LIVE FEED
1860 events · 13 sources · newest first
Events in view
1860
all sources
Critical
1860
severity
Active sources
13
collectors
Last sync
2026-08-30 00:00
UTC
All sources
NVD CVE · 1810CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2022-10-12
NVD CVE
CVE-2022-33106: WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit atta
CRITICAL
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
2022-10-11
CISA KEV
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially...
2022-09-30
NVD CVE
CVE-2022-35156: Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnera
CRITICAL
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
2022-09-30
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the...
2022-09-30
CISA KEV
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
2022-09-21
NVD CVE
CVE-2022-38619: SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability
CRITICAL
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
2022-09-21
NVD CVE
CVE-2022-40030: SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL
CRITICAL
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
2022-09-16
NVD CVE
CVE-2022-36536: An issue in the component post_applogin.php of Super Flexible Software GmbH & Co
CRITICAL
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
2022-09-15
NVD CVE
CVE-2022-37257: Prototype pollution vulnerability in function convertLater in npm-convert.js in
CRITICAL
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
2022-09-08
CISA KEV
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed...
2022-09-08
CISA KEV
Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
2022-09-08
CISA KEV
Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test...
2022-09-02
NVD CVE
CVE-2022-36640: influxData influxDB before v1.8.10 contains no authentication mechanism or contr
CRITICAL
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's...
2022-08-31
NVD CVE
CVE-2022-36202: Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edo
CRITICAL
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
2022-08-30
NVD CVE
CVE-2022-37176: Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability
CRITICAL
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.
2022-08-29
NVD CVE
CVE-2022-32993: TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue vi
CRITICAL
TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
2022-08-28
NVD CVE
CVE-2022-37053: TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpin
CRITICAL
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
2022-08-28
NVD CVE
CVE-2022-38555: Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
CRITICAL
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
2022-08-25
CISA KEV
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web...
2022-08-25
CISA KEV
dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location....
2022-08-23
NVD CVE
CVE-2021-42232: TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vul
CRITICAL
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command....
2022-08-23
NVD CVE
CVE-2021-42627: The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.
CRITICAL
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage...
2022-08-19
NVD CVE
CVE-2022-35201: Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RC
CRITICAL
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
2022-08-15
NVD CVE
CVE-2022-36262: An issue was discovered in taocms 3.0.2. in the website settings that allows arb
CRITICAL
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
2022-08-12
NVD CVE
CVE-2022-37042: Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality tha
CRITICAL
◈ 2 sources · orig. NVD CVE
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload...
2022-08-11
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained...
2022-08-11
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.
2022-08-09
CISA KEV
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
2022-08-05
NVD CVE
CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in infl
CRITICAL
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common...
2022-08-04
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.
2022-08-01
NVD CVE
CVE-2022-31321: The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input va
CRITICAL
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.
2022-07-25
NVD CVE
CVE-2022-35131: Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted paylo
CRITICAL
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
2022-07-06
NVD CVE
CVE-2022-32385: Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the
CRITICAL
Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
2022-07-06
NVD CVE
CVE-2022-33047: OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via ot
CRITICAL
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
2022-07-06
NVD CVE
CVE-2022-32386: Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvS
CRITICAL
Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
2022-06-27
CISA KEV
The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
2022-06-17
NVD CVE
CVE-2021-45024: ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Ent
CRITICAL
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
2022-06-16
NVD CVE
CVE-2022-31382: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
2022-06-16
NVD CVE
CVE-2022-31383: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
2022-06-16
NVD CVE
CVE-2022-31384: Directory Management System v1.0 was discovered to contain a SQL injection vulne
CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.