LIVE FEED
3639 events · 4 sources · newest first
Events in view
3639
all sources
Critical
1860
severity
Active sources
4
collectors
Last sync
2026-08-30 00:00
UTC
2021-11-03
CISA KEV
Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.
2021-11-03
CISA KEV
Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.
2021-11-03
CISA KEV
Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.
2021-11-03
CISA KEV
Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.
2021-11-03
CISA KEV
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
2021-11-03
CISA KEV
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.
2021-11-03
CISA KEV
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.
2021-11-03
CISA KEV
PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.
2021-11-03
CISA KEV
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.
2021-11-03
CISA KEV
Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
2021-10-31
NVD CVE
CVE-2020-25912: A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit
CRITICAL
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
2021-09-16
NVD CVE
CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
CRITICAL
◈ 2 sources · orig. NVD CVE
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
2021-09-14
NVD CVE
CVE-2021-36582: In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to t
CRITICAL
In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to...
2021-09-14
NVD CVE
CVE-2021-36581: Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to uplo
CRITICAL
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to...
2021-07-09
NVD CVE
CVE-2021-30116: Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild i
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The...
2021-05-26
NVD CVE
CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to
CRITICAL
◈ 2 sources · orig. NVD CVE
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with...
2021-05-19
NVD CVE
CVE-2017-17674: BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due t
CRITICAL
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port...
2021-05-03
NVD CVE
CVE-2021-28860: In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an
CRITICAL
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in...
2021-04-23
NVD CVE
CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting fro
CRITICAL
◈ 2 sources · orig. NVD CVE
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
2021-04-23
NVD CVE
CVE-2021-22893: Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication b
CRITICAL
◈ 2 sources · orig. NVD CVE
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can...
2021-04-09
NVD CVE
CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
2021-03-04
NVD CVE
CVE-2020-24914: A PHP object injection bug in profile.php in qcubed (all versions including 3.1.
CRITICAL
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a...
2021-03-04
NVD CVE
CVE-2020-24913: A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profil
CRITICAL
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
2021-02-27
NVD CVE
CVE-2021-27132: SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header
CRITICAL
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
2021-02-24
NVD CVE
CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a v
CRITICAL
◈ 2 sources · orig. NVD CVE
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted...
2021-02-16
NVD CVE
CVE-2020-24841: PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.j
CRITICAL
PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent...
2021-02-04
NVD CVE
CVE-2021-20016: A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a re
CRITICAL
◈ 2 sources · orig. NVD CVE
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability...
2020-12-21
NVD CVE
CVE-2020-35276: EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can
CRITICAL
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
2020-12-11
NVD CVE
CVE-2020-29574: An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04
CRITICAL
◈ 2 sources · orig. NVD CVE
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
2020-11-27
NVD CVE
CVE-2017-15681: In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists w
CRITICAL
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
2020-11-02
NVD CVE
CVE-2020-24881: SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file
CRITICAL
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
2020-10-28
NVD CVE
CVE-2018-19949: If exploited, this command injection vulnerability could allow remote attackers
CRITICAL
◈ 2 sources · orig. NVD CVE
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS...
2020-10-23
NVD CVE
CVE-2020-25466: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which c
CRITICAL
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
2020-10-20
NVD CVE
CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E
CRITICAL
◈ 2 sources · orig. NVD CVE
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network...