Skip to content
COOEY
LIVE FEED
3623 events · 4 sources · newest first
2022-03-25 CISA KEV
A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote...
2022-03-25 CISA KEV
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or...
2022-03-25 CISA KEV
When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
2022-03-25 CISA KEV
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be...
2022-03-25 CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
2022-03-25 CISA KEV
Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
2022-03-25 CISA KEV
Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
2022-03-25 CISA KEV
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
2022-03-25 CISA KEV
The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
2022-03-25 CISA KEV
Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.
2022-03-25 CISA KEV
Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
2022-03-25 CISA KEV
Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
2022-03-25 CISA KEV
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
2022-03-25 CISA KEV
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
2022-03-25 CISA KEV
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
2022-03-25 CISA KEV
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
2022-03-25 CISA KEV
The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
2022-03-25 CISA KEV
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
2022-03-25 CISA KEV
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
2022-03-25 CISA KEV
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.
2022-03-25 CISA KEV
A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
2022-03-25 CISA KEV
HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.
2022-03-25 CISA KEV
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
2022-03-25 CISA KEV
sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
2022-03-25 CISA KEV
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
2022-03-25 CISA KEV
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
2022-03-25 CISA KEV
Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
2022-03-25 CISA KEV
Adobe ColdFusion Directory Traversal Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
2022-03-25 CISA KEV
Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
2022-03-25 CISA KEV
Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
2022-03-25 CISA KEV
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
2022-03-25 CISA KEV
HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
2022-03-25 CISA KEV
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.
2022-03-25 CISA KEV
A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a...
2022-03-25 CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
2022-03-25 CISA KEV
Sitecore XP Remote Command Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
2022-03-25 CISA KEV
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
2022-03-25 CISA KEV
D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.
2022-03-25 CISA KEV
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.
2022-03-25 CISA KEV
smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
◀ PREV PAGE 75 / 91 NEXT ▶