CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 10 of 85
CVE-2025-66644
KEV CRITICAL

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

CVSS 9.8 Arraynetworks arrayos_ag 2025-12-05
CVE-2025-55182
KEV CRITICAL

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serve...

CVSS 10 Facebook react 2025-12-03
CVE-2025-62593
KEV HIGH

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox an...

CVSS 8.8 Anyscale ray 2025-11-26
CVE-2025-58360
KEV CRITICAL

GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnera...

CVSS 9.8 Geoserver geoserver 2025-11-25
CVE-2025-58034
KEV HIGH

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWe...

CVSS 7.2 Fortinet fortiweb 2025-11-18
CVE-2025-13223
KEV HIGH

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:...

CVSS 8.8 Google chrome 2025-11-17
CVE-2025-64446
KEV CRITICAL

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWe...

CVSS 9.8 Fortinet fortiweb 2025-11-14
CVE-2025-62215
KEV HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS 7 Microsoft windows_10_1809 2025-11-11
CVE-2025-60710
KEV HIGH

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_11_24h2 2025-11-11
CVE-2025-12480
KEV CRITICAL

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

CVSS 9.1 Gladinet triofox 2025-11-10
CVE-2025-64328
KEV HIGH

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrat...

CVSS 7.2 Sangoma filestore 2025-11-07
CVE-2023-43000
KEV HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7...

CVSS 8.8 Apple safari 2025-11-05
CVE-2025-11953
KEV CRITICAL

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS co...

CVSS 9.8 React-native-community react_native_community_cli 2025-11-03
CVE-2025-61757
KEV CRITICAL

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easil...

CVSS 9.8 Oracle identity_manager 2025-10-21
CVE-2025-61932
KEV CRITICAL

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrar...

CVSS 9.8 Motex lanscope_endpoint_manager 2025-10-20
CVE-2025-53521
KEV CRITICAL

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached...

CVSS 9.8 F5 big-ip_access_policy_manager 2025-10-15
CVE-2025-59287
KEV CRITICAL

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CVSS 9.8 Microsoft windows_server_2012 2025-10-14
CVE-2025-59230
KEV HIGH

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1507 2025-10-14
CVE-2025-24990
KEV HIGH

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming r...

CVSS 7.8 Microsoft windows_10_1507 2025-10-14
CVE-2025-39964
KEV MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is ...

CVSS 5.5 Linux linux_kernel 2025-10-13
1 8 9 10 11 12 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.