Skip to content
COOEY
LIVE FEED
1683 events · 4 sources · newest first
2022-04-15 CISA KEV
Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
2022-04-15 CISA KEV
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.
2022-04-15 CISA KEV
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
2022-04-15 CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-04-15 CISA KEV
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
2022-04-15 CISA KEV
A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
2022-04-15 CISA KEV
The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).
2022-04-15 CISA KEV
InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
2022-04-14 CISA KEV
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
2022-04-13 CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
2022-04-13 CISA KEV
Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
2022-04-13 CISA KEV
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
2022-04-13 CISA KEV
Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
2022-04-13 CISA KEV
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
2022-04-13 CISA KEV
Drupal Core Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
2022-04-13 CISA KEV
Kaseya VSA Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
2022-04-13 CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
2022-04-13 CISA KEV
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
2022-04-13 CISA KEV
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
2022-04-11 CISA KEV
QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
2022-04-11 CISA KEV
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
2022-04-11 CISA KEV
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.
2022-04-11 CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11 CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11 CISA KEV
Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
2022-04-11 CISA KEV
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
2022-04-11 CISA KEV
Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.
2022-04-06 CISA KEV
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
2022-04-06 CISA KEV
Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
2022-04-06 CISA KEV
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
2022-04-04 CISA KEV
A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
2022-04-04 CISA KEV
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
2022-04-04 CISA KEV
macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
2022-04-04 CISA KEV
macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
2022-03-31 CISA KEV
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
2022-03-31 CISA KEV
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
2022-03-31 CISA KEV
An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
2022-03-31 CISA KEV
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
2022-03-31 CISA KEV
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
2022-03-31 CISA KEV
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
◀ PREV PAGE 27 / 43 NEXT ▶