LIVE FEED
3621 events · 4 sources · newest first
Events in view
3621
all sources
Critical
1843
severity
Active sources
4
collectors
Last sync
2026-08-28 06:00
UTC
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
2022-05-23
CISA KEV
Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
2022-05-23
CISA KEV
Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
2022-05-16
CISA KEV
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
2022-05-16
NVD CVE
CVE-2022-29351: An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue...
2022-05-16
CISA KEV
A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
2022-05-10
CISA KEV
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
2022-05-04
NVD CVE
CVE-2022-29347: An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to exec
CRITICAL
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
2022-05-04
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2022-05-04
CISA KEV
The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
2022-05-04
CISA KEV
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
2022-05-04
NVD CVE
CVE-2022-28568: Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to R
CRITICAL
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the...
2022-05-04
NVD CVE
CVE-2021-43163: A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-
CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
2022-05-04
CISA KEV
A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
2022-05-04
CISA KEV
A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
2022-05-03
NVD CVE
CVE-2022-28118: SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plu
CRITICAL
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
2022-04-29
NVD CVE
CVE-2021-44596: Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code exe
CRITICAL
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the...
2022-04-28
NVD CVE
CVE-2021-41945: Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL
CRITICAL
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
2022-04-26
NVD CVE
CVE-2022-27984: CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the me
CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
2022-04-26
NVD CVE
CVE-2022-29499: The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows
CRITICAL
◈ 2 sources · orig. NVD CVE
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
2022-04-26
NVD CVE
CVE-2022-27985: CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin
CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
2022-04-25
CISA KEV
Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.
2022-04-25
CISA KEV
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
2022-04-25
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2022-04-25
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2022-04-25
CISA KEV
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
2022-04-25
CISA KEV
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
2022-04-25
CISA KEV
Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."
2022-04-25
NVD CVE
CVE-2022-28093: SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a loc
CRITICAL
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
2022-04-19
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.
2022-04-19
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
2022-04-19
CISA KEV
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
2022-04-15
CISA KEV
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.
2022-04-15
CISA KEV
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
2022-04-15
CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-04-15
CISA KEV
Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
2022-04-15
CISA KEV
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
2022-04-15
CISA KEV
A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
2022-04-15
CISA KEV
The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).