CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 14 of 85
CVE-2025-48927
KEV MEDIUM

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

CVSS 5.3 Smarsh telemessage 2025-05-28
CVE-2025-34026
KEV HIGH

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative...

CVSS 7.5 Versa-networks concerto 2025-05-21
CVE-2025-4008
KEV HIGH

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written i...

CVSS 8.8 Smartbedded meteobridge_vm 2025-05-21
CVE-2025-32709
KEV HIGH

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1507 2025-05-13
CVE-2025-32706
KEV HIGH

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1507 2025-05-13
CVE-2025-32701
KEV HIGH

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1507 2025-05-13
CVE-2025-30400
KEV HIGH

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1809 2025-05-13
CVE-2025-30397
KEV HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

CVSS 7.5 Microsoft windows_10_1507 2025-05-13
CVE-2025-4428
KEV HIGH

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via cr...

CVSS 8.8 Ivanti endpoint_manager_mobile 2025-05-13
CVE-2025-4427
KEV HIGH

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the...

CVSS 7.5 Ivanti endpoint_manager_mobile 2025-05-13
CVE-2025-32756
KEV CRITICAL

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMa...

CVSS 9.8 Fortinet fortimail 2025-05-13
CVE-2025-4632
KEV CRITICAL

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system au...

CVSS 9.8 Samsung magicinfo_9_server 2025-05-13
CVE-2025-42999
KEV CRITICAL

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a...

CVSS 9.1 Sap netweaver 2025-05-13
CVE-2025-35939
KEV MEDIUM

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Cra...

CVSS 5.3 Craftcms craft_cms 2025-05-07
CVE-2025-2776
KEV CRITICAL

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrat...

CVSS 9.8 Sysaid sysaid 2025-05-07
CVE-2025-2775
KEV HIGH

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator...

CVSS 7.5 Sysaid sysaid 2025-05-07
CVE-2025-27920
KEV HIGH

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sens...

CVSS 8.8 Srimax output_messenger 2025-05-05
CVE-2025-3935
KEV HIGH

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with...

CVSS 7.2 Connectwise screenconnect 2025-04-25
CVE-2025-3928
KEV HIGH

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised...

CVSS 8.8 Commvault commvault 2025-04-25
CVE-2025-32432
KEV CRITICAL

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15,...

CVSS 10 Craftcms craft_cms 2025-04-25
1 12 13 14 15 16 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.