CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 18 of 85
CVE-2025-21335
KEV HIGH

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_21h2 2025-01-14
CVE-2025-21334
KEV HIGH

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_21h2 2025-01-14
CVE-2025-21333
KEV HIGH

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_21h2 2025-01-14
CVE-2024-13161
KEV HIGH

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit...

CVSS 7.5 Ivanti endpoint_manager 2025-01-14
CVE-2024-13160
KEV HIGH

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit...

CVSS 7.5 Ivanti endpoint_manager 2025-01-14
CVE-2024-13159
KEV HIGH

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit...

CVSS 7.5 Ivanti endpoint_manager 2025-01-14
CVE-2024-55591
KEV CRITICAL

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7...

CVSS 9.8 Fortinet fortiproxy 2025-01-14
CVE-2024-53704
KEV CRITICAL

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

CVSS 9.8 Sonicwall sonicos 2025-01-09
CVE-2025-0282
KEV CRITICAL

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22....

CVSS 9 Ivanti connect_secure 2025-01-08
CVE-2024-50603
KEV CRITICAL

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthent...

CVSS 9.8 Aviatrix controller 2025-01-08
CVE-2024-12987
KEV CRITICAL

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcf...

CVSS 9.8 Draytek vigor300b_firmware 2024-12-27
CVE-2024-53197
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a ...

CVSS 7.8 Linux linux_kernel 2024-12-27
CVE-2024-3393
KEV HIGH

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data p...

CVSS 7.5 Paloaltonetworks pan-os 2024-12-27
CVE-2024-53150
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't ...

CVSS 7.1 Debian debian_linux 2024-12-24
CVE-2024-56145
KEV CRITICAL

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini...

CVSS 9.8 Craftcms craft_cms 2024-12-18
CVE-2024-12686
KEV HIGH

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands...

CVSS 7.2 Beyondtrust privileged_remote_access 2024-12-18
CVE-2024-12356
KEV CRITICAL

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that ...

CVSS 9.8 Beyondtrust privileged_remote_access 2024-12-17
CVE-2024-55956
KEV CRITICAL

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the ...

CVSS 9.8 Cleo harmony 2024-12-13
CVE-2024-49138
KEV HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2024-12-12
CVE-2024-53104
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of boun...

CVSS 7.8 Debian debian_linux 2024-12-02
1 16 17 18 19 20 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.