LIVE FEED
3620 events · 4 sources · newest first
Events in view
3620
all sources
Critical
1842
severity
Active sources
4
collectors
Last sync
2026-08-28 00:00
UTC
2022-09-21
NVD CVE
CVE-2022-40030: SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL
CRITICAL
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
2022-09-16
NVD CVE
CVE-2022-36536: An issue in the component post_applogin.php of Super Flexible Software GmbH & Co
CRITICAL
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
2022-09-15
NVD CVE
CVE-2022-37257: Prototype pollution vulnerability in function convertLater in npm-convert.js in
CRITICAL
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
2022-09-15
CISA KEV
Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation.
2022-09-15
CISA KEV
The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buffer overflow vulnerability that allows for privilege escalation. Code Aurora is used in third-party products such as Qualcomm...
2022-09-15
CISA KEV
The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to...
2022-09-15
CISA KEV
Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this...
2022-09-15
CISA KEV
Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation.
2022-09-15
CISA KEV
Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.
2022-09-14
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2022-09-14
CISA KEV
Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges.
2022-09-08
CISA KEV
Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
2022-09-08
CISA KEV
In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.
2022-09-08
CISA KEV
Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information.
2022-09-08
CISA KEV
Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.
2022-09-08
CISA KEV
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.
2022-09-08
CISA KEV
The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and...
2022-09-08
CISA KEV
D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.
2022-09-08
CISA KEV
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed...
2022-09-08
CISA KEV
Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page....
2022-09-08
CISA KEV
Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test...
2022-09-08
CISA KEV
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
2022-09-02
NVD CVE
CVE-2022-36640: influxData influxDB before v1.8.10 contains no authentication mechanism or contr
CRITICAL
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's...
2022-08-31
NVD CVE
CVE-2022-36202: Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edo
CRITICAL
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
2022-08-30
NVD CVE
CVE-2022-37176: Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability
CRITICAL
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.
2022-08-29
NVD CVE
CVE-2022-32993: TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue vi
CRITICAL
TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
2022-08-28
NVD CVE
CVE-2022-37053: TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpin
CRITICAL
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
2022-08-28
NVD CVE
CVE-2022-38555: Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
CRITICAL
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
2022-08-25
CISA KEV
PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and...
2022-08-25
CISA KEV
dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location....
2022-08-25
CISA KEV
Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.
2022-08-25
CISA KEV
Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.
2022-08-25
CISA KEV
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to...
2022-08-25
CISA KEV
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web...
2022-08-25
CISA KEV
Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.
2022-08-25
CISA KEV
Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution.
2022-08-25
CISA KEV
In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.
2022-08-25
CISA KEV
PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system...
2022-08-23
NVD CVE
CVE-2021-42627: The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.
CRITICAL
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage...
2022-08-23
NVD CVE
CVE-2021-42232: TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vul
CRITICAL
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command....