CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 19 of 85
CVE-2024-11667
KEV CRITICAL

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38...

CVSS 9.8 Zyxel zld 2024-11-27
CVE-2024-49035
KEV CRITICAL

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

CVSS 9.8 Microsoft partner_center 2024-11-26
CVE-2024-11680
KEV CRITICAL

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP reques...

CVSS 9.8 Projectsend projectsend 2024-11-26
CVE-2024-44309
KEV MEDIUM

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequ...

CVSS 6.3 Debian debian_linux 2024-11-20
CVE-2024-44308
KEV HIGH

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1...

CVSS 8.8 Debian debian_linux 2024-11-20
CVE-2024-50302
KEV MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in variou...

CVSS 5.5 Debian debian_linux 2024-11-19
CVE-2024-21287
KEV HIGH

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is...

CVSS 7.5 Oracle agile_product_lifecycle_management 2024-11-18
CVE-2024-9474
KEV HIGH

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firew...

CVSS 7.2 Paloaltonetworks pan-os 2024-11-18
CVE-2024-0012
KEV CRITICAL

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator ...

CVSS 9.8 Paloaltonetworks pan-os 2024-11-18
CVE-2024-11182
KEV MEDIUM

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remot...

CVSS 6.1 Mdaemon mdaemon 2024-11-15
CVE-2024-11120
KEV CRITICAL

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system com...

CVSS 9.8 Geovision gv-vs12_firmware 2024-11-15
CVE-2024-43093
KEV HIGH

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicod...

CVSS 7.3 Google android 2024-11-13
CVE-2024-8069
KEV HIGH

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the ses...

CVSS 8 Citrix session_recording 2024-11-12
CVE-2024-8068
KEV HIGH

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the sessi...

CVSS 8 Citrix session_recording 2024-11-12
CVE-2024-49039
KEV HIGH

Windows Task Scheduler Elevation of Privilege Vulnerability

CVSS 8.8 Microsoft windows_10_1507 2024-11-12
CVE-2024-43451
KEV MEDIUM

NTLM Hash Disclosure Spoofing Vulnerability

CVSS 6.5 Microsoft windows_10_1507 2024-11-12
CVE-2024-51567
KEV CRITICAL

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBas...

CVSS 9.8 Cyberpanel cyberpanel 2024-10-29
CVE-2024-51378
KEV CRITICAL

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /...

CVSS 9.8 Cyberpanel cyberpanel 2024-10-29
CVE-2024-50623
KEV CRITICAL

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

CVSS 9.8 Cleo harmony 2024-10-28
CVE-2024-20481
KEV MEDIUM

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauth...

CVSS 5.8 Cisco secure_firewall_threat_defense 2024-10-23
1 17 18 19 20 21 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.