LIVE FEED
3614 events · 4 sources · newest first
Events in view
3614
all sources
Critical
1837
severity
Active sources
4
collectors
Last sync
2026-08-27 18:01
UTC
2024-01-24
CISA KEV
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
2024-01-23
CISA KEV
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that...
2024-01-23
NVD CVE
CVE-2023-36177: An issue was discovered in badaix Snapcast version 0.27.0, allows remote attacke
CRITICAL
An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.
2024-01-22
CISA KEV
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
2024-01-20
NVD CVE
CVE-2023-51924: An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceMana
CRITICAL
An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
2024-01-20
NVD CVE
CVE-2023-51925: An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.actio
CRITICAL
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
2024-01-20
NVD CVE
CVE-2023-51927: YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the
CRITICAL
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.
2024-01-20
NVD CVE
CVE-2023-51928: An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.actio
CRITICAL
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
2024-01-20
NVD CVE
CVE-2023-51906: An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary
CRITICAL
An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.
2024-01-20
NVD CVE
CVE-2023-51892: An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute a
CRITICAL
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.
2024-01-19
NVD CVE
CVE-2023-51947: Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1
CRITICAL
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.
2024-01-19
NVD CVE
CVE-2024-23687: Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and
CRITICAL
Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including...
2024-01-19
NVD CVE
CVE-2024-23679: Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. A
CRITICAL
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
2024-01-18
CISA KEV
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
CRITICAL
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
2024-01-17
CISA KEV
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
2024-01-17
CISA KEV
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
2024-01-17
CISA KEV
Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple...
2024-01-16
CISA KEV
Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application...
2024-01-12
NVD CVE
CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9.
CRITICAL
◈ 2 sources · orig. NVD CVE
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute...
2024-01-10
CISA KEV
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted...
2024-01-10
CISA KEV
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This...
2024-01-10
CISA KEV
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated...
2024-01-09
NVD CVE
CVE-2023-26999: An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execut
CRITICAL
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.
2024-01-09
NVD CVE
CVE-2023-50643: An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to ex
CRITICAL
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
2024-01-08
CISA KEV
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
2024-01-08
CISA KEV
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.
2024-01-08
CISA KEV
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.
2024-01-08
CISA KEV
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
2024-01-08
CISA KEV
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
2024-01-08
CISA KEV
Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default...
2024-01-04
NVD CVE
CVE-2024-22051: CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnera
CRITICAL
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading...
2024-01-02
CISA KEV
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format...
2024-01-02
NVD CVE
CVE-2023-47458: An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate
CRITICAL
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
2024-01-02
CISA KEV
Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption...
2023-12-30
NVD CVE
CVE-2023-50651: TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote comman
CRITICAL
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
2023-12-21
CISA KEV
QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.
2023-12-21
CISA KEV
FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.
2023-12-20
NVD CVE
CVE-2023-50987: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.
2023-12-20
NVD CVE
CVE-2023-50988: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the band
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.
2023-12-20
NVD CVE
CVE-2023-50983: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerabil
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.