LIVE FEED
1860 events · 13 sources · newest first
Events in view
1860
all sources
Critical
1860
severity
Active sources
13
collectors
Last sync
2026-08-30 00:00
UTC
All sources
NVD CVE · 1810CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2022-06-16
NVD CVE
CVE-2022-24562: In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POS
CRITICAL
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint,...
2022-06-14
NVD CVE
CVE-2021-42675: Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media dire
CRITICAL
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
2022-06-14
CISA KEV
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the...
2022-06-08
CISA KEV
QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.
2022-06-08
CISA KEV
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
2022-06-08
CISA KEV
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.
2022-06-08
CISA KEV
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
2022-06-02
NVD CVE
CVE-2022-24240: ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerabi
CRITICAL
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
2022-06-02
NVD CVE
CVE-2022-28945: An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traver
CRITICAL
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
2022-06-02
NVD CVE
CVE-2022-30490: Badminton Center Management System V1.0 is vulnerable to SQL Injection via param
CRITICAL
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
2022-06-02
NVD CVE
BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
2022-06-02
NVD CVE
CVE-2021-42875: TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability
CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
2022-06-02
NVD CVE
CVE-2022-31340: Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table
CRITICAL
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
2022-06-02
CISA KEV
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
2022-06-02
NVD CVE
CVE-2021-42872: TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability
CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
2022-06-02
NVD CVE
CVE-2022-24239: ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file uplo
CRITICAL
ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.
2022-05-25
CISA KEV
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
2022-05-25
CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
2022-05-25
CISA KEV
A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
2022-05-25
CISA KEV
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.
2022-05-25
CISA KEV
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote...
2022-05-25
CISA KEV
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this...
2022-05-25
CISA KEV
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
2022-05-25
CISA KEV
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
2022-05-24
CISA KEV
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
2022-05-24
CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
2022-05-24
CISA KEV
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the...
2022-05-24
CISA KEV
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
2022-05-24
CISA KEV
A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
2022-05-24
CISA KEV
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
2022-05-23
CISA KEV
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
2022-05-23
NVD CVE
CVE-2022-28932: D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permiss
CRITICAL
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
2022-05-16
NVD CVE
CVE-2022-29351: An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue...
2022-05-10
CISA KEV
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
2022-05-04
NVD CVE
CVE-2021-43163: A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-
CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
2022-05-04
NVD CVE
CVE-2022-29347: An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to exec
CRITICAL
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
2022-05-04
NVD CVE
CVE-2022-28568: Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to R
CRITICAL
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the...
2022-05-03
NVD CVE
CVE-2022-28118: SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plu
CRITICAL
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.