LIVE FEED
1860 events · 13 sources · newest first
Events in view
1860
all sources
Critical
1860
severity
Active sources
13
collectors
Last sync
2026-08-30 00:00
UTC
All sources
NVD CVE · 1810CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2023-01-26
CISA KEV
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
2023-01-23
CISA KEV
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
2023-01-18
NVD CVE
CVE-2022-47966: Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through
CRITICAL
◈ 2 sources · orig. NVD CVE
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT...
2023-01-10
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
2022-12-22
NVD CVE
CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free
CRITICAL
◈ 2 sources · orig. NVD CVE
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox <...
2022-12-19
NVD CVE
CVE-2022-40434: Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field
CRITICAL
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
2022-12-14
NVD CVE
CVE-2022-31358: A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environm
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.
2022-12-13
CISA KEV
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading...
2022-12-13
CISA KEV
Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.
2022-12-13
CISA KEV
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
2022-12-13
CISA KEV
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading...
2022-12-02
NVD CVE
CVE-2022-44945: Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via t
CRITICAL
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
2022-12-02
NVD CVE
CVE-2022-44291: webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the
CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
2022-12-02
NVD CVE
CVE-2022-44290: webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the
CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
2022-11-25
NVD CVE
CVE-2022-45207: Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via th
CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
2022-11-25
NVD CVE
CVE-2022-37720: Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). W
CRITICAL
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full...
2022-11-25
NVD CVE
CVE-2022-37721: PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low priv
CRITICAL
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or...
2022-11-25
NVD CVE
CVE-2022-45206: Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via th
CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
2022-11-22
NVD CVE
CVE-2022-36180: Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirec
CRITICAL
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection],...
2022-11-22
NVD CVE
Fusiondirectory 1.3 suffers from Improper Session Handling.
2022-11-22
NVD CVE
CVE-2022-40842: ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side req
CRITICAL
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
2022-11-22
NVD CVE
CVE-2022-42989: ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XS
CRITICAL
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
2022-11-22
NVD CVE
CVE-2022-44194: Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_d
CRITICAL
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.
2022-11-15
NVD CVE
CVE-2022-42120: A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 thr
CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a...
2022-11-15
NVD CVE
CVE-2022-42122: A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7
CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into...
2022-11-10
NVD CVE
CVE-2022-44089: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
2022-11-10
NVD CVE
CVE-2022-44088: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
2022-11-10
NVD CVE
CVE-2022-44087: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
2022-11-08
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2022-11-08
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
2022-10-25
NVD CVE
CVE-2022-38580: Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
CRITICAL
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
2022-10-24
CISA KEV
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by...
2022-10-24
CISA KEV
The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the...
2022-10-24
CISA KEV
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid...
2022-10-24
CISA KEV
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with...
2022-10-24
CISA KEV
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number...
2022-10-24
CISA KEV
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a...
2022-10-19
NVD CVE
CVE-2022-41415: Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflo
CRITICAL
Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode...
2022-10-18
NVD CVE
CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortine
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and...
2022-10-17
NVD CVE
CVE-2022-40055: An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to
CRITICAL
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.