Skip to content
COOEY
LIVE FEED
1828 events · 4 sources · newest first
2022-03-28 CISA KEV
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
2022-03-28 CISA KEV
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
2022-03-28 CISA KEV
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
2022-03-28 CISA KEV
The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
2022-03-28 CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D
2022-03-25 CISA KEV
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
2022-03-25 CISA KEV
VMware Tanzu Spring Data Commons Property Binder Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
2022-03-25 CISA KEV
Adobe ColdFusion Directory Traversal Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
2022-03-25 CISA KEV
Webmin Command Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
2022-03-25 CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
2022-03-25 CISA KEV
Sitecore XP Remote Command Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
2022-03-25 CISA KEV
Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
2022-03-25 CISA KEV
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
2022-03-25 CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
2022-03-25 CISA KEV
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be...
2022-03-25 CISA KEV
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
2022-03-23 NVD CVE
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
2022-03-18 NVD CVE
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
2022-03-18 NVD CVE
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary...
2022-03-17 NVD CVE
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
2022-03-17 NVD CVE
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
2022-03-15 CISA KEV
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an...
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-11 NVD CVE
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
2022-03-10 NVD CVE
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal...
2022-03-07 CISA KEV
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
2022-03-03 CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.
2022-03-03 CISA KEV
An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
◀ PREV PAGE 41 / 46 NEXT ▶