LIVE FEED
1357 events · 13 sources · newest first
Events in view
1357
all sources
Critical
0
severity
Active sources
13
collectors
Last sync
2026-08-29 00:00
UTC
All sources
NVD CVE · 1803CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2023-11-16
CISA KEV
Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.
2023-11-16
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2023-11-16
CISA KEV
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
2023-11-14
CISA KEV
Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
2023-11-14
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
2023-11-14
CISA KEV
Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.
2023-11-13
CISA KEV
Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted...
2023-11-13
CISA KEV
Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a...
2023-11-13
CISA KEV
Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a...
2023-11-13
CISA KEV
Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a...
2023-11-13
CISA KEV
Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a...
2023-11-08
CISA KEV
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a...
2023-10-31
CISA KEV
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system...
2023-10-26
CISA KEV
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
2023-10-23
CISA KEV
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to...
2023-10-16
CISA KEV
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can...
2023-10-10
CISA KEV
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
2023-10-10
CISA KEV
HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
2023-10-10
CISA KEV
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a...
2023-10-10
CISA KEV
Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.
2023-10-10
CISA KEV
Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.
2023-10-05
CISA KEV
Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.
2023-10-04
CISA KEV
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
2023-10-03
CISA KEV
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.
2023-10-02
CISA KEV
Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web...
2023-09-28
CISA KEV
Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code...
2023-09-25
CISA KEV
Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.
2023-09-25
CISA KEV
Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation.
2023-09-25
CISA KEV
Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use...
2023-09-21
CISA KEV
Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code...
2023-09-19
CISA KEV
MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to...
2023-09-18
CISA KEV
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.
2023-09-18
CISA KEV
Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.
2023-09-14
CISA KEV
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
2023-09-13
CISA KEV
Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that...
2023-09-13
CISA KEV
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
2023-09-12
CISA KEV
Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.
2023-09-12
CISA KEV
Microsoft Word contains an unspecified vulnerability that allows for information disclosure.
2023-09-11
CISA KEV
Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained...
2023-09-11
CISA KEV
Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061.