LIVE FEED
3614 events · 4 sources · newest first
Events in view
3614
all sources
Critical
1837
severity
Active sources
4
collectors
Last sync
2026-08-27 18:01
UTC
2024-04-23
CISA KEV
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
2024-04-12
CISA KEV
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
2024-04-11
CISA KEV
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.
2024-04-11
CISA KEV
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.
2024-04-04
CISA KEV
Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.
2024-04-04
CISA KEV
Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.
2024-03-26
CISA KEV
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
2024-03-25
CISA KEV
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
2024-03-25
CISA KEV
Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.
2024-03-25
CISA KEV
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
2024-03-12
NVD CVE
CVE-2023-42789: A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, For
CRITICAL
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0,...
2024-03-07
CISA KEV
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
2024-03-06
CISA KEV
Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.
2024-03-06
CISA KEV
Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.
2024-03-05
CISA KEV
Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to...
2024-03-05
CISA KEV
Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr...
2024-03-04
CISA KEV
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege...
2024-02-29
CISA KEV
Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
2024-02-29
NVD CVE
CVE-2024-23052: An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote at
CRITICAL
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.
2024-02-22
CISA KEV
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.
2024-02-21
NVD CVE
CVE-2024-1212: Unauthenticated remote attackers can access the system through the LoadMaster ma
CRITICAL
◈ 2 sources · orig. NVD CVE
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
2024-02-15
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
2024-02-15
CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the...
2024-02-13
CISA KEV
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
2024-02-13
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to...
2024-02-12
CISA KEV
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.
2024-02-09
CISA KEV
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
2024-02-09
NVD CVE
CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th
CRITICAL
◈ 2 sources · orig. NVD CVE
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through...
2024-02-08
NVD CVE
CVE-2024-24321: An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbi
CRITICAL
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
2024-02-06
NVD CVE
CVE-2024-24398: Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS bef
CRITICAL
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
2024-02-06
CISA KEV
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium,...
2024-02-06
NVD CVE
CVE-2023-46359: An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1
CRITICAL
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted...
2024-02-05
NVD CVE
CVE-2024-23054: An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that
CRITICAL
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
2024-02-02
NVD CVE
CVE-2024-22901: Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
2024-02-02
NVD CVE
CVE-2024-22902: Vinchin Backup & Recovery v7.2 was discovered to be configured with default root
CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
2024-01-31
CISA KEV
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
CRITICAL
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker...
2024-01-31
CISA KEV
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.
2024-01-30
NVD CVE
CVE-2024-21488: Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command
HIGH
Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the...
2024-01-29
NVD CVE
CVE-2024-1015: Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting
CRITICAL
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web...
2024-01-25
NVD CVE
CVE-2024-22922: An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe a
CRITICAL
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php