Skip to content
COOEY
LIVE FEED
1828 events · 4 sources · newest first
2021-12-15 CISA KEV
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
2021-12-15 NVD CVE
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
2021-12-10 NVD CVE
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and...
2021-12-10 CISA KEV
Apache Log4j2 Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
2021-12-10 CISA KEV
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
2021-12-08 NVD CVE
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
2021-12-07 NVD CVE
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
2021-11-19 NVD CVE
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S),...
2021-11-17 CISA KEV
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
2021-11-17 CISA KEV
Unspecified vulnerability allows for an authenticated user to escalate privileges.
2021-11-13 NVD CVE
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
2021-11-05 NVD CVE
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special...
2021-11-04 NVD CVE
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
2021-11-04 NVD CVE
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha...
2021-11-04 NVD CVE
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the...
2021-11-03 CISA KEV
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or...
2021-11-03 CISA KEV
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
2021-11-03 CISA KEV
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
2021-11-03 CISA KEV
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
2021-11-03 CISA KEV
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
2021-11-03 CISA KEV
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
2021-11-03 CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could...
2021-11-03 CISA KEV
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
2021-11-03 CISA KEV
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
2021-11-03 CISA KEV
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
2021-11-03 CISA KEV
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
2021-11-03 CISA KEV
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
2021-11-03 CISA KEV
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all...
2021-11-03 CISA KEV
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all...
2021-11-03 CISA KEV
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
2021-11-03 CISA KEV
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
2021-11-03 CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
2021-11-03 CISA KEV
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
2021-11-03 CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
2021-11-03 CISA KEV
SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.
2021-11-03 CISA KEV
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
2021-11-03 CISA KEV
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
2021-11-03 CISA KEV
SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
2021-11-03 CISA KEV
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
2021-11-03 CISA KEV
Fortinet FortiOS SSL VPN Improper Authentication Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the...
◀ PREV PAGE 43 / 46 NEXT ▶