LIVE FEED
1861 events · 13 sources · newest first
Events in view
1861
all sources
Critical
1861
severity
Active sources
13
collectors
Last sync
2026-08-30 06:00
UTC
All sources
NVD CVE · 1811CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2021-11-19
NVD CVE
CVE-2021-41435: A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX1
CRITICAL
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S),...
2021-11-17
CISA KEV
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
2021-11-17
CISA KEV
Unspecified vulnerability allows for an authenticated user to escalate privileges.
2021-11-13
NVD CVE
CVE-2021-41653: The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL
CRITICAL
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
2021-11-05
NVD CVE
CVE-2021-42237: Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an
CRITICAL
◈ 2 sources · orig. NVD CVE
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special...
2021-11-04
NVD CVE
CVE-2020-25367: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link
CRITICAL
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha...
2021-11-04
NVD CVE
CVE-2020-25366: An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1
CRITICAL
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
2021-11-04
NVD CVE
CVE-2020-25368: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link
CRITICAL
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the...
2021-11-03
CISA KEV
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute...
2021-11-03
CISA KEV
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
CRITICAL
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or...
2021-11-03
CISA KEV
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
2021-11-03
CISA KEV
Exim Buffer Overflow Vulnerability
CRITICAL
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
2021-11-03
CISA KEV
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
2021-11-03
CISA KEV
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
2021-11-03
CISA KEV
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
2021-11-03
CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could...
2021-11-03
CISA KEV
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
2021-11-03
CISA KEV
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
2021-11-03
CISA KEV
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
2021-11-03
CISA KEV
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
2021-11-03
CISA KEV
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
2021-11-03
CISA KEV
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all...
2021-11-03
CISA KEV
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
2021-11-03
CISA KEV
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all...
2021-11-03
CISA KEV
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
2021-11-03
CISA KEV
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
2021-11-03
CISA KEV
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
2021-11-03
CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
2021-11-03
CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
2021-11-03
CISA KEV
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in...
2021-11-03
CISA KEV
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
2021-11-03
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03
CISA KEV
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the...
2021-11-03
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03
CISA KEV
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who...