LIVE FEED
1582 events · 4 sources · newest first
Events in view
1582
all sources
Critical
0
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2022-01-28
CISA KEV
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in...
2022-01-21
CISA KEV
SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.
2022-01-21
CISA KEV
The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
2022-01-21
CISA KEV
ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).
2022-01-18
CISA KEV
Improper sanitization in the extension file names is present in Drupal core.
2022-01-18
CISA KEV
Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
2022-01-18
CISA KEV
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
2022-01-18
CISA KEV
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
2022-01-18
CISA KEV
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
2022-01-18
CISA KEV
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
2022-01-18
CISA KEV
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
2022-01-18
CISA KEV
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
2022-01-18
CISA KEV
In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
2022-01-18
CISA KEV
A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
2022-01-18
CISA KEV
The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.
2022-01-18
CISA KEV
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
2022-01-10
CISA KEV
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
2022-01-10
CISA KEV
Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
2022-01-10
CISA KEV
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
2022-01-10
CISA KEV
Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution
2022-01-10
CISA KEV
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
2022-01-10
CISA KEV
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.
2022-01-10
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.
2022-01-10
CISA KEV
A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.
2022-01-10
CISA KEV
Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
2022-01-10
CISA KEV
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
2021-12-15
CISA KEV
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2021-12-10
CISA KEV
Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
2021-12-10
CISA KEV
RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.
2021-12-10
CISA KEV
Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.
2021-12-10
CISA KEV
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
2021-12-10
CISA KEV
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security...
2021-12-10
CISA KEV
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
2021-12-10
CISA KEV
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
2021-12-10
CISA KEV
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
2021-12-10
CISA KEV
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
2021-12-10
CISA KEV
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
2021-12-10
CISA KEV
Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.
2021-12-03
NVD CVE
CVE-2021-23758: All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted
HIGH
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
ajaxnetajaxnet-professionalajaxprocisa-kevcve-2021-23758deserializationendlife
2021-12-01
CISA KEV
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution