Skip to content
COOEY
LIVE FEED
1828 events · 4 sources · newest first
2022-05-23 CISA KEV
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
2022-05-23 CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
2022-05-16 NVD CVE
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue...
2022-05-10 CISA KEV
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
2022-05-04 NVD CVE
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the...
2022-05-04 NVD CVE
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
2022-05-04 NVD CVE
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
2022-05-03 NVD CVE
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
2022-04-29 NVD CVE
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the...
2022-04-28 NVD CVE
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
2022-04-26 NVD CVE
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
2022-04-26 NVD CVE
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
2022-04-26 NVD CVE
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
2022-04-25 CISA KEV
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
2022-04-25 NVD CVE
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
2022-04-19 CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
2022-04-15 CISA KEV
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
2022-04-14 CISA KEV
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
2022-04-13 CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
2022-04-13 CISA KEV
Kaseya VSA Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
2022-04-13 CISA KEV
Drupal Core Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
2022-04-12 NVD CVE
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
2022-04-12 NVD CVE
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
2022-04-12 NVD CVE
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation,...
2022-04-11 CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11 NVD CVE
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
2022-04-11 CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-06 CISA KEV
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
2022-03-31 CISA KEV
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
2022-03-31 CISA KEV
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
2022-03-30 NVD CVE
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command...
2022-03-30 NVD CVE
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
2022-03-30 NVD CVE
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
2022-03-30 NVD CVE
Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.
2022-03-29 NVD CVE
NUUO v03.11.00 was discovered to contain access control issue.
2022-03-28 CISA KEV
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
2022-03-28 NVD CVE
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
2022-03-28 CISA KEV
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
2022-03-28 CISA KEV
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
2022-03-28 CISA KEV
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
◀ PREV PAGE 40 / 46 NEXT ▶