LIVE FEED
3621 events · 4 sources · newest first
Events in view
3621
all sources
Critical
1843
severity
Active sources
4
collectors
Last sync
2026-08-28 06:00
UTC
2022-08-23
NVD CVE
CVE-2021-42232: TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vul
CRITICAL
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command....
2022-08-22
CISA KEV
A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.
2022-08-19
NVD CVE
CVE-2022-35201: Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RC
CRITICAL
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
2022-08-18
CISA KEV
Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.
2022-08-18
CISA KEV
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
2022-08-18
CISA KEV
Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect...
2022-08-18
CISA KEV
Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.
2022-08-18
CISA KEV
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's...
2022-08-18
CISA KEV
Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.
2022-08-18
CISA KEV
Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
2022-08-15
NVD CVE
CVE-2022-36262: An issue was discovered in taocms 3.0.2. in the website settings that allows arb
CRITICAL
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
2022-08-12
NVD CVE
CVE-2022-37042: Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality tha
CRITICAL
◈ 2 sources · orig. NVD CVE
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload...
2022-08-11
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained...
2022-08-11
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.
2022-08-09
CISA KEV
A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.
2022-08-09
CISA KEV
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
2022-08-05
NVD CVE
CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in infl
CRITICAL
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common...
2022-08-04
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.
2022-08-01
NVD CVE
CVE-2022-31321: The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input va
CRITICAL
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.
2022-07-29
CISA KEV
Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all...
2022-07-25
NVD CVE
CVE-2022-35131: Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted paylo
CRITICAL
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
2022-07-12
CISA KEV
Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.
2022-07-06
NVD CVE
CVE-2022-33047: OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via ot
CRITICAL
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
2022-07-06
NVD CVE
CVE-2022-32385: Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the
CRITICAL
Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
2022-07-06
NVD CVE
CVE-2022-32386: Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvS
CRITICAL
Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
2022-07-01
CISA KEV
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
2022-06-27
CISA KEV
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
2022-06-27
CISA KEV
Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.
2022-06-27
CISA KEV
A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.
2022-06-27
CISA KEV
The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
2022-06-27
CISA KEV
Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple...
2022-06-27
CISA KEV
Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.
2022-06-27
CISA KEV
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
2022-06-27
CISA KEV
Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
2022-06-17
NVD CVE
CVE-2021-45024: ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Ent
CRITICAL
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
2022-06-16
NVD CVE
CVE-2022-24562: In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POS
CRITICAL
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint,...
2022-06-16
NVD CVE
CVE-2022-31384: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
2022-06-16
NVD CVE
CVE-2022-31383: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
2022-06-16
NVD CVE
CVE-2022-31382: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
2022-06-14
NVD CVE
CVE-2021-42675: Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media dire
CRITICAL
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.