LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2023-09-06
NVD CVE
CVE-2023-20269: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appl
MEDIUM
◈ 2 sources · orig. NVD CVE
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a...
2023-09-05
NVD CVE
CVE-2023-36361: Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via th
CRITICAL
Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.
2023-09-05
NVD CVE
CVE-2023-41009: File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to
CRITICAL
File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.
2023-08-29
NVD CVE
CVE-2023-41265: An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windo
CRITICAL
◈ 2 sources · orig. NVD CVE
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022...
2023-08-29
NVD CVE
CVE-2021-3262: TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20
CRITICAL
TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was...
2023-08-22
NVD CVE
CVE-2022-48174: There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In
CRITICAL
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
2023-08-21
NVD CVE
CVE-2023-39808: N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root
CRITICAL
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the...
2023-08-21
NVD CVE
CVE-2023-39807: N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection
CRITICAL
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.
2023-08-21
NVD CVE
CVE-2023-39809: N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command in
CRITICAL
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.
2023-08-21
NVD CVE
CVE-2020-28715: An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN0
CRITICAL
An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
2023-08-16
NVD CVE
CVE-2020-26037: Directory Traversal vulnerability in Server functionalty in Even Balance Punkbus
CRITICAL
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.
2023-08-16
NVD CVE
CVE-2023-38894: A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remo
CRITICAL
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
2023-08-14
NVD CVE
CVE-2023-30187: An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3
CRITICAL
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
2023-08-14
NVD CVE
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
2023-08-14
NVD CVE
CVE-2023-30186: A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3
CRITICAL
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
2023-08-10
NVD CVE
CVE-2023-39806: iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bak
CRITICAL
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
2023-08-10
NVD CVE
CVE-2023-39805: iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the whe
CRITICAL
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
2023-08-09
NVD CVE
CVE-2023-39004: Insecure permissions in the configuration directory (/conf/) of OPNsense Communi
CRITICAL
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password)...
2023-08-09
NVD CVE
CVE-2023-33468: KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.13
CRITICAL
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection...
2023-08-08
NVD CVE
Windows Mobile Device Management Elevation of Privilege Vulnerability
2023-08-08
NVD CVE
Windows System Assessment Tool Elevation of Privilege Vulnerability
2023-08-05
NVD CVE
CVE-2023-36095: An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arb
CRITICAL
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.
2023-08-03
NVD CVE
CVE-2023-36082: An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote att
CRITICAL
An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials.
2023-08-03
NVD CVE
CVE-2023-37679: A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 a
CRITICAL
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
2023-08-03
NVD CVE
CVE-2023-38954: ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerabil
CRITICAL
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
2023-08-03
NVD CVE
CVE-2023-38951: ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authentica
CRITICAL
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a...
2023-08-01
NVD CVE
CVE-2023-34960: A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11
CRITICAL
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
2023-07-31
NVD CVE
CVE-2023-34842: Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote att
CRITICAL
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
2023-07-31
NVD CVE
CVE-2023-37647: SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id p
CRITICAL
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
2023-07-25
NVD CVE
CVE-2023-35078: An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
2023-07-19
NVD CVE
Unauthenticated remote code execution
2023-07-12
NVD CVE
CVE-2023-33668: DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attac
CRITICAL
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
2023-07-11
NVD CVE
CVE-2023-3617: A vulnerability was found in SourceCodester Best POS Management System 1.0. It h
HIGH
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation...
2023-06-19
NVD CVE
CVE-2023-29534: Different techniques existed to obscure the fullscreen notification in Firefox a
CRITICAL
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks.
*This bug only affects Firefox and Focus...
2023-06-16
NVD CVE
CVE-2023-34832: TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow
CRITICAL
TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
2023-06-14
NVD CVE
CVE-2023-34752: bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the
CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
2023-06-13
NVD CVE
CVE-2023-31541: A unrestricted file upload vulnerability was discovered in the ‘Browse and uploa
CRITICAL
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
2023-06-13
NVD CVE
CVE-2023-27997: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an
CRITICAL
◈ 2 sources · orig. NVD CVE
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version...
2023-06-13
NVD CVE
CVE-2023-34944: An arbitrary file upload vulnerability in the /fileUpload.lib.php component of C
CRITICAL
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
2023-06-06
NVD CVE
CVE-2023-33532: There is a command injection vulnerability in the Netgear R6250 router with Firm
CRITICAL
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters,...