LIVE FEED
1860 events · 13 sources · newest first
Events in view
1860
all sources
Critical
1860
severity
Active sources
13
collectors
Last sync
2026-08-30 00:00
UTC
All sources
NVD CVE · 1810CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2023-04-13
NVD CVE
CVE-2023-27779: AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via
CRITICAL
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
2023-04-11
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2023-04-07
CISA KEV
Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.
2023-04-07
CISA KEV
Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.
2023-04-07
CISA KEV
Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
2023-04-07
CISA KEV
Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.
2023-04-04
NVD CVE
CVE-2021-28235: Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers t
CRITICAL
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
2023-04-04
NVD CVE
CVE-2020-29312: An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to e
CRITICAL
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The...
2023-03-31
NVD CVE
CVE-2023-27162: openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request F
CRITICAL
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and...
2023-03-30
CISA KEV
Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.
2023-03-27
NVD CVE
CVE-2023-25261: Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This af
CRITICAL
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the...
2023-03-24
NVD CVE
CVE-2022-45597: ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor
CRITICAL
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport...
2023-03-17
NVD CVE
CVE-2023-28531: ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the inten
CRITICAL
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
2023-03-15
NVD CVE
CVE-2023-28461: Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote cod
CRITICAL
◈ 2 sources · orig. NVD CVE
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without...
2023-03-14
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
2023-03-09
NVD CVE
CVE-2023-27205: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
2023-03-09
NVD CVE
CVE-2023-27204: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
2023-03-09
NVD CVE
CVE-2023-27203: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
2023-03-09
NVD CVE
CVE-2023-27202: Best POS Management System 1.0 was discovered to contain a SQL injection vulnera
CRITICAL
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
2023-03-03
NVD CVE
CVE-2022-45551: An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.1
CRITICAL
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.
2023-03-03
NVD CVE
CVE-2022-45553: An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.
CRITICAL
An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.
2023-03-02
NVD CVE
CVE-2022-46501: Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contai
CRITICAL
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.
2023-02-27
CISA KEV
ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This...
2023-02-24
NVD CVE
CVE-2021-33224: File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attack
CRITICAL
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
2023-02-21
CISA KEV
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
2023-02-21
NVD CVE
CVE-2023-24080: A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222
CRITICAL
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.
2023-02-21
CISA KEV
The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.
2023-02-21
CISA KEV
The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.
2023-02-14
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2023-02-14
NVD CVE
Microsoft Word Remote Code Execution Vulnerability
2023-02-13
NVD CVE
CVE-2023-24188: ureport v2.2.9 was discovered to contain a directory traversal vulnerability via
CRITICAL
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
2023-02-10
CISA KEV
TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.
2023-02-10
CISA KEV
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
2023-02-10
CISA KEV
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
2023-02-02
CISA KEV
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
2023-02-01
NVD CVE
CVE-2022-47770: Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticat
CRITICAL
Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.
2023-02-01
NVD CVE
CVE-2022-47769: An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1
CRITICAL
An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.
2023-02-01
NVD CVE
CVE-2022-47003: A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows
CRITICAL
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
2023-01-30
NVD CVE
CVE-2022-23334: The Robot application in Ip-label Newtest before v8.5R0 was discovered to use we
CRITICAL
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
2023-01-26
NVD CVE
CVE-2020-22452: SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.
CRITICAL
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.