LIVE FEED
1861 events · 13 sources · newest first
Events in view
1861
all sources
Critical
1861
severity
Active sources
13
collectors
Last sync
2026-08-30 06:00
UTC
All sources
NVD CVE · 1811CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2021-11-03
CISA KEV
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
2021-11-03
CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
2021-11-03
CISA KEV
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
2021-11-03
CISA KEV
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code...
2021-11-03
CISA KEV
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate...
2021-11-03
CISA KEV
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
2021-11-03
CISA KEV
Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
2021-11-03
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform...
2021-11-03
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
2021-11-03
CISA KEV
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially...
2021-11-03
CISA KEV
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03
CISA KEV
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
2021-11-03
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
2021-11-03
CISA KEV
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
2021-11-03
CISA KEV
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully...
2021-11-03
CISA KEV
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
2021-11-03
CISA KEV
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.
2021-11-03
CISA KEV
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
2021-11-03
CISA KEV
SonicWall Email Security Improper Privilege Management Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability...
2021-11-03
CISA KEV
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges...
2021-11-03
CISA KEV
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
2021-11-03
CISA KEV
Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
2021-11-03
CISA KEV
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
2021-11-03
CISA KEV
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the...
2021-11-03
CISA KEV
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
2021-11-03
CISA KEV
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
2021-11-03
CISA KEV
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
2021-11-03
CISA KEV
SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
2021-11-03
CISA KEV
GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which...
2021-11-03
CISA KEV
SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.
2021-11-03
CISA KEV
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit...
2021-11-03
CISA KEV
Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful...
2021-11-03
CISA KEV
VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to...
2021-11-03
CISA KEV
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
2021-11-03
CISA KEV
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
2021-10-31
NVD CVE
CVE-2020-25912: A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit
CRITICAL
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).