LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2022-05-23
CISA KEV
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
2022-05-16
NVD CVE
CVE-2022-29351: An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue...
2022-05-10
CISA KEV
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
2022-05-04
NVD CVE
CVE-2022-28568: Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to R
CRITICAL
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the...
2022-05-04
NVD CVE
CVE-2022-29347: An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to exec
CRITICAL
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
2022-05-04
NVD CVE
CVE-2021-43163: A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-
CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
2022-05-03
NVD CVE
CVE-2022-28118: SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plu
CRITICAL
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
2022-04-29
NVD CVE
CVE-2021-44596: Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code exe
CRITICAL
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the...
2022-04-28
NVD CVE
CVE-2021-41945: Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL
CRITICAL
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
2022-04-26
NVD CVE
CVE-2022-29499: The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows
CRITICAL
◈ 2 sources · orig. NVD CVE
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
2022-04-26
NVD CVE
CVE-2022-27985: CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin
CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
2022-04-26
NVD CVE
CVE-2022-27984: CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the me
CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
2022-04-25
CISA KEV
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
2022-04-25
NVD CVE
CVE-2022-28093: SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a loc
CRITICAL
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
2022-04-19
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
2022-04-15
CISA KEV
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
2022-04-14
CISA KEV
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
CRITICAL
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
2022-04-13
CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
2022-04-13
CISA KEV
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
2022-04-13
CISA KEV
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
2022-04-12
NVD CVE
CVE-2022-27262: An arbitrary file upload vulnerability in the file upload module of Skipper v0.9
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
2022-04-12
NVD CVE
CVE-2022-27260: An arbitrary file upload vulnerability in the file upload component of ButterCMS
CRITICAL
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
2022-04-12
NVD CVE
CVE-2022-28397: An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation,...
2022-04-11
CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11
NVD CVE
CVE-2021-37291: An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management
CRITICAL
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
2022-04-11
CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-06
CISA KEV
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
2022-03-31
CISA KEV
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
2022-03-31
CISA KEV
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
2022-03-30
NVD CVE
CVE-2021-46007: totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of
CRITICAL
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command...
2022-03-30
NVD CVE
CVE-2021-46009: In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite
CRITICAL
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
2022-03-30
NVD CVE
CVE-2022-26645: A remote code execution (RCE) vulnerability in Online Banking System Protect v1.
CRITICAL
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
2022-03-30
NVD CVE
CVE-2022-26646: Online Banking System Protect v1.0 was discovered to contain a local file inclus
CRITICAL
Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.
2022-03-29
NVD CVE
NUUO v03.11.00 was discovered to contain access control issue.
2022-03-28
CISA KEV
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
2022-03-28
NVD CVE
CVE-2022-26258: D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE)
CRITICAL
◈ 2 sources · orig. NVD CVE
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
2022-03-28
CISA KEV
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
2022-03-28
CISA KEV
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
2022-03-28
CISA KEV
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.