LIVE FEED
1859 events · 13 sources · newest first
Events in view
1859
all sources
Critical
1859
severity
Active sources
13
collectors
Last sync
2026-08-29 18:00
UTC
All sources
NVD CVE · 1809CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2025-09-17
NVD CVE
CVE-2025-9242: An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process
CRITICAL
◈ 2 sources · orig. NVD CVE
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2...
2025-08-27
NVD CVE
CVE-2025-34157: Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-sit
CRITICAL
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a...
2025-08-20
NVD CVE
CVE-2010-20103: A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball
CRITICAL
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes...
2025-08-13
NVD CVE
CVE-2025-51452: In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login
CRITICAL
In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
2025-08-13
NVD CVE
CVE-2025-51451: In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sendi
CRITICAL
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
2025-07-22
CISA KEV
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive...
2025-07-22
CISA KEV
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch...
2025-07-20
CISA KEV
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with...
2025-07-10
CISA KEV
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN...
2025-06-25
CISA KEV
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
2025-05-30
NVD CVE
CVE-2025-48938: go-gh is a collection of Go modules to make authoring GitHub CLI extensions easi
CRITICAL
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could...
2025-05-21
NVD CVE
CVE-2025-34027: The Versa Concerto SD-WAN orchestration platform is vulnerable to an authenticat
CRITICAL
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload...
2025-05-05
CISA KEV
Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
2025-04-29
CISA KEV
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
2025-04-24
NVD CVE
CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a
CRITICAL
◈ 2 sources · orig. NVD CVE
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host...
2025-04-08
CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
2025-04-07
NVD CVE
CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/
CRITICAL
◈ 2 sources · orig. NVD CVE
Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code.
2025-04-07
CISA KEV
CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin),...
2025-04-04
CISA KEV
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
2025-04-03
NVD CVE
CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6,
CRITICAL
◈ 2 sources · orig. NVD CVE
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker...
2025-03-18
CISA KEV
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
2025-03-11
CISA KEV
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.
2025-03-04
CISA KEV
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
2025-03-03
CISA KEV
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run...
2025-02-18
CISA KEV
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
2025-02-13
CISA KEV
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These...
2025-01-24
CISA KEV
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute...
2025-01-23
NVD CVE
CVE-2025-23006: Pre-authentication deserialization of untrusted data vulnerability has been iden
CRITICAL
◈ 2 sources · orig. NVD CVE
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could...
2025-01-14
NVD CVE
CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CRITICAL
◈ 2 sources · orig. NVD CVE
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote...
2025-01-14
CISA KEV
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
2025-01-13
CISA KEV
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
2025-01-09
NVD CVE
CVE-2024-53704: An Improper Authentication vulnerability in the SSLVPN authentication mechanism
CRITICAL
◈ 2 sources · orig. NVD CVE
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
2025-01-08
NVD CVE
CVE-2025-0282: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5,
CRITICAL
◈ 2 sources · orig. NVD CVE
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote...
2025-01-08
CISA KEV
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
2025-01-07
CISA KEV
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This...
2025-01-07
CISA KEV
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an...
2024-12-17
CISA KEV
Cleo Multiple Products Unauthenticated File Upload Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or...
2024-12-13
NVD CVE
CVE-2024-55956: In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.
CRITICAL
◈ 2 sources · orig. NVD CVE
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the...
2024-12-13
CISA KEV
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
2024-12-04
CISA KEV
CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.