Skip to content
COOEY
LIVE FEED
329 events · 13 sources · newest first
2022-05-25 CISA KEV
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote...
2022-05-25 CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
2022-05-25 CISA KEV
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
2022-05-25 CISA KEV
A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
2022-05-25 CISA KEV
Oracle Fusion Middleware Unspecified Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.
2022-05-25 CISA KEV
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this...
2022-05-25 CISA KEV
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
2022-05-24 CISA KEV
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the...
2022-05-24 CISA KEV
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
2022-05-24 CISA KEV
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
2022-05-24 CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
2022-05-24 CISA KEV
QNAP NAS File Station Command Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
2022-05-24 CISA KEV
Kaseya VSA SQL Injection Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
2022-05-23 CISA KEV
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
2022-05-23 CISA KEV
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
2022-05-23 CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
2022-05-10 CISA KEV
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
2022-04-25 CISA KEV
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
2022-04-19 CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
2022-04-15 CISA KEV
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
2022-04-14 CISA KEV
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
2022-04-13 CISA KEV
Drupal Core Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
2022-04-13 CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
2022-04-13 CISA KEV
Kaseya VSA Remote Code Execution Vulnerability CRITICAL ◈ 2 sources · orig. NVD CVE
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
2022-04-11 CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11 CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-06 CISA KEV
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
2022-03-31 CISA KEV
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
2022-03-31 CISA KEV
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
2022-03-28 CISA KEV
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
2022-03-28 CISA KEV
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
2022-03-28 CISA KEV
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
2022-03-28 CISA KEV
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
2022-03-28 CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D
2022-03-28 CISA KEV
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
2022-03-28 CISA KEV
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
2022-03-28 CISA KEV
The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
2022-03-28 CISA KEV
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
2022-03-25 CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
◀ PREV PAGE 05 / 09 NEXT ▶