CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 17 of 85
CVE-2025-0111
KEV MEDIUM

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read fil...

CVSS 6.5 Paloaltonetworks pan-os 2025-02-12
CVE-2025-0108
KEV CRITICAL

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authenticat...

CVSS 9.1 Paloaltonetworks pan-os 2025-02-12
CVE-2025-21418
KEV HIGH

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1607 2025-02-11
CVE-2025-21391
KEV HIGH

Windows Storage Elevation of Privilege Vulnerability

CVSS 7.1 Microsoft windows_10_1507 2025-02-11
CVE-2025-24472
KEV HIGH

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19...

CVSS 8.1 Fortinet fortiproxy 2025-02-11
CVE-2025-24016
KEV CRITICAL

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulner...

CVSS 9.9 Wazuh wazuh 2025-02-10
CVE-2025-24200
KEV MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3...

CVSS 6.1 Apple ipados 2025-02-10
CVE-2025-0994
KEV HIGH

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authen...

CVSS 8.8 Trimble cityworks 2025-02-06
CVE-2024-40891
KEV HIGH

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4...

CVSS 8.8 Zyxel vmg1312-b10a_firmware 2025-02-04
CVE-2024-40890
KEV HIGH

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_2017...

CVSS 8.8 Zyxel vmg1312-b10a_firmware 2025-02-04
CVE-2023-52163
KEV HIGH

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS 8.8 Digiever ds-2105_pro_firmware 2025-02-03
CVE-2025-25181
KEV HIGH

A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

CVSS 7.5 Advantive veracore 2025-02-03
CVE-2024-57968
KEV HIGH

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). up...

CVSS 8.8 Advantive veracore 2025-02-03
CVE-2025-24085
KEV CRITICAL

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS...

CVSS 10 Apple ipados 2025-01-27
CVE-2025-0411
KEV HIGH

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User i...

CVSS 7 Netapp active_iq_unified_manager 2025-01-25
CVE-2025-23006
KEV CRITICAL

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which...

CVSS 9.8 Sonicwall sma8200v 2025-01-23
CVE-2025-23209
KEV HIGH

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and ...

CVSS 8.1 Craftcms craft_cms 2025-01-18
CVE-2024-57728
KEV HIGH

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This ...

CVSS 7.2 Simple-help simplehelp 2025-01-15
CVE-2024-57727
KEV HIGH

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary fil...

CVSS 7.5 Simple-help simplehelp 2025-01-15
CVE-2024-57726
KEV CRITICAL

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be...

CVSS 9.9 Simple-help simplehelp 2025-01-15
1 15 16 17 18 19 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.