LIVE FEED
3621 events · 4 sources · newest first
Events in view
3621
all sources
Critical
1843
severity
Active sources
4
collectors
Last sync
2026-08-28 06:00
UTC
2022-04-15
CISA KEV
InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
2022-04-15
CISA KEV
Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
2022-04-14
CISA KEV
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
CRITICAL
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
2022-04-13
CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
2022-04-13
CISA KEV
Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
2022-04-13
CISA KEV
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
2022-04-13
CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
2022-04-13
CISA KEV
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
2022-04-13
CISA KEV
Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
2022-04-13
CISA KEV
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
2022-04-13
CISA KEV
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
2022-04-13
CISA KEV
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
2022-04-13
CISA KEV
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
2022-04-12
NVD CVE
CVE-2022-27262: An arbitrary file upload vulnerability in the file upload module of Skipper v0.9
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
2022-04-12
NVD CVE
CVE-2022-27260: An arbitrary file upload vulnerability in the file upload component of ButterCMS
CRITICAL
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
2022-04-12
NVD CVE
CVE-2022-28397: An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation,...
2022-04-11
CISA KEV
QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
2022-04-11
CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11
NVD CVE
CVE-2021-37291: An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management
CRITICAL
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
2022-04-11
CISA KEV
Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.
2022-04-11
CISA KEV
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
2022-04-11
CISA KEV
Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
2022-04-11
CISA KEV
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
2022-04-11
CISA KEV
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.
2022-04-11
CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-06
CISA KEV
Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
2022-04-06
CISA KEV
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
2022-04-06
CISA KEV
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
2022-04-04
CISA KEV
macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
2022-04-04
CISA KEV
A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
2022-04-04
CISA KEV
macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
2022-04-04
CISA KEV
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
2022-03-31
CISA KEV
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
2022-03-31
CISA KEV
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
2022-03-31
CISA KEV
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
2022-03-31
CISA KEV
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
2022-03-31
CISA KEV
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
2022-03-31
CISA KEV
An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
2022-03-31
CISA KEV
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
2022-03-30
NVD CVE
CVE-2021-46007: totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of
CRITICAL
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command...