LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2024-08-29
NVD CVE
CVE-2024-44777: A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
2024-08-29
NVD CVE
CVE-2024-44778: A reflected cross-site scripting (XSS) vulnerability in the parent parameter in
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
2024-08-29
NVD CVE
CVE-2024-44779: A reflected cross-site scripting (XSS) vulnerability in the viewname parameter i
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a...
2024-08-19
CISA KEV
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
2024-08-13
NVD CVE
CVE-2024-41623: An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a l
CRITICAL
An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload
2024-08-12
NVD CVE
CVE-2024-42467: openHAB, a provider of open-source home automation software, has add-ons includi
CRITICAL
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be...
2024-08-02
NVD CVE
CVE-2024-38887: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the...
2024-08-02
NVD CVE
CVE-2024-38889: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements...
2024-08-02
NVD CVE
CVE-2024-38886: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the...
2024-07-30
CISA KEV
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user...
2024-07-09
NVD CVE
CVE-2024-39171: Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and d
CRITICAL
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
2024-07-09
NVD CVE
CVE-2023-48194: Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s
CRITICAL
Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.
2024-06-17
NVD CVE
CVE-2023-37058: Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX
CRITICAL
Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.
2024-06-13
CISA KEV
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
2024-06-12
CISA KEV
PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
2024-06-12
NVD CVE
CVE-2024-36265: ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache
CRITICAL
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.
This issue affects Apache Submarine Server Core: from 0.8.0.
An attacker can bypass authentication by sending...
2024-05-31
NVD CVE
CVE-2024-23692: Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t
CRITICAL
◈ 2 sources · orig. NVD CVE
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the...
2024-05-30
CISA KEV
Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.
2024-05-30
CISA KEV
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with...
2024-05-20
CISA KEV
NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.
2024-05-14
CISA KEV
Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
2024-04-12
CISA KEV
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
2024-03-26
CISA KEV
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
2024-03-25
CISA KEV
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
2024-03-25
CISA KEV
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
2024-03-12
NVD CVE
CVE-2023-42789: A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, For
CRITICAL
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0,...
2024-03-07
CISA KEV
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
2024-03-04
CISA KEV
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege...
2024-02-29
NVD CVE
CVE-2024-23052: An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote at
CRITICAL
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.
2024-02-22
CISA KEV
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.
2024-02-21
NVD CVE
CVE-2024-1212: Unauthenticated remote attackers can access the system through the LoadMaster ma
CRITICAL
◈ 2 sources · orig. NVD CVE
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
2024-02-15
CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the...
2024-02-13
CISA KEV
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
2024-02-09
CISA KEV
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
2024-02-09
NVD CVE
CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th
CRITICAL
◈ 2 sources · orig. NVD CVE
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through...
2024-02-08
NVD CVE
CVE-2024-24321: An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbi
CRITICAL
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
2024-02-06
NVD CVE
CVE-2023-46359: An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1
CRITICAL
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted...
2024-02-06
NVD CVE
CVE-2024-24398: Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS bef
CRITICAL
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
2024-02-05
NVD CVE
CVE-2024-23054: An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that
CRITICAL
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
2024-02-02
NVD CVE
CVE-2024-22902: Vinchin Backup & Recovery v7.2 was discovered to be configured with default root
CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.