LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2021-11-03
CISA KEV
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in...
2021-11-03
CISA KEV
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit...
2021-11-03
CISA KEV
Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful...
2021-11-03
CISA KEV
VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to...
2021-11-03
CISA KEV
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
2021-11-03
CISA KEV
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
2021-10-31
NVD CVE
CVE-2020-25912: A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit
CRITICAL
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
2021-09-16
NVD CVE
CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
CRITICAL
◈ 2 sources · orig. NVD CVE
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
2021-09-14
NVD CVE
CVE-2021-36581: Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to uplo
CRITICAL
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to...
2021-09-14
NVD CVE
CVE-2021-36582: In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to t
CRITICAL
In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to...
2021-07-09
NVD CVE
CVE-2021-30116: Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild i
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The...
2021-05-26
NVD CVE
CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to
CRITICAL
◈ 2 sources · orig. NVD CVE
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with...
2021-05-19
NVD CVE
CVE-2017-17674: BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due t
CRITICAL
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port...
2021-05-03
NVD CVE
CVE-2021-28860: In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an
CRITICAL
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in...
2021-04-23
NVD CVE
CVE-2021-22893: Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication b
CRITICAL
◈ 2 sources · orig. NVD CVE
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can...
2021-04-23
NVD CVE
CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting fro
CRITICAL
◈ 2 sources · orig. NVD CVE
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
2021-04-09
NVD CVE
CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
2021-03-04
NVD CVE
CVE-2020-24913: A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profil
CRITICAL
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
2021-03-04
NVD CVE
CVE-2020-24914: A PHP object injection bug in profile.php in qcubed (all versions including 3.1.
CRITICAL
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a...
2021-02-27
NVD CVE
CVE-2021-27132: SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header
CRITICAL
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
2021-02-24
NVD CVE
CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a v
CRITICAL
◈ 2 sources · orig. NVD CVE
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted...
2021-02-16
NVD CVE
CVE-2020-24841: PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.j
CRITICAL
PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent...
2021-02-04
NVD CVE
CVE-2021-20016: A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a re
CRITICAL
◈ 2 sources · orig. NVD CVE
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability...
2020-12-21
NVD CVE
CVE-2020-35276: EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can
CRITICAL
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
2020-12-11
NVD CVE
CVE-2020-29574: An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04
CRITICAL
◈ 2 sources · orig. NVD CVE
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
2020-11-27
NVD CVE
CVE-2017-15681: In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists w
CRITICAL
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
2020-11-02
NVD CVE
CVE-2020-24881: SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file
CRITICAL
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
2020-10-28
NVD CVE
CVE-2018-19949: If exploited, this command injection vulnerability could allow remote attackers
CRITICAL
◈ 2 sources · orig. NVD CVE
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS...
2020-10-23
NVD CVE
CVE-2020-25466: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which c
CRITICAL
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
2020-10-20
NVD CVE
CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E
CRITICAL
◈ 2 sources · orig. NVD CVE
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network...
2020-10-12
NVD CVE
CVE-2020-26867: ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deseria
CRITICAL
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
2020-09-30
NVD CVE
CVE-2018-5353: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 bui
CRITICAL
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server...
2020-09-14
NVD CVE
CVE-2020-25576: An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of
CRITICAL
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
2020-09-03
NVD CVE
CVE-2020-24193: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System
CRITICAL
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.
2020-07-24
NVD CVE
CVE-2020-12812: An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6
CRITICAL
◈ 2 sources · orig. NVD CVE
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of...
2020-05-21
NVD CVE
CVE-2020-0901: A remote code execution vulnerability exists in Microsoft Excel software when th
CRITICAL
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code...
2020-05-06
NVD CVE
CVE-2020-3187: A vulnerability in the web services interface of Cisco Adaptive Security Applian
CRITICAL
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory...
2020-05-01
NVD CVE
CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti
CRITICAL
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the...
2020-03-12
NVD CVE
CVE-2020-0796: A remote code execution vulnerability exists in the way that the Microsoft Serve
CRITICAL
◈ 2 sources · orig. NVD CVE
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
2020-03-02
NVD CVE
CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
CRITICAL
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).