LIVE FEED
3632 events · 4 sources · newest first
Events in view
3632
all sources
Critical
1853
severity
Active sources
4
collectors
Last sync
2026-08-29 12:00
UTC
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an...
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
2022-03-15
CISA KEV
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
2022-03-15
CISA KEV
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
2022-03-15
CISA KEV
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
CRITICAL
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
2022-03-11
NVD CVE
CVE-2021-44620: A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B2020
CRITICAL
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
2022-03-10
NVD CVE
CVE-2022-23383: YzmCMS v6.3 is affected by broken access control. Without login, unauthorized ac
CRITICAL
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal...
2022-03-07
CISA KEV
VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
2022-03-07
CISA KEV
A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
2022-03-07
CISA KEV
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
2022-03-07
CISA KEV
NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.
2022-03-07
CISA KEV
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
2022-03-07
CISA KEV
Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
2022-03-07
CISA KEV
Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
2022-03-07
CISA KEV
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
2022-03-07
CISA KEV
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
2022-03-07
CISA KEV
NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.
2022-03-07
CISA KEV
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
2022-03-03
CISA KEV
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
2022-03-03
CISA KEV
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
2022-03-03
CISA KEV
The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
2022-03-03
CISA KEV
The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
2022-03-03
CISA KEV
Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.
2022-03-03
CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03
CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03
CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03
CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03
CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03
CISA KEV
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
2022-03-03
CISA KEV
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
2022-03-03
CISA KEV
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected...