LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2022-08-12
NVD CVE
CVE-2022-37042: Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality tha
CRITICAL
◈ 2 sources · orig. NVD CVE
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload...
2022-08-05
NVD CVE
CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in infl
CRITICAL
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common...
2022-08-01
NVD CVE
CVE-2022-31321: The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input va
CRITICAL
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.
2022-07-25
NVD CVE
CVE-2022-35131: Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted paylo
CRITICAL
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
2022-07-06
NVD CVE
CVE-2022-33047: OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via ot
CRITICAL
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
2022-07-06
NVD CVE
CVE-2022-32385: Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the
CRITICAL
Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
2022-07-06
NVD CVE
CVE-2022-32386: Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvS
CRITICAL
Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
2022-06-17
NVD CVE
CVE-2021-45024: ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Ent
CRITICAL
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
2022-06-16
NVD CVE
CVE-2022-31384: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
2022-06-16
NVD CVE
CVE-2022-31383: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
2022-06-16
NVD CVE
CVE-2022-31382: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
2022-06-16
NVD CVE
CVE-2022-24562: In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POS
CRITICAL
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint,...
2022-06-14
NVD CVE
CVE-2021-42675: Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media dire
CRITICAL
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
2022-06-02
NVD CVE
CVE-2022-24239: ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file uplo
CRITICAL
ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.
2022-06-02
NVD CVE
CVE-2022-24240: ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerabi
CRITICAL
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
2022-06-02
NVD CVE
CVE-2022-28945: An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traver
CRITICAL
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
2022-06-02
NVD CVE
CVE-2021-42875: TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability
CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
2022-06-02
NVD CVE
CVE-2021-42872: TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability
CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
2022-06-02
NVD CVE
CVE-2022-31340: Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table
CRITICAL
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
2022-06-02
NVD CVE
BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
2022-06-02
NVD CVE
CVE-2022-30490: Badminton Center Management System V1.0 is vulnerable to SQL Injection via param
CRITICAL
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
2022-05-23
NVD CVE
CVE-2022-28932: D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permiss
CRITICAL
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
2022-05-16
NVD CVE
CVE-2022-29351: An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue...
2022-05-04
NVD CVE
CVE-2021-43163: A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-
CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
2022-05-04
NVD CVE
CVE-2022-28568: Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to R
CRITICAL
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the...
2022-05-04
NVD CVE
CVE-2022-29347: An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to exec
CRITICAL
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
2022-05-03
NVD CVE
CVE-2022-28118: SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plu
CRITICAL
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
2022-04-29
NVD CVE
CVE-2021-44596: Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code exe
CRITICAL
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the...
2022-04-28
NVD CVE
CVE-2021-41945: Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL
CRITICAL
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
2022-04-26
NVD CVE
CVE-2022-27984: CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the me
CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
2022-04-26
NVD CVE
CVE-2022-27985: CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin
CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
2022-04-26
NVD CVE
CVE-2022-29499: The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows
CRITICAL
◈ 2 sources · orig. NVD CVE
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
2022-04-25
NVD CVE
CVE-2022-28093: SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a loc
CRITICAL
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
2022-04-12
NVD CVE
CVE-2022-27260: An arbitrary file upload vulnerability in the file upload component of ButterCMS
CRITICAL
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
2022-04-12
NVD CVE
CVE-2022-27262: An arbitrary file upload vulnerability in the file upload module of Skipper v0.9
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
2022-04-12
NVD CVE
CVE-2022-28397: An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation,...
2022-04-11
NVD CVE
CVE-2021-37291: An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management
CRITICAL
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
2022-03-30
NVD CVE
CVE-2022-26646: Online Banking System Protect v1.0 was discovered to contain a local file inclus
CRITICAL
Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.
2022-03-30
NVD CVE
CVE-2021-46007: totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of
CRITICAL
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command...
2022-03-30
NVD CVE
CVE-2021-46009: In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite
CRITICAL
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.