LIVE FEED
1859 events · 13 sources · newest first
Events in view
1859
all sources
Critical
1859
severity
Active sources
13
collectors
Last sync
2026-08-29 18:00
UTC
All sources
NVD CVE · 1809CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2024-12-03
CISA KEV
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
2024-11-26
NVD CVE
CVE-2024-11680: ProjectSend versions prior to r1720 are affected by an improper authentication v
CRITICAL
◈ 2 sources · orig. NVD CVE
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling...
2024-11-25
CISA KEV
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
2024-11-22
NVD CVE
CVE-2024-52723: In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str f
CRITICAL
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
2024-11-19
NVD CVE
CVE-2024-52714: Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the f
CRITICAL
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
2024-11-18
CISA KEV
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
2024-11-18
NVD CVE
CVE-2024-0012: An authentication bypass in Palo Alto Networks PAN-OS software enables an unauth
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative...
2024-11-18
CISA KEV
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
2024-11-12
CISA KEV
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.
2024-11-07
CISA KEV
CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.
2024-10-29
NVD CVE
CVE-2024-51378: getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel)
CRITICAL
◈ 2 sources · orig. NVD CVE
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or...
2024-10-29
NVD CVE
CVE-2024-51567: upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before
CRITICAL
◈ 2 sources · orig. NVD CVE
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing...
2024-10-28
NVD CVE
CVE-2024-50623: In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.
CRITICAL
◈ 2 sources · orig. NVD CVE
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
2024-10-22
CISA KEV
Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
2024-10-21
NVD CVE
CVE-2024-41713: A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiColl
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input...
2024-10-20
NVD CVE
CVE-2024-49604: Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Medi
CRITICAL
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.
2024-10-17
CISA KEV
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
2024-10-15
CISA KEV
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
2024-10-15
CISA KEV
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
2024-10-09
NVD CVE
CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit
CRITICAL
◈ 2 sources · orig. NVD CVE
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability...
2024-10-07
NVD CVE
CVE-2024-46446: Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct
CRITICAL
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of...
2024-09-25
NVD CVE
CVE-2024-6592: An incorrect authorization vulnerability in the protocol communication between t
CRITICAL
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS...
2024-09-25
NVD CVE
CVE-2024-6593: Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka
CRITICAL
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands.
An attacker that has...
2024-09-19
NVD CVE
CVE-2024-33109: Directory Traversal in the web interface of the Tiptel IP 286 with firmware vers
CRITICAL
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
2024-09-17
NVD CVE
CVE-2024-44004: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection.
This issue affects WPCargo Track & Trace: before 8.0.4.
2024-09-16
CISA KEV
Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.
2024-09-09
CISA KEV
Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
2024-09-09
NVD CVE
CVE-2024-44902: A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to
CRITICAL
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
2024-09-09
CISA KEV
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
2024-08-29
NVD CVE
CVE-2024-44777: A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
2024-08-29
NVD CVE
CVE-2024-44778: A reflected cross-site scripting (XSS) vulnerability in the parent parameter in
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
2024-08-29
NVD CVE
CVE-2024-44779: A reflected cross-site scripting (XSS) vulnerability in the viewname parameter i
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a...
2024-08-19
CISA KEV
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
2024-08-13
NVD CVE
CVE-2024-41623: An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a l
CRITICAL
An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload
2024-08-12
NVD CVE
CVE-2024-42467: openHAB, a provider of open-source home automation software, has add-ons includi
CRITICAL
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be...
2024-08-02
NVD CVE
CVE-2024-38889: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements...
2024-08-02
NVD CVE
CVE-2024-38886: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the...
2024-08-02
NVD CVE
CVE-2024-38887: An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.
CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the...
2024-07-30
CISA KEV
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user...
2024-07-09
NVD CVE
CVE-2024-39171: Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and d
CRITICAL
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.