LIVE FEED
329 events · 13 sources · newest first
Events in view
329
all sources
Critical
329
severity
Active sources
13
collectors
Last sync
2026-08-28 18:00
UTC
All sources
NVD CVE · 1796CISA KEV · 1686News · 435CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2021-11-03
CISA KEV
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially...
2021-11-03
CISA KEV
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
2021-11-03
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
2021-11-03
CISA KEV
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
2021-11-03
CISA KEV
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in...
2021-11-03
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03
CISA KEV
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit...
2021-11-03
CISA KEV
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
2021-11-03
CISA KEV
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
2021-11-03
CISA KEV
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
2021-11-03
CISA KEV
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
2021-11-03
CISA KEV
Exim Buffer Overflow Vulnerability
CRITICAL
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
2021-11-03
CISA KEV
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
2021-11-03
CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
2021-11-03
CISA KEV
SonicWall Email Security Improper Privilege Management Vulnerability
CRITICAL
◈ 2 sources · orig. NVD CVE
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability...
2021-11-03
CISA KEV
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
2021-11-03
CISA KEV
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges...
2021-11-03
CISA KEV
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
2021-11-03
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform...
2021-11-03
CISA KEV
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code...
2021-11-03
CISA KEV
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
2021-11-03
CISA KEV
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute...
2021-11-03
CISA KEV
Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.
2021-11-03
CISA KEV
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03
CISA KEV
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03
CISA KEV
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate...
2021-11-03
CISA KEV
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
2021-11-03
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2021-11-03
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
2021-11-03
CISA KEV
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
2021-11-03
CISA KEV
SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
2021-11-03
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
2021-11-03
CISA KEV
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
2021-11-03
CISA KEV
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.