CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 1 of 85
CVE-2026-87886
KEV HIGH

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Ba...

CVSS 7.8 Acronis acronis_backup 2026-09-17
CVE-2026-76460
KEV CRITICAL

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insuffic...

CVSS 10 Cisco identity_services_engine 2026-09-16
CVE-2026-58704
KEV HIGH

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional ...

CVSS 8.8 Google android 2026-09-15
CVE-2026-76461
KEV CRITICAL

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with roo...

CVSS 9.8 Cisco asyncos 2026-09-14
CVE-2026-85706
KEV CRITICAL

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthe...

CVSS 10 Gitlab gitlab 2026-09-12
CVE-2026-87491
KEV HIGH

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security...

CVSS 8.8 Google chrome 2026-09-09
CVE-2026-84869
KEV CRITICAL

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circum...

CVSS 9.9 Connectwise screenconnect 2026-09-08
CVE-2026-85880
KEV HIGH

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1607 2026-09-08
CVE-2026-81963
KEV HIGH

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_11_23h2 2026-09-08
CVE-2026-75650
KEV CRITICAL

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of...

CVSS 10 Adobe commerce 2026-09-07
CVE-2026-86218
KEV CRITICAL

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

CVSS 9.8 N-able n-central 2026-09-06
CVE-2026-86060
KEV CRITICAL

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be ch...

CVSS 9.8 Mikrotik routeros 2026-09-05
CVE-2026-67277
KEV HIGH

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 U...

CVSS 8.2 Mikrotik routeros 2026-09-05
CVE-2026-85046
KEV HIGH

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security seve...

CVSS 8.8 Google chrome 2026-09-03
CVE-2026-83548
KEV CRITICAL

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could pot...

CVSS 10 Sonicwall sma8200v 2026-09-01
CVE-2026-83549
KEV HIGH

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management...

CVSS 7.8 Sonicwall sma8200v 2026-09-01
CVE-2026-82329
KEV CRITICAL

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileg...

CVSS 9.8 Jfrog artifactory 2026-08-28
CVE-2026-82078
KEV CRITICAL

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based...

CVSS 9.1 Papercut papercut_mf 2026-08-28
CVE-2026-81578
KEV CRITICAL

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting...

CVSS 9.8 Papercut papercut_mf 2026-08-28
CVE-2026-60004
KEV CRITICAL

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVSS 9.8 Gitea gitea 2026-08-26
1 2 3 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.