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1....
add-actcommand-injectioncve-2026-19348enable-1exploitm300-wi-fi-repeaternet-smacfilter-confnvd-cve
2026-08-09
NVD CVE
CVE-2026-71988: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71987: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71989: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71985: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71986: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71986dmzfirmwaremalicious-commandsmsi
2026-08-09
NVD CVE
CVE-2026-71990: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the...
axe6600command-injectioncve-2026-71990firmwaremsinvd-cveradixremote-attacks
2026-08-09
NVD CVE
CVE-2026-71984: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71984firmwaremalicious-commandsmsinvd-cve
2026-08-09
NVD CVE
CVE-2026-71991: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71992: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71992firmwarefirmware-vulnerabilitiesmacfiltermsi
2026-08-08
NVD CVE
CVE-2026-71958: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71957: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71983: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71953: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71951: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71954: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71949: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71948: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71950: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71955: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71945: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71946: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71956: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71947: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71944: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71952: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori
CRITICAL
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to...
administrator-accountai-copilotauthorization-bypasscontents-generatorcve-2026-14526frontend-pagejavascriptmalicious-workflow
2026-08-07
NVD CVE
CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL
HIGH
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
azure-sqlimproper-restrictions-communicationsnetworks-vulnerabilitiesnvd-cveprivileges-elevationunauthorized-attacks
2026-08-07
NVD CVE
CVE-2026-56793: Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im
HIGH
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,...
cve-2026-56793cybersecuritydelldfar-252-204-7012improper-authenticationincident-responsenist-800-171nvd-cve