LIVE FEED
3620 events · 4 sources · newest first
Events in view
3620
all sources
Critical
1842
severity
Active sources
4
collectors
Last sync
2026-08-28 00:00
UTC
2023-03-30
CISA KEV
Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.
2023-03-30
CISA KEV
Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely.
2023-03-30
CISA KEV
Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.
2023-03-30
CISA KEV
Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web...
2023-03-30
CISA KEV
Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.
2023-03-30
CISA KEV
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
2023-03-30
CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.
2023-03-27
NVD CVE
CVE-2023-25261: Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This af
CRITICAL
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the...
2023-03-24
NVD CVE
CVE-2022-45597: ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor
CRITICAL
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport...
2023-03-17
NVD CVE
CVE-2023-28531: ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the inten
CRITICAL
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
2023-03-15
CISA KEV
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
2023-03-15
NVD CVE
CVE-2023-28461: Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote cod
CRITICAL
◈ 2 sources · orig. NVD CVE
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without...
2023-03-14
CISA KEV
Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.
2023-03-14
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
2023-03-14
CISA KEV
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
2023-03-10
CISA KEV
Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the...
2023-03-10
CISA KEV
XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server....
2023-03-09
NVD CVE
CVE-2023-27205: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
2023-03-09
NVD CVE
CVE-2023-27202: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
2023-03-09
NVD CVE
CVE-2023-27204: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
2023-03-09
NVD CVE
CVE-2023-27203: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
2023-03-07
CISA KEV
Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.
2023-03-07
CISA KEV
Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.
2023-03-07
CISA KEV
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
2023-03-03
NVD CVE
CVE-2022-45553: An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.
CRITICAL
An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.
2023-03-03
NVD CVE
CVE-2022-45551: An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.1
CRITICAL
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.
2023-03-02
NVD CVE
CVE-2022-46501: Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contai
CRITICAL
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.
2023-02-27
CISA KEV
ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This...
2023-02-24
NVD CVE
CVE-2021-33224: File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attack
CRITICAL
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
2023-02-21
NVD CVE
CVE-2023-24080: A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222
CRITICAL
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.
2023-02-21
NVD CVE
CVE-2023-0946: A vulnerability has been found in SourceCodester Best POS Management System 1.0
MEDIUM
A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The...
2023-02-21
CISA KEV
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
2023-02-21
CISA KEV
The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.
2023-02-21
CISA KEV
The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.
2023-02-16
CISA KEV
Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
2023-02-14
CISA KEV
Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use...
2023-02-14
CISA KEV
Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.
2023-02-14
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2023-02-14
NVD CVE
Microsoft Word Remote Code Execution Vulnerability
2023-02-14
CISA KEV
Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.