Threat Alerts
Real-time critical CVE alerts, security advisories, and vulnerability intelligence — curated by the Vulnios Threat Intelligence team.
Critical Vulnerability: CVE-2021-3193 — nagios — nagios_xi
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
Critical Vulnerability: CVE-2021-3190 — async-git_project — async-git
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
Critical Vulnerability: CVE-2020-35270 — student_result_management_system_project — student_result_management_system
Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.
Critical Vulnerability: CVE-2020-27583 — ibm — infosphere_information_server
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only a
Critical Vulnerability: CVE-2020-20269 — caret — caret
A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22.
Critical Vulnerability: CVE-2021-3325 — fibranet, fedoraproject — monitorix, fedora
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control
Critical Vulnerability: CVE-2020-28221 — schneider-electric — ecostruxure_operator_terminal_expert, hmi_sto_501
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when
Critical Vulnerability: CVE-2020-23448 — newbee-mall_project — newbee-mall
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code
Critical Vulnerability: CVE-2020-27539 — company — cs-c2shw_firmware, cs-c2shw
Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). I
Critical Vulnerability: CVE-2020-6779 — bosch — fsm-2500_firmware, fsm-2500
Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with
Critical Vulnerability: CVE-2021-25905 — bra_project — bra
An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.
Critical Vulnerability: CVE-2021-3278 — local_services_search_engine_management_system_project — local_services_search_engine_management_system
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.
Protect Your Organization
Monitor CVEs, scan for vulnerabilities, and get real-time threat alerts — all in one platform.
Weekly threat digest
KEV-listed exploits and vendor advisories, every Monday.
One email a week. Unsubscribe any time.