LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2022-03-03
CISA KEV
Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
2022-03-03
CISA KEV
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
2022-03-03
CISA KEV
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
2022-03-03
CISA KEV
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
2022-03-03
CISA KEV
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability...
2022-03-03
CISA KEV
Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
2022-03-03
CISA KEV
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
2022-03-03
CISA KEV
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
2022-03-03
CISA KEV
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.
2022-03-03
NVD CVE
CVE-2022-25089: Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privil
CRITICAL
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
2022-02-25
NVD CVE
CVE-2022-25060: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
2022-02-25
NVD CVE
CVE-2022-25064: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execu
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
2022-02-25
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.
2022-02-25
NVD CVE
CVE-2021-42952: Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability.
CRITICAL
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and...
2022-02-25
NVD CVE
CVE-2022-25061: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
2022-02-17
NVD CVE
CVE-2022-22916: O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerabilit
CRITICAL
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
2022-02-15
CISA KEV
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
2022-02-15
CISA KEV
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
2022-02-15
CISA KEV
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
2022-02-15
CISA KEV
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
2022-02-14
NVD CVE
CVE-2021-45420: Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerabil
CRITICAL
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on...
2022-02-10
CISA KEV
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
2022-02-10
CISA KEV
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
2022-02-10
CISA KEV
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
2022-02-10
CISA KEV
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the...
2022-02-02
NVD CVE
CVE-2021-42637: PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled inpu
CRITICAL
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
2022-02-02
NVD CVE
CVE-2021-42640: PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Ins
CRITICAL
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
2022-01-28
NVD CVE
CVE-2021-44971: Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 F
CRITICAL
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine...
2022-01-28
CISA KEV
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
2022-01-28
CISA KEV
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
2022-01-21
CISA KEV
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
2022-01-18
CISA KEV
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal...
2022-01-17
NVD CVE
CVE-2022-23304: The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before
CRITICAL
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix...
2022-01-17
NVD CVE
CVE-2022-23303: The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10
CRITICAL
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for...
2022-01-13
NVD CVE
CVE-2021-45807: jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonC
CRITICAL
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
2022-01-10
CISA KEV
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
2022-01-10
CISA KEV
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
2022-01-10
CISA KEV
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
2022-01-10
CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
2022-01-10
CISA KEV
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.