LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2022-07-06
NVD CVE
CVE-2022-33047: OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via ot
CRITICAL
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
2022-07-06
NVD CVE
CVE-2022-32385: Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the
CRITICAL
Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
2022-07-06
NVD CVE
CVE-2022-32386: Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvS
CRITICAL
Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
2022-06-27
CISA KEV
The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
2022-06-17
NVD CVE
CVE-2021-45024: ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Ent
CRITICAL
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
2022-06-16
NVD CVE
CVE-2022-31384: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
2022-06-16
NVD CVE
CVE-2022-31383: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
2022-06-16
NVD CVE
CVE-2022-24562: In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POS
CRITICAL
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint,...
2022-06-16
NVD CVE
CVE-2022-31382: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
2022-06-14
NVD CVE
CVE-2021-42675: Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media dire
CRITICAL
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
2022-06-14
CISA KEV
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the...
2022-06-08
CISA KEV
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.
2022-06-08
CISA KEV
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
2022-06-08
CISA KEV
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
2022-06-08
CISA KEV
QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.
2022-06-02
NVD CVE
CVE-2022-30490: Badminton Center Management System V1.0 is vulnerable to SQL Injection via param
CRITICAL
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
2022-06-02
NVD CVE
CVE-2022-24240: ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerabi
CRITICAL
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
2022-06-02
NVD CVE
CVE-2022-24239: ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file uplo
CRITICAL
ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.
2022-06-02
NVD CVE
CVE-2021-42872: TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability
CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
2022-06-02
CISA KEV
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
2022-06-02
NVD CVE
CVE-2022-31340: Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table
CRITICAL
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
2022-06-02
NVD CVE
CVE-2021-42875: TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability
CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
2022-06-02
NVD CVE
BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
2022-06-02
NVD CVE
CVE-2022-28945: An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traver
CRITICAL
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
2022-05-25
CISA KEV
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this...
2022-05-25
CISA KEV
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
2022-05-25
CISA KEV
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
2022-05-25
CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
2022-05-25
CISA KEV
A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
2022-05-25
CISA KEV
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.
2022-05-25
CISA KEV
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
2022-05-25
CISA KEV
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote...
2022-05-24
CISA KEV
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
2022-05-24
CISA KEV
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
2022-05-24
CISA KEV
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
2022-05-24
CISA KEV
A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
2022-05-24
CISA KEV
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the...
2022-05-24
CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
2022-05-23
NVD CVE
CVE-2022-28932: D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permiss
CRITICAL
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.