Skip to content
COOEY
LIVE FEED
3623 events · 4 sources · newest first
2022-03-25 CISA KEV
Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.
2022-03-25 CISA KEV
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.
2022-03-25 CISA KEV
QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
2022-03-25 CISA KEV
Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
2022-03-25 CISA KEV
Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.
2022-03-25 CISA KEV
A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an...
2022-03-25 CISA KEV
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
2022-03-25 CISA KEV
Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
2022-03-25 CISA KEV
Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.
2022-03-25 CISA KEV
Webmin Command Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
2022-03-25 CISA KEV
Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
2022-03-25 CISA KEV
Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
2022-03-25 CISA KEV
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
2022-03-25 CISA KEV
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
2022-03-25 CISA KEV
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
2022-03-25 CISA KEV
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of...
2022-03-25 CISA KEV
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
2022-03-25 CISA KEV
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
2022-03-25 CISA KEV
VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
2022-03-25 CISA KEV
LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.
2022-03-25 CISA KEV
VMware Tanzu Spring Data Commons Property Binder Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
2022-03-25 CISA KEV
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
2022-03-25 CISA KEV
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due...
2022-03-25 CISA KEV
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
2022-03-25 CISA KEV
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands
2022-03-23 NVD CVE
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
2022-03-18 NVD CVE
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary...
2022-03-18 NVD CVE
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
2022-03-17 NVD CVE
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
2022-03-17 NVD CVE
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an...
2022-03-15 CISA KEV
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
◀ PREV PAGE 76 / 91 NEXT ▶