LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release
cve record

CVE-2023-38646

CVSS
Severitynone
Weakness
ExploitedNot in CISA KEV

Description

References

← Back to the CVE Tracker

Our coverage of CVE-2023-38646

CVE-2023-38646critical

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has issued a critical alert regarding a zero-day vulnerability in its business intelligence software that has been actively exploited. The flaw allows unauthenticated attackers to inject SQL, leading to administrator access, credential theft, and data exfiltration. Metabase Cloud instances have been patched, and users of self-hosted versions are urged to update immediately.