LIVE FEED
3620 events · 4 sources · newest first
Events in view
3620
all sources
Critical
1842
severity
Active sources
4
collectors
Last sync
2026-08-28 00:00
UTC
2023-08-09
CISA KEV
Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).
2023-08-09
NVD CVE
CVE-2023-33468: KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.13
CRITICAL
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection...
2023-08-08
NVD CVE
Windows System Assessment Tool Elevation of Privilege Vulnerability
2023-08-08
NVD CVE
Windows Mobile Device Management Elevation of Privilege Vulnerability
2023-08-07
CISA KEV
Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the...
2023-08-05
NVD CVE
CVE-2023-36095: An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arb
CRITICAL
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.
2023-08-03
NVD CVE
CVE-2023-38951: ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authentica
CRITICAL
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a...
2023-08-03
NVD CVE
CVE-2023-37679: A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 a
CRITICAL
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
2023-08-03
NVD CVE
CVE-2023-38954: ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerabil
CRITICAL
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
2023-08-03
NVD CVE
CVE-2023-36082: An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote att
CRITICAL
An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials.
2023-08-01
NVD CVE
CVE-2023-34960: A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11
CRITICAL
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
2023-07-31
NVD CVE
CVE-2023-34842: Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote att
CRITICAL
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
2023-07-31
CISA KEV
Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in...
2023-07-31
NVD CVE
CVE-2023-37647: SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id p
CRITICAL
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
2023-07-27
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.
2023-07-26
CISA KEV
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
2023-07-25
NVD CVE
CVE-2023-35078: An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
2023-07-25
CISA KEV
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API...
2023-07-20
CISA KEV
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
2023-07-20
CISA KEV
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
2023-07-19
CISA KEV
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
2023-07-19
NVD CVE
Unauthenticated remote code execution
2023-07-17
CISA KEV
Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.
2023-07-13
CISA KEV
Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use...
2023-07-13
CISA KEV
SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
2023-07-12
NVD CVE
CVE-2023-33668: DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attac
CRITICAL
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
2023-07-11
CISA KEV
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.
2023-07-11
CISA KEV
Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.
2023-07-11
CISA KEV
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
2023-07-11
CISA KEV
Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.
2023-07-11
CISA KEV
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user....
2023-07-11
NVD CVE
CVE-2023-3617: A vulnerability was found in SourceCodester Best POS Management System 1.0. It h
HIGH
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation...
2023-07-07
CISA KEV
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
2023-06-29
CISA KEV
D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially...
2023-06-29
CISA KEV
Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.
2023-06-29
CISA KEV
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
2023-06-29
CISA KEV
D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save...
2023-06-29
CISA KEV
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
2023-06-29
CISA KEV
Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.
2023-06-29
CISA KEV
Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.