LIVE FEED
3620 events · 4 sources · newest first
Events in view
3620
all sources
Critical
1842
severity
Active sources
4
collectors
Last sync
2026-08-28 00:00
UTC
2022-11-22
NVD CVE
CVE-2022-42989: ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XS
CRITICAL
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
2022-11-22
NVD CVE
CVE-2022-44194: Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_d
CRITICAL
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.
2022-11-22
NVD CVE
Fusiondirectory 1.3 suffers from Improper Session Handling.
2022-11-15
NVD CVE
CVE-2022-42122: A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7
CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into...
2022-11-15
NVD CVE
CVE-2022-42120: A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 thr
CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a...
2022-11-14
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2022-11-10
NVD CVE
CVE-2022-44087: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
2022-11-10
NVD CVE
CVE-2022-44089: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
2022-11-10
NVD CVE
CVE-2022-44088: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
2022-11-08
CISA KEV
Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was...
2022-11-08
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2022-11-08
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
2022-11-08
CISA KEV
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
2022-11-08
CISA KEV
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.
2022-11-08
CISA KEV
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369...
2022-11-08
CISA KEV
Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This...
2022-10-28
CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-10-25
CISA KEV
Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges.
2022-10-25
NVD CVE
CVE-2022-38580: Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
CRITICAL
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
2022-10-24
CISA KEV
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with...
2022-10-24
CISA KEV
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a...
2022-10-24
CISA KEV
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid...
2022-10-24
CISA KEV
The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the...
2022-10-24
CISA KEV
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by...
2022-10-24
CISA KEV
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number...
2022-10-20
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.
2022-10-20
CISA KEV
The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
2022-10-19
NVD CVE
CVE-2022-41415: Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflo
CRITICAL
Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode...
2022-10-18
NVD CVE
CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortine
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and...
2022-10-17
NVD CVE
CVE-2022-40055: An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to
CRITICAL
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.
2022-10-12
NVD CVE
CVE-2022-33106: WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit atta
CRITICAL
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
2022-10-11
CISA KEV
Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.
2022-10-11
CISA KEV
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially...
2022-09-30
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the...
2022-09-30
NVD CVE
CVE-2022-35156: Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnera
CRITICAL
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
2022-09-30
CISA KEV
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
2022-09-30
CISA KEV
Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private...
2022-09-23
CISA KEV
A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
2022-09-22
CISA KEV
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.
2022-09-21
NVD CVE
CVE-2022-38619: SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability
CRITICAL
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.