CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 11 of 85
CVE-2025-61884
KEV HIGH

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu...

CVSS 7.5 Oracle configurator 2025-10-12
CVE-2025-11371
KEV HIGH

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system...

CVSS 7.5 Gladinet centrestack 2025-10-09
CVE-2025-61882
KEV CRITICAL

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14...

CVSS 9.8 Oracle concurrent_processing 2025-10-05
CVE-2025-41244
KEV HIGH

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VM...

CVSS 7.8 Vmware aria_operations 2025-09-29
CVE-2025-20362
KEV HIGH

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by...

CVSS 8.6 Cisco adaptive_security_appliance_software 2025-09-25
CVE-2025-20333
KEV CRITICAL

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an aut...

CVSS 9.9 Cisco adaptive_security_appliance_software 2025-09-25
CVE-2025-20352
KEV HIGH

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote ...

CVSS 7.7 Cisco ios_xe_sd-wan 2025-09-24
CVE-2025-10585
KEV CRITICAL

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:...

CVSS 9.8 Google chrome 2025-09-24
CVE-2025-26399
KEV CRITICAL

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker...

CVSS 9.8 Solarwinds web_help_desk 2025-09-23
CVE-2025-59689
KEV MEDIUM

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been ...

CVSS 6.1 Libraesva email_security_gateway 2025-09-19
CVE-2025-48703
KEV CRITICAL

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager ch...

CVSS 9 Control-webpanel webpanel 2025-09-19
CVE-2025-10035
KEV CRITICAL

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor...

CVSS 9.8 Fortra goanywhere_managed_file_transfer 2025-09-18
CVE-2025-9242
KEV CRITICAL

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects bo...

CVSS 9.8 Watchguard fireware 2025-09-17
CVE-2025-21043
KEV CRITICAL

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CVSS 9.8 Samsung android 2025-09-12
CVE-2025-21042
KEV CRITICAL

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

CVSS 9.8 Samsung android 2025-09-12
CVE-2025-54236
KEV CRITICAL

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attac...

CVSS 9.1 Adobe commerce 2025-09-09
CVE-2025-39682
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contig...

CVSS 7.1 Linux linux_kernel 2025-09-05
CVE-2025-48543
KEV HIGH

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege wi...

CVSS 8.8 Google android 2025-09-04
CVE-2025-53690
KEV CRITICAL

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (...

CVSS 9 Sitecore experience_commerce 2025-09-03
CVE-2025-9377
KEV HIGH

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer ...

CVSS 7.2 Tp-link tl-wr841n_firmware 2025-08-29
1 9 10 11 12 13 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.