LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 12:00
UTC
2020-03-02
NVD CVE
CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
CRITICAL
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
2020-02-24
NVD CVE
CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting inc
CRITICAL
◈ 2 sources · orig. NVD CVE
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection....
2019-12-27
NVD CVE
CVE-2019-19781: An issue was discovered in Citrix Application Delivery Controller (ADC) and Gate
CRITICAL
◈ 2 sources · orig. NVD CVE
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
2019-11-27
NVD CVE
CVE-2019-18184: Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell m
CRITICAL
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
2019-08-16
NVD CVE
CVE-2019-15107: An issue was discovered in Webmin <=1.920. The parameter old in password_change.
CRITICAL
◈ 2 sources · orig. NVD CVE
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
2019-08-08
NVD CVE
CVE-2019-1971: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Softwar
CRITICAL
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root...
2019-08-07
NVD CVE
CVE-2019-1895: A vulnerability in the Virtual Network Computing (VNC) console implementation of
CRITICAL
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session...
2019-05-22
NVD CVE
CVE-2019-11634: Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CRITICAL
◈ 2 sources · orig. NVD CVE
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
2019-04-26
NVD CVE
CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar
CRITICAL
◈ 2 sources · orig. NVD CVE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability...
2019-02-05
NVD CVE
CVE-2017-18362: ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable
CRITICAL
◈ 2 sources · orig. NVD CVE
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively...
2019-02-05
NVD CVE
CVE-2018-20753: Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively...
2018-12-21
NVD CVE
CVE-2018-19323: The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRA
CRITICAL
◈ 2 sources · orig. NVD CVE
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine...
2018-11-20
NVD CVE
CVE-2018-18861: Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via t
CRITICAL
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
2018-10-11
NVD CVE
CVE-2018-9206: Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Uploa
CRITICAL
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
2018-07-19
NVD CVE
CVE-2018-7602: A remote code execution vulnerability exists within multiple subsystems of Drupa
CRITICAL
◈ 2 sources · orig. NVD CVE
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site...
2018-05-31
NVD CVE
CVE-2018-11138: The '/common/download_agent_installer.php' script in the Quest KACE System Manag
CRITICAL
◈ 2 sources · orig. NVD CVE
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
2018-04-11
NVD CVE
CVE-2018-1273: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older
CRITICAL
◈ 2 sources · orig. NVD CVE
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated...
2018-01-29
NVD CVE
CVE-2018-0101: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco
CRITICAL
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or...
2017-10-04
NVD CVE
CVE-2017-12149: In Jboss Application Server as shipped with Red Hat Enterprise Application Platf
CRITICAL
◈ 2 sources · orig. NVD CVE
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it...
2017-08-23
NVD CVE
CVE-2017-11357: Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restri
CRITICAL
◈ 2 sources · orig. NVD CVE
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
2017-06-29
NVD CVE
CVE-2017-10684: In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function
CRITICAL
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
2017-06-29
NVD CVE
CVE-2017-10685: In ncurses 6.0, there is a format string vulnerability in the fmt_entry function
CRITICAL
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
2017-05-23
NVD CVE
CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif
CRITICAL
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
2017-04-06
NVD CVE
CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7
CRITICAL
◈ 2 sources · orig. NVD CVE
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach...
2016-04-07
NVD CVE
CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a den
CRITICAL
◈ 2 sources · orig. NVD CVE
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
2012-08-28
NVD CVE
CVE-2012-4681: Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Orac
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager...
2012-05-03
NVD CVE
CVE-2012-1710: Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in
CRITICAL
◈ 2 sources · orig. NVD CVE
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors...
2010-08-11
NVD CVE
CVE-2010-2861: Multiple directory traversal vulnerabilities in the administrator console in Ado
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1)...