Skip to content
COOEY
LIVE FEED
1860 events · 13 sources · newest first
2022-06-16 NVD CVE
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint,...
2022-06-14 NVD CVE
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
2022-06-14 CISA KEV
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the...
2022-06-08 CISA KEV
QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.
2022-06-08 CISA KEV
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
2022-06-08 CISA KEV
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.
2022-06-08 CISA KEV
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
2022-06-02 NVD CVE
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
2022-06-02 NVD CVE
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
2022-06-02 NVD CVE
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
2022-06-02 NVD CVE
BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
2022-06-02 NVD CVE
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
2022-06-02 NVD CVE
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
2022-06-02 CISA KEV
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
2022-06-02 NVD CVE
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
2022-06-02 NVD CVE
ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.
2022-05-25 CISA KEV
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
2022-05-25 CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
2022-05-25 CISA KEV
A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
2022-05-25 CISA KEV
Oracle Fusion Middleware Unspecified Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.
2022-05-25 CISA KEV
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote...
2022-05-25 CISA KEV
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this...
2022-05-25 CISA KEV
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
2022-05-25 CISA KEV
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
2022-05-24 CISA KEV
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
2022-05-24 CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
2022-05-24 CISA KEV
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the...
2022-05-24 CISA KEV
Kaseya VSA SQL Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
2022-05-24 CISA KEV
QNAP NAS File Station Command Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
2022-05-24 CISA KEV
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
2022-05-23 CISA KEV
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
2022-05-23 CISA KEV
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
2022-05-23 CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
2022-05-23 NVD CVE
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
2022-05-16 NVD CVE
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue...
2022-05-10 CISA KEV
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
2022-05-04 NVD CVE
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
2022-05-04 NVD CVE
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
2022-05-04 NVD CVE
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the...
2022-05-03 NVD CVE
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
◀ PREV PAGE 40 / 47 NEXT ▶