LIVE FEED
1859 events · 13 sources · newest first
Events in view
1859
all sources
Critical
1859
severity
Active sources
13
collectors
Last sync
2026-08-29 18:00
UTC
All sources
NVD CVE · 1809CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2024-01-20
NVD CVE
CVE-2023-51927: YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the
CRITICAL
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.
2024-01-19
NVD CVE
CVE-2024-23687: Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and
CRITICAL
Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including...
2024-01-19
NVD CVE
CVE-2024-23679: Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. A
CRITICAL
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
2024-01-19
NVD CVE
CVE-2023-51947: Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1
CRITICAL
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.
2024-01-18
CISA KEV
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
CRITICAL
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
2024-01-12
NVD CVE
CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9.
CRITICAL
◈ 2 sources · orig. NVD CVE
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute...
2024-01-10
CISA KEV
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This...
2024-01-10
CISA KEV
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated...
2024-01-10
CISA KEV
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted...
2024-01-09
NVD CVE
CVE-2023-26999: An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execut
CRITICAL
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.
2024-01-09
NVD CVE
CVE-2023-50643: An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to ex
CRITICAL
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
2024-01-08
CISA KEV
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
2024-01-08
CISA KEV
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
2024-01-04
NVD CVE
CVE-2024-22051: CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnera
CRITICAL
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading...
2024-01-02
NVD CVE
CVE-2023-47458: An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate
CRITICAL
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
2023-12-30
NVD CVE
CVE-2023-50651: TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote comman
CRITICAL
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
2023-12-20
NVD CVE
CVE-2023-50989: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerabil
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
2023-12-20
NVD CVE
CVE-2023-50990: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebo
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.
2023-12-20
NVD CVE
CVE-2023-50992: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip pa
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.
2023-12-20
NVD CVE
CVE-2023-50983: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerabil
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
2023-12-20
NVD CVE
CVE-2023-50984: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip p
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.
2023-12-20
NVD CVE
CVE-2023-50986: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
2023-12-20
NVD CVE
CVE-2023-50985: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanG
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.
2023-12-20
NVD CVE
CVE-2023-50987: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.
2023-12-20
NVD CVE
CVE-2023-50988: Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the band
CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.
2023-12-07
CISA KEV
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
2023-12-07
CISA KEV
Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the...
2023-11-29
NVD CVE
CVE-2023-23325: Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a co
CRITICAL
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter.
2023-11-29
NVD CVE
CVE-2023-23324: Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hard
CRITICAL
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.
2023-11-28
NVD CVE
CVE-2023-48193: Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote a
CRITICAL
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not...
2023-11-21
NVD CVE
CVE-2023-49105: An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker ca
CRITICAL
◈ 2 sources · orig. NVD CVE
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key...
attacker-accessesauthentication-bypasscisa-kevcve-2023-49105data-integrityfile-deletionfile-modificationfiles-access
2023-11-21
NVD CVE
CVE-2023-49060: An attacker could have accessed internal pages or data by ex-filtrating a securi
CRITICAL
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
2023-11-14
NVD CVE
CVE-2023-43902: Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7
CRITICAL
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a...
2023-11-13
CISA KEV
SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.
2023-11-10
NVD CVE
CVE-2023-47246: In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to cod
CRITICAL
◈ 2 sources · orig. NVD CVE
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
2023-11-07
CISA KEV
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on...
2023-11-02
CISA KEV
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire...
2023-11-02
NVD CVE
CVE-2023-46958: An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via
CRITICAL
An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.
2023-10-31
NVD CVE
CVE-2023-42425: An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to
CRITICAL
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.
2023-10-31
CISA KEV
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the...