LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2022-03-30
NVD CVE
CVE-2022-26645: A remote code execution (RCE) vulnerability in Online Banking System Protect v1.
CRITICAL
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
2022-03-29
NVD CVE
NUUO v03.11.00 was discovered to contain access control issue.
2022-03-28
NVD CVE
CVE-2022-26258: D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE)
CRITICAL
◈ 2 sources · orig. NVD CVE
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
2022-03-23
NVD CVE
CVE-2021-45756: Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected b
CRITICAL
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
2022-03-18
NVD CVE
CVE-2022-25578: taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing
CRITICAL
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
2022-03-18
NVD CVE
CVE-2021-45834: An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.
CRITICAL
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary...
2022-03-17
NVD CVE
CVE-2021-44087: A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance
CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
2022-03-17
NVD CVE
CVE-2021-44088: An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll S
CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
2022-03-11
NVD CVE
CVE-2021-44620: A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B2020
CRITICAL
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
2022-03-10
NVD CVE
CVE-2022-23383: YzmCMS v6.3 is affected by broken access control. Without login, unauthorized ac
CRITICAL
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal...
2022-03-03
NVD CVE
CVE-2022-25089: Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privil
CRITICAL
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
2022-02-25
NVD CVE
CVE-2022-25061: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
2022-02-25
NVD CVE
CVE-2022-25064: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execu
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
2022-02-25
NVD CVE
CVE-2022-25060: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
2022-02-25
NVD CVE
CVE-2021-42952: Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability.
CRITICAL
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and...
2022-02-17
NVD CVE
CVE-2022-22916: O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerabilit
CRITICAL
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
2022-02-14
NVD CVE
CVE-2021-45420: Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerabil
CRITICAL
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on...
2022-02-02
NVD CVE
CVE-2021-42640: PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Ins
CRITICAL
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
2022-02-02
NVD CVE
CVE-2021-42637: PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled inpu
CRITICAL
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
2022-01-28
NVD CVE
CVE-2021-44971: Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 F
CRITICAL
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine...
2022-01-17
NVD CVE
CVE-2022-23304: The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before
CRITICAL
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix...
2022-01-17
NVD CVE
CVE-2022-23303: The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10
CRITICAL
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for...
2022-01-13
NVD CVE
CVE-2021-45807: jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonC
CRITICAL
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
2021-12-15
NVD CVE
CVE-2021-42216: A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via Verificat
CRITICAL
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
2021-12-10
NVD CVE
CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
CRITICAL
◈ 2 sources · orig. NVD CVE
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and...
2021-12-08
NVD CVE
CVE-2021-44529: A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA)
CRITICAL
◈ 2 sources · orig. NVD CVE
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
2021-12-07
NVD CVE
CVE-2021-41716: Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prio
CRITICAL
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
2021-12-03
NVD CVE
CVE-2021-23758: All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted
HIGH
◈ 2 sources · orig. NVD CVE
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
ajaxnetajaxnet-professionalajaxprocisa-kevcve-2021-23758deserializationendlife
2021-11-19
NVD CVE
CVE-2021-41435: A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX1
CRITICAL
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S),...
2021-11-13
NVD CVE
CVE-2021-41653: The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL
CRITICAL
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
2021-11-05
NVD CVE
CVE-2021-42237: Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an
CRITICAL
◈ 2 sources · orig. NVD CVE
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special...
2021-11-04
NVD CVE
CVE-2020-25368: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link
CRITICAL
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the...
2021-11-04
NVD CVE
CVE-2020-25367: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link
CRITICAL
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha...
2021-11-04
NVD CVE
CVE-2020-25366: An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1
CRITICAL
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
2021-10-31
NVD CVE
CVE-2020-25912: A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit
CRITICAL
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
2021-09-16
NVD CVE
CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
CRITICAL
◈ 2 sources · orig. NVD CVE
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
2021-09-14
NVD CVE
CVE-2021-36582: In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to t
CRITICAL
In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to...
2021-09-14
NVD CVE
CVE-2021-36581: Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to uplo
CRITICAL
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to...
2021-07-09
NVD CVE
CVE-2021-30116: Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild i
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The...
2021-05-26
NVD CVE
CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to
CRITICAL
◈ 2 sources · orig. NVD CVE
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with...