LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2024-09-10
NVD CVE
Microsoft SQL Server Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Windows Remote Desktop Licensing Service Spoofing Vulnerability
2024-09-10
NVD CVE
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Azure Stack Hub Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
CVE-2024-38194: An authenticated attacker can exploit an improper authorization vulnerability in
HIGH
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
2024-09-09
NVD CVE
CVE-2024-44902: A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to
CRITICAL
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
2024-08-29
NVD CVE
CVE-2024-44778: A reflected cross-site scripting (XSS) vulnerability in the parent parameter in
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
2024-08-29
NVD CVE
CVE-2024-44777: A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
2024-08-29
NVD CVE
CVE-2024-44779: A reflected cross-site scripting (XSS) vulnerability in the viewname parameter i
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a...
2024-08-13
NVD CVE
CVE-2024-41623: An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a l
CRITICAL
An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload
2024-08-12
NVD CVE
CVE-2024-42467: openHAB, a provider of open-source home automation software, has add-ons includi
CRITICAL
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be...
2024-08-08
NVD CVE
CVE-2024-42256: In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix s
HIGH
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix server re-repick on subrequest retry
When a subrequest is marked for needing retry, netfs will call
cifs_prepare_write() which will make...
2024-08-02
NVD CVE
CVE-2024-38887: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the...
2024-08-02
NVD CVE
CVE-2024-38886: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the...
2024-08-02
NVD CVE
CVE-2024-38889: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements...
2024-07-09
NVD CVE
CVE-2023-48194: Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s
CRITICAL
Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.
2024-07-09
NVD CVE
CVE-2024-39171: Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and d
CRITICAL
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
2024-06-27
NVD CVE
CVE-2024-35260: An authenticated attacker can exploit an untrusted search path vulnerability in
HIGH
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
2024-06-17
NVD CVE
CVE-2023-37058: Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX
CRITICAL
Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.
2024-06-12
NVD CVE
CVE-2024-36265: ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache
CRITICAL
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.
This issue affects Apache Submarine Server Core: from 0.8.0.
An attacker can bypass authentication by sending...
2024-05-31
NVD CVE
CVE-2024-23692: Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t
CRITICAL
◈ 2 sources · orig. NVD CVE
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the...
2024-04-25
NVD CVE
CVE-2024-22373: An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStream
HIGH
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An...
2024-03-12
NVD CVE
CVE-2023-42789: A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, For
CRITICAL
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0,...
2024-02-29
NVD CVE
CVE-2024-23052: An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote at
CRITICAL
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.
2024-02-21
NVD CVE
CVE-2024-1212: Unauthenticated remote attackers can access the system through the LoadMaster ma
CRITICAL
◈ 2 sources · orig. NVD CVE
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
2024-02-09
NVD CVE
CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th
CRITICAL
◈ 2 sources · orig. NVD CVE
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through...
2024-02-08
NVD CVE
CVE-2024-24321: An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbi
CRITICAL
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
2024-02-06
NVD CVE
CVE-2024-24398: Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS bef
CRITICAL
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
2024-02-06
NVD CVE
CVE-2023-46359: An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1
CRITICAL
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted...
2024-02-05
NVD CVE
CVE-2024-23054: An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that
CRITICAL
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
2024-02-02
NVD CVE
CVE-2024-22901: Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
2024-02-02
NVD CVE
CVE-2024-22902: Vinchin Backup & Recovery v7.2 was discovered to be configured with default root
CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
2024-01-30
NVD CVE
CVE-2024-21488: Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command
HIGH
Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the...
2024-01-29
NVD CVE
CVE-2024-1015: Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting
CRITICAL
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web...
2024-01-25
NVD CVE
CVE-2024-22922: An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe a
CRITICAL
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php
2024-01-23
NVD CVE
CVE-2023-36177: An issue was discovered in badaix Snapcast version 0.27.0, allows remote attacke
CRITICAL
An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.
2024-01-20
NVD CVE
CVE-2023-51927: YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the
CRITICAL
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.
2024-01-20
NVD CVE
CVE-2023-51924: An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceMana
CRITICAL
An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
2024-01-20
NVD CVE
CVE-2023-51925: An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.actio
CRITICAL
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.