LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2023-05-02
NVD CVE
CVE-2023-29778: GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/li
CRITICAL
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
2023-05-01
CISA KEV
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain...
2023-04-27
NVD CVE
CVE-2022-47758: Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attacke
CRITICAL
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
2023-04-26
NVD CVE
CVE-2023-30404: Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a re
CRITICAL
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a...
2023-04-21
CISA KEV
PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.
2023-04-18
NVD CVE
CVE-2022-46640: Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection
CRITICAL
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
2023-04-13
NVD CVE
CVE-2023-27667: Auto Dealer Management System v1.0 was discovered to contain a SQL injection vul
CRITICAL
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
2023-04-13
NVD CVE
CVE-2023-27779: AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via
CRITICAL
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
2023-04-13
NVD CVE
CVE-2023-27812: bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerabilit
CRITICAL
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
2023-04-11
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2023-04-07
CISA KEV
Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.
2023-04-07
CISA KEV
Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.
2023-04-07
CISA KEV
Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.
2023-04-07
CISA KEV
Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
2023-04-04
NVD CVE
CVE-2021-28235: Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers t
CRITICAL
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
2023-04-04
NVD CVE
CVE-2020-29312: An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to e
CRITICAL
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The...
2023-03-31
NVD CVE
CVE-2023-27162: openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request F
CRITICAL
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and...
2023-03-30
CISA KEV
Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.
2023-03-27
NVD CVE
CVE-2023-25261: Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This af
CRITICAL
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the...
2023-03-24
NVD CVE
CVE-2022-45597: ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor
CRITICAL
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport...
2023-03-17
NVD CVE
CVE-2023-28531: ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the inten
CRITICAL
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
2023-03-15
NVD CVE
CVE-2023-28461: Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote cod
CRITICAL
◈ 2 sources · orig. NVD CVE
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without...
2023-03-14
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
2023-03-09
NVD CVE
CVE-2023-27204: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
2023-03-09
NVD CVE
CVE-2023-27202: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
2023-03-09
NVD CVE
CVE-2023-27205: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
2023-03-09
NVD CVE
CVE-2023-27203: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
2023-03-03
NVD CVE
CVE-2022-45553: An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.
CRITICAL
An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.
2023-03-03
NVD CVE
CVE-2022-45551: An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.1
CRITICAL
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.
2023-03-02
NVD CVE
CVE-2022-46501: Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contai
CRITICAL
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.
2023-02-27
CISA KEV
ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This...
2023-02-24
NVD CVE
CVE-2021-33224: File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attack
CRITICAL
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
2023-02-21
NVD CVE
CVE-2023-24080: A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222
CRITICAL
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.
2023-02-21
CISA KEV
The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.
2023-02-21
CISA KEV
The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.
2023-02-21
CISA KEV
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
2023-02-14
NVD CVE
Microsoft Word Remote Code Execution Vulnerability
2023-02-14
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2023-02-13
NVD CVE
CVE-2023-24188: ureport v2.2.9 was discovered to contain a directory traversal vulnerability via
CRITICAL
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
2023-02-10
CISA KEV
TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.