LIVE FEED
1531 events · 13 sources · newest first
Events in view
1531
all sources
Critical
1531
severity
Active sources
13
collectors
Last sync
2026-08-30 00:00
UTC
All sources
NVD CVE · 1810CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2022-03-18
NVD CVE
CVE-2021-45834: An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.
CRITICAL
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary...
2022-03-18
NVD CVE
CVE-2022-25578: taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing
CRITICAL
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
2022-03-17
NVD CVE
CVE-2021-44087: A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance
CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
2022-03-17
NVD CVE
CVE-2021-44088: An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll S
CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
2022-03-11
NVD CVE
CVE-2021-44620: A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B2020
CRITICAL
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
2022-03-10
NVD CVE
CVE-2022-23383: YzmCMS v6.3 is affected by broken access control. Without login, unauthorized ac
CRITICAL
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal...
2022-03-03
NVD CVE
CVE-2022-25089: Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privil
CRITICAL
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
2022-02-25
NVD CVE
CVE-2022-25061: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
2022-02-25
NVD CVE
CVE-2022-25064: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execu
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
2022-02-25
NVD CVE
CVE-2022-25060: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
2022-02-25
NVD CVE
CVE-2021-42952: Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability.
CRITICAL
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and...
2022-02-17
NVD CVE
CVE-2022-22916: O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerabilit
CRITICAL
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
2022-02-14
NVD CVE
CVE-2021-45420: Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerabil
CRITICAL
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on...
2022-02-02
NVD CVE
CVE-2021-42640: PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Ins
CRITICAL
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
2022-02-02
NVD CVE
CVE-2021-42637: PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled inpu
CRITICAL
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
2022-01-28
NVD CVE
CVE-2021-44971: Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 F
CRITICAL
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine...
2022-01-17
NVD CVE
CVE-2022-23303: The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10
CRITICAL
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for...
2022-01-17
NVD CVE
CVE-2022-23304: The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before
CRITICAL
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix...
2022-01-13
NVD CVE
CVE-2021-45807: jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonC
CRITICAL
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
2021-12-15
NVD CVE
CVE-2021-42216: A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via Verificat
CRITICAL
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
2021-12-10
NVD CVE
CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
CRITICAL
◈ 2 sources · orig. NVD CVE
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and...
2021-12-08
NVD CVE
CVE-2021-44529: A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA)
CRITICAL
◈ 2 sources · orig. NVD CVE
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
2021-12-07
NVD CVE
CVE-2021-41716: Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prio
CRITICAL
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
2021-11-19
NVD CVE
CVE-2021-41435: A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX1
CRITICAL
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S),...
2021-11-13
NVD CVE
CVE-2021-41653: The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL
CRITICAL
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
2021-11-05
NVD CVE
CVE-2021-42237: Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an
CRITICAL
◈ 2 sources · orig. NVD CVE
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special...
2021-11-04
NVD CVE
CVE-2020-25367: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link
CRITICAL
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha...
2021-11-04
NVD CVE
CVE-2020-25366: An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1
CRITICAL
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
2021-11-04
NVD CVE
CVE-2020-25368: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link
CRITICAL
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the...
2021-10-31
NVD CVE
CVE-2020-25912: A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit
CRITICAL
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
2021-09-16
NVD CVE
CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
CRITICAL
◈ 2 sources · orig. NVD CVE
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
2021-09-14
NVD CVE
CVE-2021-36581: Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to uplo
CRITICAL
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to...
2021-09-14
NVD CVE
CVE-2021-36582: In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to t
CRITICAL
In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to...
2021-07-09
NVD CVE
CVE-2021-30116: Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild i
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The...
2021-05-26
NVD CVE
CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to
CRITICAL
◈ 2 sources · orig. NVD CVE
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with...
2021-05-19
NVD CVE
CVE-2017-17674: BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due t
CRITICAL
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port...
2021-05-03
NVD CVE
CVE-2021-28860: In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an
CRITICAL
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in...
2021-04-23
NVD CVE
CVE-2021-22893: Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication b
CRITICAL
◈ 2 sources · orig. NVD CVE
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can...
2021-04-23
NVD CVE
CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting fro
CRITICAL
◈ 2 sources · orig. NVD CVE
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
2021-04-09
NVD CVE
CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac
CRITICAL
◈ 2 sources · orig. NVD CVE
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.