CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 15 of 85
CVE-2025-31324
KEV CRITICAL

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries tha...

CVSS 9.8 Sap netweaver 2025-04-24
CVE-2025-1976
KEV MEDIUM

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges...

CVSS 6.7 Broadcom fabric_operating_system 2025-04-24
CVE-2025-34028
KEV CRITICAL

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vu...

CVSS 10 Commvault commvault 2025-04-22
CVE-2025-42599
KEV CRITICAL

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthe...

CVSS 9.8 Qualitia active\!_mail 2025-04-18
CVE-2025-32433
KEV CRITICAL

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform ...

CVSS 10 Cisco confd_basic 2025-04-16
CVE-2025-31201
KEV CRITICAL

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with a...

CVSS 9.8 Apple macos 2025-04-16
CVE-2025-31200
KEV CRITICAL

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watch...

CVSS 9.8 Apple macos 2025-04-16
CVE-2024-58136
KEV CRITICAL

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 202...

CVSS 9.8 Yiiframework yii 2025-04-10
CVE-2025-29824
KEV HIGH

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1507 2025-04-08
CVE-2025-3248
KEV CRITICAL

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to e...

CVSS 9.8 Langflow langflow 2025-04-07
CVE-2025-31161
KEV CRITICAL

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild i...

CVSS 9.8 Crushftp crushftp 2025-04-03
CVE-2025-30406
KEV CRITICAL

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited...

CVSS 9.8 Gladinet centrestack 2025-04-03
CVE-2025-22457
KEV CRITICAL

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows...

CVSS 9.8 Ivanti connect_secure 2025-04-03
CVE-2025-31125
KEV HIGH

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev serve...

CVSS 7.5 Vitejs vite 2025-03-31
CVE-2025-2783
KEV HIGH

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malic...

CVSS 8.3 Google chrome 2025-03-26
CVE-2025-29635
KEV HIGH

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /g...

CVSS 7.2 Dlink dir-823x_firmware 2025-03-25
CVE-2025-2749
KEV HIGH

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path...

CVSS 7.2 Kentico xperience 2025-03-24
CVE-2025-2747
KEV CRITICAL

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. A...

CVSS 9.8 Kentico xperience 2025-03-24
CVE-2025-2746
KEV CRITICAL

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authenticat...

CVSS 9.8 Kentico xperience 2025-03-24
CVE-2025-30154
KEV HIGH

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added ...

CVSS 8.6 Reviewdog action-ast-grep 2025-03-19
1 13 14 15 16 17 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.