LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2024-01-20
NVD CVE
CVE-2023-51906: An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary
CRITICAL
An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.
2024-01-20
NVD CVE
CVE-2023-51928: An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.actio
CRITICAL
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
2024-01-20
NVD CVE
CVE-2023-51892: An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute a
CRITICAL
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.
2024-01-19
NVD CVE
CVE-2024-23687: Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and
CRITICAL
Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including...
2024-01-19
NVD CVE
CVE-2024-23679: Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. A
CRITICAL
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
2024-01-19
NVD CVE
CVE-2023-51947: Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1
CRITICAL
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.
2024-01-12
NVD CVE
CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9.
CRITICAL
◈ 2 sources · orig. NVD CVE
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute...
2024-01-09
NVD CVE
CVE-2023-26999: An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execut
CRITICAL
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.
2024-01-09
NVD CVE
CVE-2023-50643: An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to ex
CRITICAL
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
2024-01-04
NVD CVE
CVE-2024-22051: CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnera
CRITICAL
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading...
2024-01-02
NVD CVE
CVE-2023-47458: An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate
CRITICAL
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
2023-12-30
NVD CVE
CVE-2023-50651: TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote comman
CRITICAL
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
2023-12-20
NVD CVE
CVE-2023-50988: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the band
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.
2023-12-20
NVD CVE
CVE-2023-50992: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip pa
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.
2023-12-20
NVD CVE
CVE-2023-50990: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebo
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.
2023-12-20
NVD CVE
CVE-2023-50989: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerabil
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
2023-12-20
NVD CVE
CVE-2023-50987: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.
2023-12-20
NVD CVE
CVE-2023-50986: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
2023-12-20
NVD CVE
CVE-2023-50985: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanG
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.
2023-12-20
NVD CVE
CVE-2023-50984: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip p
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.
2023-12-20
NVD CVE
CVE-2023-50983: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerabil
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
2023-11-29
NVD CVE
CVE-2023-23325: Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a co
CRITICAL
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter.
2023-11-29
NVD CVE
CVE-2023-23324: Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hard
CRITICAL
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.
2023-11-28
NVD CVE
CVE-2023-48193: Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote a
CRITICAL
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not...
2023-11-21
NVD CVE
CVE-2023-49060: An attacker could have accessed internal pages or data by ex-filtrating a securi
CRITICAL
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
2023-11-10
NVD CVE
CVE-2023-47246: In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to cod
CRITICAL
◈ 2 sources · orig. NVD CVE
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
2023-11-02
NVD CVE
CVE-2023-46958: An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via
CRITICAL
An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.
2023-10-31
NVD CVE
CVE-2023-42425: An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to
CRITICAL
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.
2023-10-25
NVD CVE
CVE-2023-46010: An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via t
CRITICAL
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
2023-10-19
NVD CVE
CVE-2023-45379: In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from
CRITICAL
In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection.
2023-10-19
NVD CVE
CVE-2023-45992: A vulnerability in the web-based interface of the RUCKUS Cloudpath product on ve
CRITICAL
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a...
2023-10-19
NVD CVE
CVE-2022-37830: Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).
CRITICAL
Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).
2023-10-14
NVD CVE
CVE-2023-45853: MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buf
CRITICAL
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib...
2023-09-27
NVD CVE
CVE-2023-41449: An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute a
CRITICAL
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
2023-09-27
NVD CVE
CVE-2023-43234: DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) v
CRITICAL
DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.
2023-09-25
NVD CVE
CVE-2023-43141: TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to In
CRITICAL
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
2023-09-20
NVD CVE
CVE-2023-38888: Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allow
CRITICAL
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to...
2023-09-12
NVD CVE
CVE-2023-4501: User authentication with username and password credentials is ineffective in Ope
CRITICAL
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as...
2023-09-12
NVD CVE
CVE-2023-39637: D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnera
CRITICAL
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
2023-09-08
NVD CVE
CVE-2021-27715: An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allo
CRITICAL
An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request.