Skip to content
COOEY
LIVE FEED
1602 events · 13 sources · newest first
2022-03-25 CISA KEV
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
2022-03-25 CISA KEV
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
2022-03-25 CISA KEV
Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
2022-03-25 CISA KEV
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
2022-03-25 CISA KEV
HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
2022-03-25 CISA KEV
Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
2022-03-25 CISA KEV
Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
2022-03-25 CISA KEV
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
2022-03-25 CISA KEV
sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
2022-03-25 CISA KEV
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
2022-03-25 CISA KEV
Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
2022-03-25 CISA KEV
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
2022-03-25 CISA KEV
The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
2022-03-25 CISA KEV
Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.
2022-03-25 CISA KEV
Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
2022-03-15 CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-15 CISA KEV
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
2022-03-08 DOJ FCA
Comprehensive Health Services LLC HIGH
Settled $930K — falsely represented compliance with contractual cybersecurity requirements for medical services at U.S. government facilities in Iraq and Afghanistan.
2022-03-07 CISA KEV
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
2022-03-07 CISA KEV
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
2022-03-07 CISA KEV
Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
2022-03-07 CISA KEV
Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
2022-03-07 CISA KEV
NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.
2022-03-07 CISA KEV
NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.
2022-03-07 CISA KEV
Mozilla Firefox Use-After-Free Vulnerability HIGH ◈ 2 sources · orig. NVD CVE
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
2022-03-07 CISA KEV
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
2022-03-07 CISA KEV
A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
2022-03-07 CISA KEV
VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
2022-03-03 CISA KEV
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.
2022-03-03 CISA KEV
Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.
2022-03-03 CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03 CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03 CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03 CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03 CISA KEV
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass...
2022-03-03 CISA KEV
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected...
2022-03-03 CISA KEV
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
2022-03-03 CISA KEV
The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
2022-03-03 CISA KEV
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS)...
2022-03-03 CISA KEV
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS)...
◀ PREV PAGE 31 / 41 NEXT ▶