LIVE FEED
1683 events · 4 sources · newest first
Events in view
1683
all sources
Critical
329
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2022-01-10
CISA KEV
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
2022-01-10
CISA KEV
Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution
2022-01-10
CISA KEV
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
2022-01-10
CISA KEV
Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
2022-01-10
CISA KEV
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
2022-01-10
CISA KEV
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
2022-01-10
CISA KEV
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
2022-01-10
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.
2022-01-10
CISA KEV
A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.
2022-01-10
CISA KEV
Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
2022-01-10
CISA KEV
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
2022-01-10
CISA KEV
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
2021-12-15
CISA KEV
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2021-12-15
CISA KEV
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
2021-12-10
CISA KEV
Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.
2021-12-10
CISA KEV
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
2021-12-10
CISA KEV
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
2021-12-10
CISA KEV
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security...
2021-12-10
CISA KEV
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
2021-12-10
CISA KEV
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
2021-12-10
CISA KEV
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
2021-12-10
CISA KEV
Red Hat JBoss Application Server Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
2021-12-10
CISA KEV
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
2021-12-10
CISA KEV
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
2021-12-10
CISA KEV
Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
2021-12-10
CISA KEV
RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.
2021-12-10
CISA KEV
Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.
2021-12-01
CISA KEV
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
2021-12-01
CISA KEV
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
2021-12-01
CISA KEV
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
2021-12-01
CISA KEV
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
2021-12-01
CISA KEV
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,...
2021-11-17
CISA KEV
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
2021-11-17
CISA KEV
Unspecified vulnerability allows for an authenticated user to escalate privileges.
2021-11-17
CISA KEV
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
2021-11-17
CISA KEV
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
2021-11-03
CISA KEV
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that...
2021-11-03
CISA KEV
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple...
2021-11-03
CISA KEV
Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium,...
2021-11-03
CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that...