LIVE FEED
1530 events · 13 sources · newest first
Events in view
1530
all sources
Critical
1530
severity
Active sources
13
collectors
Last sync
2026-08-29 18:00
UTC
All sources
NVD CVE · 1809CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-01-19
NVD CVE
CVE-2026-23533: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX ClearCodec decode path when maliciously crafted residual data causes...
2026-01-19
NVD CVE
CVE-2026-23532: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between...
2026-01-19
NVD CVE
CVE-2026-23531: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the...
2026-01-14
NVD CVE
CVE-2026-22859: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in...
2026-01-14
NVD CVE
CVE-2026-22853: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated...
2026-01-14
NVD CVE
CVE-2026-22855: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This...
2026-01-14
NVD CVE
CVE-2026-22858: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char...
2026-01-12
NVD CVE
CVE-2026-22214: RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buf
CRITICAL
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incoming serial frame data. The...
2026-01-12
NVD CVE
CVE-2026-22213: RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buf
CRITICAL
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen()...
2026-01-07
NVD CVE
CVE-2026-22189: The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains
CRITICAL
The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing...
2026-01-07
NVD CVE
CVE-2025-12543: A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBo
CRITICAL
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a...
2025-12-31
NVD CVE
CVE-2025-34468: libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a s
CRITICAL
libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer...
2025-12-22
NVD CVE
CVE-2025-67288: An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers t
CRITICAL
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file...
2025-12-19
NVD CVE
CVE-2025-14733: An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process
CRITICAL
◈ 2 sources · orig. NVD CVE
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2...
2025-11-06
NVD CVE
CVE-2022-50589: SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within t
CRITICAL
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers...
2025-10-17
NVD CVE
CVE-2025-34282: ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulner
CRITICAL
ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If...
2025-10-14
NVD CVE
CVE-2025-34267: Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled c
CRITICAL
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules...
2025-09-24
NVD CVE
CVE-2025-10585: Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote a
CRITICAL
◈ 2 sources · orig. NVD CVE
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
2025-09-18
NVD CVE
CVE-2025-10035: A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MF
CRITICAL
◈ 2 sources · orig. NVD CVE
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading...
2025-09-17
NVD CVE
CVE-2025-9242: An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process
CRITICAL
◈ 2 sources · orig. NVD CVE
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2...
2025-08-27
NVD CVE
CVE-2025-34157: Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-sit
CRITICAL
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a...
2025-08-20
NVD CVE
CVE-2010-20103: A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball
CRITICAL
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes...
2025-08-13
NVD CVE
CVE-2025-51452: In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login
CRITICAL
In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
2025-08-13
NVD CVE
CVE-2025-51451: In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sendi
CRITICAL
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
2025-05-30
NVD CVE
CVE-2025-48938: go-gh is a collection of Go modules to make authoring GitHub CLI extensions easi
CRITICAL
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could...
2025-05-21
NVD CVE
CVE-2025-34027: The Versa Concerto SD-WAN orchestration platform is vulnerable to an authenticat
CRITICAL
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload...
2025-04-24
NVD CVE
CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a
CRITICAL
◈ 2 sources · orig. NVD CVE
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host...
2025-04-07
NVD CVE
CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/
CRITICAL
◈ 2 sources · orig. NVD CVE
Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code.
2025-04-03
NVD CVE
CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6,
CRITICAL
◈ 2 sources · orig. NVD CVE
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker...
2025-01-23
NVD CVE
CVE-2025-23006: Pre-authentication deserialization of untrusted data vulnerability has been iden
CRITICAL
◈ 2 sources · orig. NVD CVE
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could...
2025-01-14
NVD CVE
CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CRITICAL
◈ 2 sources · orig. NVD CVE
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote...
2025-01-09
NVD CVE
CVE-2024-53704: An Improper Authentication vulnerability in the SSLVPN authentication mechanism
CRITICAL
◈ 2 sources · orig. NVD CVE
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
2025-01-08
NVD CVE
CVE-2025-0282: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5,
CRITICAL
◈ 2 sources · orig. NVD CVE
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote...
2024-12-13
NVD CVE
CVE-2024-55956: In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.
CRITICAL
◈ 2 sources · orig. NVD CVE
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the...
2024-11-26
NVD CVE
CVE-2024-11680: ProjectSend versions prior to r1720 are affected by an improper authentication v
CRITICAL
◈ 2 sources · orig. NVD CVE
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling...
2024-11-22
NVD CVE
CVE-2024-52723: In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str f
CRITICAL
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
2024-11-19
NVD CVE
CVE-2024-52714: Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the f
CRITICAL
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
2024-11-18
NVD CVE
CVE-2024-0012: An authentication bypass in Palo Alto Networks PAN-OS software enables an unauth
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative...
2024-10-29
NVD CVE
CVE-2024-51378: getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel)
CRITICAL
◈ 2 sources · orig. NVD CVE
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or...
2024-10-29
NVD CVE
CVE-2024-51567: upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before
CRITICAL
◈ 2 sources · orig. NVD CVE
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing...