LIVE FEED
1860 events · 13 sources · newest first
Events in view
1860
all sources
Critical
1860
severity
Active sources
13
collectors
Last sync
2026-08-30 00:00
UTC
All sources
NVD CVE · 1810CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2022-04-29
NVD CVE
CVE-2021-44596: Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code exe
CRITICAL
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the...
2022-04-28
NVD CVE
CVE-2021-41945: Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL
CRITICAL
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
2022-04-26
NVD CVE
CVE-2022-29499: The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows
CRITICAL
◈ 2 sources · orig. NVD CVE
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
2022-04-26
NVD CVE
CVE-2022-27985: CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin
CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
2022-04-26
NVD CVE
CVE-2022-27984: CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the me
CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
2022-04-25
CISA KEV
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
2022-04-25
NVD CVE
CVE-2022-28093: SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a loc
CRITICAL
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
2022-04-19
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
2022-04-15
CISA KEV
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
2022-04-14
CISA KEV
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
CRITICAL
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
2022-04-13
CISA KEV
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
2022-04-13
CISA KEV
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
2022-04-13
CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
2022-04-12
NVD CVE
CVE-2022-28397: An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation,...
2022-04-12
NVD CVE
CVE-2022-27260: An arbitrary file upload vulnerability in the file upload component of ButterCMS
CRITICAL
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
2022-04-12
NVD CVE
CVE-2022-27262: An arbitrary file upload vulnerability in the file upload module of Skipper v0.9
CRITICAL
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
2022-04-11
CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11
NVD CVE
CVE-2021-37291: An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management
CRITICAL
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
2022-04-11
CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-06
CISA KEV
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
2022-03-31
CISA KEV
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
2022-03-31
CISA KEV
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
2022-03-30
NVD CVE
CVE-2022-26645: A remote code execution (RCE) vulnerability in Online Banking System Protect v1.
CRITICAL
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
2022-03-30
NVD CVE
CVE-2021-46007: totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of
CRITICAL
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command...
2022-03-30
NVD CVE
CVE-2021-46009: In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite
CRITICAL
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
2022-03-30
NVD CVE
CVE-2022-26646: Online Banking System Protect v1.0 was discovered to contain a local file inclus
CRITICAL
Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.
2022-03-29
NVD CVE
NUUO v03.11.00 was discovered to contain access control issue.
2022-03-28
CISA KEV
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
2022-03-28
CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D
2022-03-28
CISA KEV
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
2022-03-28
CISA KEV
The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
2022-03-28
CISA KEV
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
2022-03-28
CISA KEV
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
2022-03-28
CISA KEV
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
2022-03-28
CISA KEV
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
2022-03-28
CISA KEV
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
2022-03-28
CISA KEV
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
2022-03-28
NVD CVE
CVE-2022-26258: D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE)
CRITICAL
◈ 2 sources · orig. NVD CVE
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
2022-03-25
CISA KEV
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
2022-03-25
CISA KEV
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.