Skip to content
COOEY
LIVE FEED
1602 events · 13 sources · newest first
2025-02-06 CISA KEV
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View...
2025-02-06 CISA KEV
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
2025-02-05 CISA KEV
Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.
2025-02-04 CISA KEV
Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
2025-02-04 CISA KEV
Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.
2025-02-04 CISA KEV
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
2025-02-04 CISA KEV
Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
2025-01-29 CISA KEV
Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.
2025-01-23 CISA KEV
JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of...
2025-01-16 CISA KEV
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for...
2025-01-14 NVD CVE
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3,...
2025-01-14 CISA KEV
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
2025-01-14 CISA KEV
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
2025-01-14 CISA KEV
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
2025-01-13 CISA KEV
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious...
2025-01-07 CISA KEV
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
2025-01-01 DOJ FCA
Raytheon / RTX / Nightwing ↗ HIGH ◈ 7 sources · orig. DOJ FCA
Settled $8.4M — knowingly failed to comply with NIST SP 800-171 cybersecurity controls required by DoD contracts.
2025-01-01 DOJ FCA
Illumina Inc. ↗ HIGH ◈ 7 sources · orig. DOJ FCA
Settled $9.8M — genomic-sequencing maker sold systems with cybersecurity vulnerabilities while misrepresenting its security practices.
2025-01-01 DOJ FCA
Swiss Automation Inc. ↗ HIGH ◈ 7 sources · orig. DOJ FCA
Settled $421K — Illinois precision-machining contractor had cybersecurity deficiencies on covered defense information systems.
2025-01-01 DOJ FCA
Settled $875K — failed to maintain required cybersecurity controls and to have a compliant system security plan on DoD research contracts.
2025-01-01 DOJ FCA
Health Net Federal Services & Centene ↗ HIGH ◈ 7 sources · orig. DOJ FCA
Settled $11.25M — falsely certified compliance with cybersecurity requirements in providing managed federal health-care services.
2025-01-01 DOJ FCA
Hill ASC Inc. ↗ HIGH ◈ 7 sources · orig. DOJ FCA
Settled $14.75M — Maryland IT contractor failed to meet contractual cybersecurity requirements on federal contracts.
2025-01-01 DOJ FCA
MORSECORP Inc. ↗ HIGH ◈ 7 sources · orig. DOJ FCA
Settled $4.6M — defense contractor failed to implement required cybersecurity controls and misrepresented its compliance.
2025-01-01 DOJ FCA
Aero Turbine & Gallant Capital Partners ↗ HIGH ◈ 7 sources · orig. DOJ FCA
Settled $1.75M — California defense contractor maintained inadequate cybersecurity controls on covered systems.
2024-12-30 CISA KEV
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall....
2024-12-23 CISA KEV
Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a...
2024-12-19 CISA KEV
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.
2024-12-18 CISA KEV
Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
2024-12-18 CISA KEV
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality...
2024-12-18 CISA KEV
NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
2024-12-18 CISA KEV
NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
2024-12-16 CISA KEV
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
2024-12-16 CISA KEV
Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
2024-12-10 CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
2024-12-03 CISA KEV
ProjectSend Improper Authentication Vulnerability HIGH ◈ 2 sources · orig. NVD CVE
ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to...
2024-12-03 CISA KEV
North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct...
2024-11-27 NVD CVE
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series...
2024-11-21 CISA KEV
Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may...
2024-11-21 CISA KEV
Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.
2024-11-21 CISA KEV
Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.
◀ PREV PAGE 16 / 41 NEXT ▶