LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2023-06-06
NVD CVE
CVE-2023-31569: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command inje
CRITICAL
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
2023-05-18
NVD CVE
CVE-2023-31729: TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cs
CRITICAL
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
2023-05-12
NVD CVE
CVE-2023-27823: An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the
CRITICAL
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
2023-05-11
NVD CVE
CVE-2023-29863: Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a
CRITICAL
Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.
2023-05-08
NVD CVE
CVE-2023-30185: CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerabil
CRITICAL
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
2023-05-05
NVD CVE
CVE-2023-30242: NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the comp
CRITICAL
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
2023-05-04
NVD CVE
CVE-2023-23059: An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windo
CRITICAL
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain...
2023-05-02
NVD CVE
CVE-2023-29778: GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/li
CRITICAL
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
2023-04-27
NVD CVE
CVE-2022-47758: Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attacke
CRITICAL
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
2023-04-26
NVD CVE
CVE-2023-30404: Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a re
CRITICAL
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a...
2023-04-21
NVD CVE
CVE-2023-2206: A vulnerability classified as critical has been found in Campcodes Retro Basketb
MEDIUM
A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file contactus.php. The manipulation of the argument email leads to sql...
2023-04-18
NVD CVE
CVE-2022-46640: Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection
CRITICAL
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
2023-04-13
NVD CVE
CVE-2023-27779: AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via
CRITICAL
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
2023-04-13
NVD CVE
CVE-2023-27667: Auto Dealer Management System v1.0 was discovered to contain a SQL injection vul
CRITICAL
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
2023-04-13
NVD CVE
CVE-2023-27812: bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerabilit
CRITICAL
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
2023-04-04
NVD CVE
CVE-2020-29312: An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to e
CRITICAL
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The...
2023-04-04
NVD CVE
CVE-2021-28235: Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers t
CRITICAL
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
2023-03-31
NVD CVE
CVE-2023-27162: openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request F
CRITICAL
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and...
2023-03-27
NVD CVE
CVE-2023-25261: Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This af
CRITICAL
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the...
2023-03-24
NVD CVE
CVE-2022-45597: ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor
CRITICAL
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport...
2023-03-17
NVD CVE
CVE-2023-28531: ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the inten
CRITICAL
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
2023-03-15
NVD CVE
CVE-2023-28461: Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote cod
CRITICAL
◈ 2 sources · orig. NVD CVE
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without...
2023-03-09
NVD CVE
CVE-2023-27202: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
2023-03-09
NVD CVE
CVE-2023-27203: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
2023-03-09
NVD CVE
CVE-2023-27204: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
2023-03-09
NVD CVE
CVE-2023-27205: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
2023-03-03
NVD CVE
CVE-2022-45551: An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.1
CRITICAL
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.
2023-03-03
NVD CVE
CVE-2022-45553: An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.
CRITICAL
An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.
2023-03-02
NVD CVE
CVE-2022-46501: Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contai
CRITICAL
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.
2023-02-24
NVD CVE
CVE-2021-33224: File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attack
CRITICAL
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
2023-02-21
NVD CVE
CVE-2023-24080: A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222
CRITICAL
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.
2023-02-21
NVD CVE
CVE-2023-0946: A vulnerability has been found in SourceCodester Best POS Management System 1.0
MEDIUM
A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The...
2023-02-14
NVD CVE
Microsoft Word Remote Code Execution Vulnerability
2023-02-13
NVD CVE
CVE-2023-24188: ureport v2.2.9 was discovered to contain a directory traversal vulnerability via
CRITICAL
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
2023-02-01
NVD CVE
CVE-2022-47770: Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticat
CRITICAL
Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.
2023-02-01
NVD CVE
CVE-2022-47003: A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows
CRITICAL
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
2023-02-01
NVD CVE
CVE-2022-47769: An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1
CRITICAL
An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.
2023-01-30
NVD CVE
CVE-2022-23334: The Robot application in Ip-label Newtest before v8.5R0 was discovered to use we
CRITICAL
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
2023-01-26
NVD CVE
CVE-2020-22452: SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.
CRITICAL
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
2023-01-18
NVD CVE
CVE-2022-47966: Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT...