LIVE FEED
329 events · 13 sources · newest first
Events in view
329
all sources
Critical
329
severity
Active sources
13
collectors
Last sync
2026-08-28 18:00
UTC
All sources
NVD CVE · 1796CISA KEV · 1686News · 435CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2022-03-25
CISA KEV
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
2022-03-25
CISA KEV
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
2022-03-25
CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
2022-03-25
CISA KEV
Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
2022-03-25
CISA KEV
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
2022-03-25
CISA KEV
Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
2022-03-25
CISA KEV
An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
2022-03-25
CISA KEV
Quest KACE System Management Appliance Remote Command Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
2022-03-25
CISA KEV
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
2022-03-25
CISA KEV
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be...
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
2022-03-15
CISA KEV
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
CRITICAL
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
2022-03-15
CISA KEV
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an...
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-07
CISA KEV
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
2022-03-03
CISA KEV
Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
2022-03-03
CISA KEV
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
2022-03-03
CISA KEV
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
2022-03-03
CISA KEV
Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
2022-03-03
CISA KEV
An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
2022-03-03
CISA KEV
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.
2022-03-03
CISA KEV
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.
2022-03-03
CISA KEV
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
2022-03-03
CISA KEV
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
2022-03-03
CISA KEV
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
2022-03-03
CISA KEV
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability...
2022-02-25
CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.
2022-02-15
CISA KEV
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
2022-02-15
CISA KEV
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
2022-02-15
CISA KEV
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
2022-02-15
CISA KEV
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution