Skip to content
COOEY
LIVE FEED
1828 events · 4 sources · newest first
2021-11-03 CISA KEV
VMware ESXi OpenSLP Use-After-Free Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
2021-11-03 CISA KEV
SonicWall SSLVPN SMA100 SQL Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
2021-11-03 CISA KEV
VMware vCenter Server Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges...
2021-11-03 CISA KEV
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
2021-11-03 CISA KEV
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability...
2021-11-03 CISA KEV
Ivanti Pulse Connect Secure Use-After-Free Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
2021-11-03 CISA KEV
VMware vCenter Server Improper Input Validation Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
2021-11-03 CISA KEV
Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
2021-11-03 CISA KEV
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
2021-11-03 CISA KEV
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
2021-11-03 CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03 CISA KEV
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the...
2021-11-03 CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03 CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03 CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03 CISA KEV
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who...
2021-11-03 CISA KEV
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
2021-11-03 CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
2021-11-03 CISA KEV
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
2021-11-03 CISA KEV
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code...
2021-11-03 CISA KEV
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate...
2021-11-03 CISA KEV
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.
2021-11-03 CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
2021-11-03 CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform...
2021-11-03 CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially...
2021-11-03 CISA KEV
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which...
2021-11-03 CISA KEV
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
2021-11-03 CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03 CISA KEV
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
2021-11-03 CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
2021-11-03 CISA KEV
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
2021-11-03 CISA KEV
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully...
2021-11-03 CISA KEV
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
2021-11-03 CISA KEV
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.
2021-11-03 CISA KEV
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute...
◀ PREV PAGE 44 / 46 NEXT ▶