LIVE FEED
3640 events · 4 sources · newest first
Events in view
3640
all sources
Critical
1861
severity
Active sources
4
collectors
Last sync
2026-08-30 06:00
UTC
2020-10-20
NVD CVE
CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E
CRITICAL
◈ 2 sources · orig. NVD CVE
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network...
2020-10-12
NVD CVE
CVE-2020-26867: ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deseria
CRITICAL
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
2020-09-30
NVD CVE
CVE-2018-5353: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 bui
CRITICAL
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server...
2020-09-14
NVD CVE
CVE-2020-25576: An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of
CRITICAL
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
2020-09-03
NVD CVE
CVE-2020-24193: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System
CRITICAL
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.
2020-07-24
NVD CVE
CVE-2020-12812: An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6
CRITICAL
◈ 2 sources · orig. NVD CVE
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of...
2020-05-21
NVD CVE
CVE-2020-0901: A remote code execution vulnerability exists in Microsoft Excel software when th
CRITICAL
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code...
2020-05-06
NVD CVE
CVE-2020-3187: A vulnerability in the web services interface of Cisco Adaptive Security Applian
CRITICAL
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory...
2020-05-01
NVD CVE
CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti
CRITICAL
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the...
2020-03-12
NVD CVE
CVE-2020-0796: A remote code execution vulnerability exists in the way that the Microsoft Serve
CRITICAL
◈ 2 sources · orig. NVD CVE
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
2020-03-02
NVD CVE
CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
CRITICAL
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
2020-03-02
NVD CVE
CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
CRITICAL
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
2020-02-24
NVD CVE
CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting inc
CRITICAL
◈ 2 sources · orig. NVD CVE
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection....
2019-12-27
NVD CVE
CVE-2019-19781: An issue was discovered in Citrix Application Delivery Controller (ADC) and Gate
CRITICAL
◈ 2 sources · orig. NVD CVE
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
2019-12-23
NVD CVE
CVE-2019-11049: In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h
MEDIUM
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in...
2019-11-27
NVD CVE
CVE-2019-18184: Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell m
CRITICAL
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
2019-08-16
NVD CVE
CVE-2019-15107: An issue was discovered in Webmin <=1.920. The parameter old in password_change.
CRITICAL
◈ 2 sources · orig. NVD CVE
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
2019-08-08
NVD CVE
CVE-2019-1971: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Softwar
CRITICAL
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root...
2019-08-07
NVD CVE
CVE-2019-1895: A vulnerability in the Virtual Network Computing (VNC) console implementation of
CRITICAL
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session...
2019-05-22
NVD CVE
CVE-2019-11634: Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CRITICAL
◈ 2 sources · orig. NVD CVE
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
2019-04-26
NVD CVE
CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar
CRITICAL
◈ 2 sources · orig. NVD CVE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability...
2019-02-05
NVD CVE
CVE-2018-20753: Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively...
2019-02-05
NVD CVE
CVE-2017-18362: ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable
CRITICAL
◈ 2 sources · orig. NVD CVE
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively...
2018-12-21
NVD CVE
CVE-2018-19323: The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRA
CRITICAL
◈ 2 sources · orig. NVD CVE
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine...
2018-11-20
NVD CVE
CVE-2018-18861: Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via t
CRITICAL
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
2018-10-11
NVD CVE
CVE-2018-9206: Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Uploa
CRITICAL
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
2018-07-19
NVD CVE
CVE-2018-7602: A remote code execution vulnerability exists within multiple subsystems of Drupa
CRITICAL
◈ 2 sources · orig. NVD CVE
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site...
2018-05-31
NVD CVE
CVE-2018-11138: The '/common/download_agent_installer.php' script in the Quest KACE System Manag
CRITICAL
◈ 2 sources · orig. NVD CVE
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
2018-04-11
NVD CVE
CVE-2018-1273: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older
CRITICAL
◈ 2 sources · orig. NVD CVE
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated...
2018-01-29
NVD CVE
CVE-2018-0101: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco
CRITICAL
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or...
2017-10-04
NVD CVE
CVE-2017-12149: In Jboss Application Server as shipped with Red Hat Enterprise Application Platf
CRITICAL
◈ 2 sources · orig. NVD CVE
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it...
2017-08-23
NVD CVE
CVE-2017-11357: Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restri
CRITICAL
◈ 2 sources · orig. NVD CVE
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
2017-06-29
NVD CVE
CVE-2017-10685: In ncurses 6.0, there is a format string vulnerability in the fmt_entry function
CRITICAL
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
2017-06-29
NVD CVE
CVE-2017-10684: In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function
CRITICAL
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
2017-05-23
NVD CVE
CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif
CRITICAL
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
2017-04-06
NVD CVE
CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7
CRITICAL
◈ 2 sources · orig. NVD CVE
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach...
2016-04-07
NVD CVE
CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a den
CRITICAL
◈ 2 sources · orig. NVD CVE
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
2012-08-28
NVD CVE
CVE-2012-4681: Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Orac
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager...
2012-05-03
NVD CVE
CVE-2012-1710: Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in
CRITICAL
◈ 2 sources · orig. NVD CVE
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors...
2010-08-11
NVD CVE
CVE-2010-2861: Multiple directory traversal vulnerabilities in the administrator console in Ado
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1)...