LIVE FEED
1861 events · 13 sources · newest first
Events in view
1861
all sources
Critical
1861
severity
Active sources
13
collectors
Last sync
2026-08-30 06:00
UTC
All sources
NVD CVE · 1811CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2022-03-03
CISA KEV
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
2022-03-03
NVD CVE
CVE-2022-25089: Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privil
CRITICAL
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
2022-03-03
CISA KEV
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
2022-02-25
NVD CVE
CVE-2022-25061: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
2022-02-25
NVD CVE
CVE-2022-25060: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
2022-02-25
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.
2022-02-25
NVD CVE
CVE-2021-42952: Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability.
CRITICAL
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and...
2022-02-25
NVD CVE
CVE-2022-25064: TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execu
CRITICAL
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
2022-02-17
NVD CVE
CVE-2022-22916: O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerabilit
CRITICAL
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
2022-02-15
CISA KEV
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
2022-02-15
CISA KEV
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
2022-02-15
CISA KEV
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
2022-02-15
CISA KEV
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
2022-02-14
NVD CVE
CVE-2021-45420: Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerabil
CRITICAL
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on...
2022-02-10
CISA KEV
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
2022-02-10
CISA KEV
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the...
2022-02-10
CISA KEV
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
2022-02-10
CISA KEV
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
2022-02-02
NVD CVE
CVE-2021-42637: PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled inpu
CRITICAL
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
2022-02-02
NVD CVE
CVE-2021-42640: PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Ins
CRITICAL
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
2022-01-28
NVD CVE
CVE-2021-44971: Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 F
CRITICAL
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine...
2022-01-28
CISA KEV
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
2022-01-28
CISA KEV
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
2022-01-21
CISA KEV
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
2022-01-18
CISA KEV
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal...
2022-01-17
NVD CVE
CVE-2022-23304: The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before
CRITICAL
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix...
2022-01-17
NVD CVE
CVE-2022-23303: The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10
CRITICAL
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for...
2022-01-13
NVD CVE
CVE-2021-45807: jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonC
CRITICAL
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
2022-01-10
CISA KEV
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
2022-01-10
CISA KEV
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
2022-01-10
CISA KEV
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
2022-01-10
CISA KEV
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
2022-01-10
CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
2021-12-15
CISA KEV
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
2021-12-15
NVD CVE
CVE-2021-42216: A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via Verificat
CRITICAL
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
2021-12-10
CISA KEV
Red Hat JBoss Application Server Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
2021-12-10
CISA KEV
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
2021-12-10
NVD CVE
CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
CRITICAL
◈ 2 sources · orig. NVD CVE
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and...
2021-12-08
NVD CVE
CVE-2021-44529: A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA)
CRITICAL
◈ 2 sources · orig. NVD CVE
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
2021-12-07
NVD CVE
CVE-2021-41716: Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prio
CRITICAL
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function