Skip to content
COOEY
LIVE FEED
329 events · 13 sources · newest first
2025-01-08 CISA KEV
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
2025-01-07 CISA KEV
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This...
2025-01-07 CISA KEV
Mitel MiCollab Path Traversal Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an...
2024-12-17 CISA KEV
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or...
2024-12-13 CISA KEV
Cleo Multiple Products Unrestricted File Upload Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
2024-12-04 CISA KEV
CyberPanel Incorrect Default Permissions Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.
2024-12-03 CISA KEV
Zyxel Multiple Firewalls Path Traversal Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
2024-11-25 CISA KEV
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
2024-11-18 CISA KEV
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
2024-11-18 CISA KEV
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
2024-11-12 CISA KEV
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.
2024-11-07 CISA KEV
CyberPanel Incorrect Default Permissions Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.
2024-10-22 CISA KEV
Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
2024-10-17 CISA KEV
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
2024-10-15 CISA KEV
Mozilla Firefox Use-After-Free Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
2024-10-15 CISA KEV
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
2024-09-16 CISA KEV
Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.
2024-09-09 CISA KEV
Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
2024-09-09 CISA KEV
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
2024-08-19 CISA KEV
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
2024-07-30 CISA KEV
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user...
2024-06-13 CISA KEV
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
2024-06-12 CISA KEV
PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
2024-05-30 CISA KEV
Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.
2024-05-30 CISA KEV
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with...
2024-05-20 CISA KEV
NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.
2024-05-14 CISA KEV
Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
2024-04-12 CISA KEV
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
2024-03-26 CISA KEV
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
2024-03-25 CISA KEV
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
2024-03-25 CISA KEV
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
2024-03-07 CISA KEV
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
2024-03-04 CISA KEV
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege...
2024-02-22 CISA KEV
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.
2024-02-15 CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the...
2024-02-13 CISA KEV
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
2024-02-09 CISA KEV
Fortinet FortiOS Out-of-Bound Write Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
2024-01-31 CISA KEV
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker...
2024-01-24 CISA KEV
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
2024-01-18 CISA KEV
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
◀ PREV PAGE 02 / 09 NEXT ▶