CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 2 of 85
CVE-2026-72530
KEV CRITICAL

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a special...

CVSS 9 Trueconf trueconf_server 2026-08-19
CVE-2026-72529
KEV CRITICAL

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an ar...

CVSS 9.8 Trueconf trueconf_server 2026-08-19
CVE-2026-19490
KEV CRITICAL

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 t...

CVSS 9.8 Citrix netscaler_application_delivery_controller 2026-08-19
CVE-2026-64849
KEV CRITICAL

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/...

CVSS 9.3 Lfprojects mlflow 2026-08-17
CVE-2026-73570
KEV HIGH

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due...

CVSS 8.9 Synacor zimbra_collaboration_suite 2026-08-13
CVE-2026-42018
KEV HIGH

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CVSS 7.5 Jfrog artifactory 2026-08-12
CVE-2026-66384
KEV MEDIUM

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

CVSS 5.3 Jfrog artifactory 2026-08-12
CVE-2026-68820
KEV HIGH

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7 Microsoft windows_10_1607 2026-08-11
CVE-2026-20349
KEV HIGH

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software co...

CVSS 8.6 Cisco adaptive_security_appliance_software 2026-08-11
CVE-2026-72898
KEV CRITICAL

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase insta...

CVSS 10 Metabase metabase 2026-08-10
CVE-2026-65400
KEV CRITICAL

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, ma...

CVSS 9.8 Apple macos 2026-08-06
CVE-2026-18577
KEV HIGH

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVSS 8.1 N-able n-central 2026-08-02
CVE-2026-18556
KEV HIGH

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CVSS 7.4 N-able n-central 2026-08-01
CVE-2026-59310
KEV CRITICAL

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

CVSS 9.8 Vmware vcenter_server 2026-07-30
CVE-2026-20316
KEV MEDIUM

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using...

CVSS 5.3 Cisco secure_firewall_management_center 2026-07-29
CVE-2026-42016
KEV HIGH

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s...

CVSS 8.8 Jfrog artifactory 2026-07-27
CVE-2026-63077
KEV CRITICAL

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS 9.8 Jetbrains teamcity 2026-07-27
CVE-2026-16812
KEV CRITICAL

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successf...

CVSS 10 Arista velocloud_orchestrator 2026-07-27
CVE-2026-16232
KEV CRITICAL

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to au...

CVSS 9.8 Checkpoint multi-domain_security_management 2026-07-22
CVE-2026-63030
KEV CRITICAL

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (C...

CVSS 9.8 Wordpress wordpress 2026-07-17
1 2 3 4 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.