LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2023-02-10
CISA KEV
TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.
2023-02-10
CISA KEV
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
2023-02-02
CISA KEV
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
2023-02-01
NVD CVE
CVE-2022-47003: A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows
CRITICAL
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
2023-02-01
NVD CVE
CVE-2022-47769: An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1
CRITICAL
An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.
2023-02-01
NVD CVE
CVE-2022-47770: Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticat
CRITICAL
Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.
2023-01-30
NVD CVE
CVE-2022-23334: The Robot application in Ip-label Newtest before v8.5R0 was discovered to use we
CRITICAL
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
2023-01-26
CISA KEV
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
2023-01-26
NVD CVE
CVE-2020-22452: SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.
CRITICAL
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
2023-01-23
CISA KEV
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
2023-01-18
NVD CVE
CVE-2022-47966: Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT...
2023-01-10
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
2022-12-22
NVD CVE
CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free
CRITICAL
◈ 2 sources · orig. NVD CVE
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox <...
2022-12-19
NVD CVE
CVE-2022-40434: Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field
CRITICAL
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
2022-12-14
NVD CVE
CVE-2022-31358: A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environm
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.
2022-12-13
CISA KEV
Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.
2022-12-13
CISA KEV
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
2022-12-13
CISA KEV
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading...
2022-12-13
CISA KEV
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading...
2022-12-02
NVD CVE
CVE-2022-44291: webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the
CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
2022-12-02
NVD CVE
CVE-2022-44290: webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the
CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
2022-12-02
NVD CVE
CVE-2022-44945: Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via t
CRITICAL
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
2022-11-25
NVD CVE
CVE-2022-37720: Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). W
CRITICAL
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full...
2022-11-25
NVD CVE
CVE-2022-45207: Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via th
CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
2022-11-25
NVD CVE
CVE-2022-37721: PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low priv
CRITICAL
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or...
2022-11-25
NVD CVE
CVE-2022-45206: Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via th
CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
2022-11-22
NVD CVE
CVE-2022-36180: Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirec
CRITICAL
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection],...
2022-11-22
NVD CVE
Fusiondirectory 1.3 suffers from Improper Session Handling.
2022-11-22
NVD CVE
CVE-2022-40842: ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side req
CRITICAL
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
2022-11-22
NVD CVE
CVE-2022-42989: ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XS
CRITICAL
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
2022-11-22
NVD CVE
CVE-2022-44194: Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_d
CRITICAL
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.
2022-11-15
NVD CVE
CVE-2022-42122: A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7
CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into...
2022-11-15
NVD CVE
CVE-2022-42120: A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 thr
CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a...
2022-11-10
NVD CVE
CVE-2022-44087: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
2022-11-10
NVD CVE
CVE-2022-44089: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
2022-11-10
NVD CVE
CVE-2022-44088: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
2022-11-08
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2022-11-08
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
2022-10-25
NVD CVE
CVE-2022-38580: Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
CRITICAL
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
2022-10-24
CISA KEV
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a...