Skip to content
COOEY
LIVE FEED
1686 events · 13 sources · newest first
2021-11-03 CISA KEV
Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.
2021-11-03 CISA KEV
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit,...
2021-11-03 CISA KEV
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying...
2021-11-03 CISA KEV
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
2021-11-03 CISA KEV
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
2021-11-03 CISA KEV
The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
2021-11-03 CISA KEV
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the...
2021-11-03 CISA KEV
Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the...
2021-11-03 CISA KEV
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all...
2021-11-03 CISA KEV
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all...
2021-11-03 CISA KEV
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
2021-11-03 CISA KEV
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to...
2021-11-03 CISA KEV
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained...
2021-11-03 CISA KEV
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and...
2021-11-03 CISA KEV
Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.
2021-11-03 CISA KEV
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
2021-11-03 CISA KEV
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
2021-11-03 CISA KEV
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
2021-11-03 CISA KEV
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
2021-11-03 CISA KEV
Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
2021-11-03 CISA KEV
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
2021-11-03 CISA KEV
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
2021-11-03 CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
2021-11-03 CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
2021-11-03 CISA KEV
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
2021-11-03 CISA KEV
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
2021-11-03 CISA KEV
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
2021-11-03 CISA KEV
VMware ESXi OpenSLP Use-After-Free Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
2021-11-03 CISA KEV
SonicWall SSLVPN SMA100 SQL Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
2021-11-03 CISA KEV
VMware vCenter Server Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges...
2021-11-03 CISA KEV
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability...
2021-11-03 CISA KEV
Ivanti Pulse Connect Secure Use-After-Free Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
2021-11-03 CISA KEV
VMware vCenter Server Improper Input Validation Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
2021-11-03 CISA KEV
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
2021-11-03 CISA KEV
Fortinet FortiOS SSL VPN Improper Authentication Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the...
2021-11-03 CISA KEV
Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges...
2021-11-03 CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending...
2021-11-03 CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could...
2021-11-03 CISA KEV
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
2021-11-03 CISA KEV
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
◀ PREV PAGE 41 / 43 NEXT ▶