LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2025-08-27
NVD CVE
CVE-2025-34157: Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-sit
CRITICAL
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a...
2025-08-20
NVD CVE
CVE-2010-20103: A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball
CRITICAL
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes...
2025-08-13
NVD CVE
CVE-2025-51451: In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sendi
CRITICAL
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
2025-08-13
NVD CVE
CVE-2025-51452: In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login
CRITICAL
In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
2025-06-05
NVD CVE
CVE-2025-5635: A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This
HIGH
A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation leads to buffer overflow. The attack can be...
2025-05-30
NVD CVE
CVE-2025-48938: go-gh is a collection of Go modules to make authoring GitHub CLI extensions easi
CRITICAL
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could...
2025-05-29
NVD CVE
CVE-2025-5331: A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as criti
HIGH
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The...
2025-05-21
NVD CVE
CVE-2025-34027: The Versa Concerto SD-WAN orchestration platform is vulnerable to an authenticat
CRITICAL
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload...
2025-05-11
NVD CVE
CVE-2025-4528: A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affec
MEDIUM
A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to...
2025-04-24
NVD CVE
CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a
CRITICAL
◈ 2 sources · orig. NVD CVE
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host...
2025-04-20
NVD CVE
CVE-2025-43955: TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-
LOW
TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression....
2025-04-07
NVD CVE
CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/
CRITICAL
◈ 2 sources · orig. NVD CVE
Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code.
2025-04-03
NVD CVE
CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6,
CRITICAL
◈ 2 sources · orig. NVD CVE
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker...
2025-02-27
NVD CVE
CVE-2024-10918: Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflo
MEDIUM
Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an
unexpected length.
2025-01-23
NVD CVE
CVE-2025-23006: Pre-authentication deserialization of untrusted data vulnerability has been iden
CRITICAL
◈ 2 sources · orig. NVD CVE
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could...
2025-01-16
NVD CVE
CVE-2024-48885: A improper limitation of a pathname to a restricted directory ('path traversal')
MEDIUM
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4,...
2025-01-14
NVD CVE
CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CRITICAL
◈ 2 sources · orig. NVD CVE
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote...
2025-01-14
NVD CVE
CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal')
HIGH
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3,...
2025-01-14
NVD CVE
CVE-2024-35276: A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 thro
MEDIUM
A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0.0 through 7.0.12, FortiAnalyzer 6.4.0 through 6.4.14, FortiAnalyzer...
2025-01-09
NVD CVE
CVE-2024-53704: An Improper Authentication vulnerability in the SSLVPN authentication mechanism
CRITICAL
◈ 2 sources · orig. NVD CVE
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
2025-01-08
NVD CVE
CVE-2025-0282: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5,
CRITICAL
◈ 2 sources · orig. NVD CVE
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote...
2024-12-13
NVD CVE
CVE-2024-55956: In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.
CRITICAL
◈ 2 sources · orig. NVD CVE
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the...
2024-11-27
NVD CVE
CVE-2024-11667: A directory traversal vulnerability in the web management interface of Zyxel ATP
HIGH
◈ 2 sources · orig. NVD CVE
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series...
2024-11-26
NVD CVE
CVE-2024-11680: ProjectSend versions prior to r1720 are affected by an improper authentication v
CRITICAL
◈ 2 sources · orig. NVD CVE
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling...
2024-11-22
NVD CVE
CVE-2024-52723: In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str f
CRITICAL
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
2024-11-19
NVD CVE
CVE-2024-52714: Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the f
CRITICAL
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
2024-11-18
NVD CVE
CVE-2024-0012: An authentication bypass in Palo Alto Networks PAN-OS software enables an unauth
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative...
2024-10-29
NVD CVE
CVE-2024-51378: getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel)
CRITICAL
◈ 2 sources · orig. NVD CVE
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or...
2024-10-29
NVD CVE
CVE-2024-51567: upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before
CRITICAL
◈ 2 sources · orig. NVD CVE
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing...
2024-10-28
NVD CVE
CVE-2024-50623: In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.
CRITICAL
◈ 2 sources · orig. NVD CVE
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
2024-10-21
NVD CVE
CVE-2024-41713: A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiColl
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input...
2024-10-20
NVD CVE
CVE-2024-49604: Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Medi
CRITICAL
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.
2024-10-09
NVD CVE
CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit
CRITICAL
◈ 2 sources · orig. NVD CVE
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability...
2024-10-07
NVD CVE
CVE-2024-46446: Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct
CRITICAL
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of...
2024-09-25
NVD CVE
CVE-2024-6593: Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka
CRITICAL
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands.
An attacker that has...
2024-09-25
NVD CVE
CVE-2024-6592: An incorrect authorization vulnerability in the protocol communication between t
CRITICAL
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS...
2024-09-19
NVD CVE
CVE-2024-33109: Directory Traversal in the web interface of the Tiptel IP 286 with firmware vers
CRITICAL
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
2024-09-17
NVD CVE
CVE-2024-44004: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection.
This issue affects WPCargo Track & Trace: before 8.0.4.
2024-09-10
NVD CVE
Microsoft SQL Server Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Windows TCP/IP Remote Code Execution Vulnerability