Threat Alerts

Real-time critical CVE alerts, security advisories, and vulnerability intelligence — curated by the Vulnios Threat Intelligence team.

Filter:
500 alerts
criticalCVE Alert
CVE-2021-3193

Critical Vulnerability: CVE-2021-3193 — nagios — nagios_xi

Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.

nagios· nagios_xi
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2021-3190

Critical Vulnerability: CVE-2021-3190 — async-git_project — async-git

The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.

async-git_project· async-git
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2020-35270

Critical Vulnerability: CVE-2020-35270 — student_result_management_system_project — student_result_management_system

Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.

student_result_management_system_project· student_result_management_system
criticalsqli
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2020-27583

Critical Vulnerability: CVE-2020-27583 — ibm — infosphere_information_server

IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only a

ibm· infosphere_information_server
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2020-20269

Critical Vulnerability: CVE-2020-20269 — caret — caret

A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22.

caret· caret
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2021-3325

Critical Vulnerability: CVE-2021-3325 — fibranet, fedoraproject — monitorix, fedora

Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control

fibranet· monitorix, fedora
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2020-28221

Critical Vulnerability: CVE-2020-28221 — schneider-electric — ecostruxure_operator_terminal_expert, hmi_sto_501

A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when

schneider-electric· ecostruxure_operator_terminal_expert, hmi_sto_501
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2020-23448

Critical Vulnerability: CVE-2020-23448 — newbee-mall_project — newbee-mall

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code

newbee-mall_project· newbee-mall
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2020-27539

Critical Vulnerability: CVE-2020-27539 — company — cs-c2shw_firmware, cs-c2shw

Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). I

company· cs-c2shw_firmware, cs-c2shw
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2020-6779

Critical Vulnerability: CVE-2020-6779 — bosch — fsm-2500_firmware, fsm-2500

Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with

bosch· fsm-2500_firmware, fsm-2500
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2021-25905

Critical Vulnerability: CVE-2021-25905 — bra_project — bra

An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.

bra_project· bra
critical
Sep 6 · 10:49 AM
Read analysis
criticalCVE Alert
CVE-2021-3278

Critical Vulnerability: CVE-2021-3278 — local_services_search_engine_management_system_project — local_services_search_engine_management_system

Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.

local_services_search_engine_management_system_project· local_services_search_engine_management_system
criticalsqliauth-bypass
Sep 6 · 10:49 AM
Read analysis

Protect Your Organization

Monitor CVEs, scan for vulnerabilities, and get real-time threat alerts — all in one platform.

Weekly threat digest

KEV-listed exploits and vendor advisories, every Monday.

One email a week. Unsubscribe any time.