CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 12 of 85
CVE-2025-55177
KEV MEDIUM

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78...

CVSS 5.4 Whatsapp whatsapp 2025-08-29
CVE-2025-57819
KEV CRITICAL

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenti...

CVSS 9.8 Sangoma freepbx 2025-08-28
CVE-2025-7775
KEV CRITICAL

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual ...

CVSS 9.8 Citrix netscaler_application_delivery_controller 2025-08-26
CVE-2025-43300
KEV CRITICAL

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS...

CVSS 10 Apple ipados 2025-08-21
CVE-2025-8876
KEV HIGH

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

CVSS 8.8 N-able n-central 2025-08-14
CVE-2025-8875
KEV HIGH

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

CVSS 7.8 N-able n-central 2025-08-14
CVE-2025-8088
KEV HIGH

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was ex...

CVSS 8.8 Rarlab winrar 2025-08-08
CVE-2025-54253
KEV CRITICAL

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this...

CVSS 10 Adobe experience_manager_forms 2025-08-05
CVE-2025-54948
KEV CRITICAL

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected in...

CVSS 9.8 Trendmicro apex_one 2025-08-05
CVE-2025-6205
KEV CRITICAL

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

CVSS 9.1 3ds delmia_apriso 2025-08-04
CVE-2025-6204
KEV HIGH

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary...

CVSS 8 3ds delmia_apriso 2025-08-04
CVE-2025-31277
KEV HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Proc...

CVSS 8.8 Apple safari 2025-07-30
CVE-2025-38352
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autor...

CVSS 7.8 Linux linux_kernel 2025-07-22
CVE-2025-53770
KEV CRITICAL

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for ...

CVSS 9.8 Microsoft sharepoint_server 2025-07-20
CVE-2025-54313
KEV HIGH

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that ...

CVSS 7.5 Prettier eslint-config-prettier 2025-07-19
CVE-2025-54309
KEV CRITICAL

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access...

CVSS 9.8 Crushftp crushftp 2025-07-18
CVE-2025-54068
KEV CRITICAL

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in s...

CVSS 9.8 Laravel livewire 2025-07-17
CVE-2025-25257
KEV CRITICAL

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4....

CVSS 9.8 Fortinet fortiweb 2025-07-17
CVE-2025-20337
KEV CRITICAL

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as roo...

CVSS 10 Cisco identity_services_engine 2025-07-16
CVE-2025-6558
KEV HIGH

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted...

CVSS 8.8 Google chrome 2025-07-15
1 10 11 12 13 14 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.