LIVE FEED
3614 events · 4 sources · newest first
Events in view
3614
all sources
Critical
1837
severity
Active sources
4
collectors
Last sync
2026-08-27 18:01
UTC
2023-12-20
NVD CVE
CVE-2023-50984: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip p
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.
2023-12-20
NVD CVE
CVE-2023-50985: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanG
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.
2023-12-20
NVD CVE
CVE-2023-50986: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
2023-12-20
NVD CVE
CVE-2023-50989: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerabil
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
2023-12-20
NVD CVE
CVE-2023-50992: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip pa
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.
2023-12-20
NVD CVE
CVE-2023-50990: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebo
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.
2023-12-11
CISA KEV
Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.
2023-12-07
CISA KEV
Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the...
2023-12-07
CISA KEV
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
2023-12-05
CISA KEV
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.
2023-12-05
CISA KEV
Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress.
2023-12-05
CISA KEV
Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
2023-12-05
CISA KEV
Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
2023-12-04
CISA KEV
Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that...
2023-12-04
CISA KEV
Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML...
2023-11-30
CISA KEV
ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.
2023-11-30
CISA KEV
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This...
2023-11-29
NVD CVE
CVE-2023-23325: Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a co
CRITICAL
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter.
2023-11-29
NVD CVE
CVE-2023-23324: Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hard
CRITICAL
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.
2023-11-28
NVD CVE
CVE-2023-48193: Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote a
CRITICAL
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not...
2023-11-21
NVD CVE
CVE-2023-49060: An attacker could have accessed internal pages or data by ex-filtrating a securi
CRITICAL
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
2023-11-21
CISA KEV
GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.
2023-11-16
CISA KEV
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
2023-11-16
CISA KEV
Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.
2023-11-16
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2023-11-14
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
2023-11-14
NVD CVE
CVE-2023-43902: Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7
CRITICAL
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a...
2023-11-14
CISA KEV
Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
2023-11-14
CISA KEV
Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.
2023-11-13
CISA KEV
Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a...
2023-11-13
CISA KEV
Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a...
2023-11-13
CISA KEV
SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.
2023-11-13
CISA KEV
Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted...
2023-11-13
CISA KEV
Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a...
2023-11-13
CISA KEV
Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a...
2023-11-10
NVD CVE
CVE-2023-47246: In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to cod
CRITICAL
◈ 2 sources · orig. NVD CVE
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
2023-11-08
CISA KEV
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a...
2023-11-07
CISA KEV
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on...
2023-11-02
NVD CVE
CVE-2023-46958: An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via
CRITICAL
An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.
2023-11-02
CISA KEV
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire...