LIVE FEED
1582 events · 4 sources · newest first
Events in view
1582
all sources
Critical
0
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2022-03-03
CISA KEV
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
2022-03-03
CISA KEV
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected...
2022-03-03
CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03
CISA KEV
smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.
2022-03-03
CISA KEV
A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.
2022-03-03
CISA KEV
An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.
2022-03-03
CISA KEV
The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.
2022-03-03
CISA KEV
Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.
2022-03-03
CISA KEV
The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.
2022-03-03
CISA KEV
A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.
2022-03-03
CISA KEV
Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
2022-03-03
CISA KEV
A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
2022-02-25
CISA KEV
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
2022-02-25
CISA KEV
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
2022-02-25
CISA KEV
Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
2022-02-22
CISA KEV
Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
2022-02-22
CISA KEV
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
2022-02-15
CISA KEV
Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.
2022-02-15
CISA KEV
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
2022-02-15
CISA KEV
Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-02-15
CISA KEV
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to...
2022-02-15
CISA KEV
Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
2022-02-11
CISA KEV
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit,...
2022-02-10
CISA KEV
Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
2022-02-10
CISA KEV
Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.
2022-02-10
CISA KEV
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.
2022-02-10
CISA KEV
D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
2022-02-10
CISA KEV
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
2022-02-10
CISA KEV
A remote code execution vulnerability exists in Microsoft Office.
2022-02-10
CISA KEV
Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory.
2022-02-10
CISA KEV
Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file
2022-02-10
CISA KEV
The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
2022-02-10
CISA KEV
A code execution vulnerability exists in the Stapler web framework used by Jenkins
2022-02-10
CISA KEV
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
2022-02-04
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2022-01-28
CISA KEV
Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.
2022-01-28
CISA KEV
Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
2022-01-28
CISA KEV
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
2022-01-28
CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.
2022-01-28
CISA KEV
Intel products contain a vulnerability which can allow attackers to perform privilege escalation.