LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2021-12-15
CISA KEV
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
2021-12-15
NVD CVE
CVE-2021-42216: A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via Verificat
CRITICAL
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
2021-12-10
NVD CVE
CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
CRITICAL
◈ 2 sources · orig. NVD CVE
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and...
2021-12-10
CISA KEV
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
2021-12-10
CISA KEV
Red Hat JBoss Application Server Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
2021-12-08
NVD CVE
CVE-2021-44529: A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA)
CRITICAL
◈ 2 sources · orig. NVD CVE
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
2021-12-07
NVD CVE
CVE-2021-41716: Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prio
CRITICAL
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
2021-11-19
NVD CVE
CVE-2021-41435: A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX1
CRITICAL
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S),...
2021-11-17
CISA KEV
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
2021-11-17
CISA KEV
Unspecified vulnerability allows for an authenticated user to escalate privileges.
2021-11-13
NVD CVE
CVE-2021-41653: The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL
CRITICAL
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
2021-11-05
NVD CVE
CVE-2021-42237: Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an
CRITICAL
◈ 2 sources · orig. NVD CVE
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special...
2021-11-04
NVD CVE
CVE-2020-25366: An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1
CRITICAL
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
2021-11-04
NVD CVE
CVE-2020-25367: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link
CRITICAL
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha...
2021-11-04
NVD CVE
CVE-2020-25368: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link
CRITICAL
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the...
2021-11-03
CISA KEV
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
CRITICAL
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or...
2021-11-03
CISA KEV
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
2021-11-03
CISA KEV
Exim Buffer Overflow Vulnerability
CRITICAL
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
2021-11-03
CISA KEV
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
2021-11-03
CISA KEV
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
2021-11-03
CISA KEV
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
2021-11-03
CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could...
2021-11-03
CISA KEV
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
2021-11-03
CISA KEV
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
2021-11-03
CISA KEV
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
2021-11-03
CISA KEV
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
2021-11-03
CISA KEV
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
2021-11-03
CISA KEV
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all...
2021-11-03
CISA KEV
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all...
2021-11-03
CISA KEV
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
2021-11-03
CISA KEV
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
2021-11-03
CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
2021-11-03
CISA KEV
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
2021-11-03
CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
2021-11-03
CISA KEV
SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.
2021-11-03
CISA KEV
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
2021-11-03
CISA KEV
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
2021-11-03
CISA KEV
SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
2021-11-03
CISA KEV
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
2021-11-03
CISA KEV
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the...