CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 20 of 85
CVE-2024-47575
KEV CRITICAL

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiMa...

CVSS 9.8 Fortinet fortimanager 2024-10-23
CVE-2024-41713
KEV CRITICAL

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path travers...

CVSS 9.1 Mitel micollab 2024-10-21
CVE-2024-9537
KEV CRITICAL

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 ...

CVSS 9.8 Sciencelogic sl1 2024-10-18
CVE-2024-9465
KEV CRITICAL

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, devic...

CVSS 9.1 Paloaltonetworks expedition 2024-10-09
CVE-2024-9463
KEV HIGH

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosur...

CVSS 7.5 Paloaltonetworks expedition 2024-10-09
CVE-2024-9680
KEV CRITICAL

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploit...

CVSS 9.8 Mozilla firefox 2024-10-09
CVE-2024-43573
KEV HIGH

Windows MSHTML Platform Spoofing Vulnerability

CVSS 8.1 Microsoft windows_10_1507 2024-10-08
CVE-2024-43572
KEV HIGH

Microsoft Management Console Remote Code Execution Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2024-10-08
CVE-2024-43468
KEV CRITICAL

Microsoft Configuration Manager Remote Code Execution Vulnerability

CVSS 9.8 Microsoft configuration_manager_2403 2024-10-08
CVE-2024-9380
KEV HIGH

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code...

CVSS 7.2 Ivanti endpoint_manager_cloud_services_appliance 2024-10-08
CVE-2024-9379
KEV HIGH

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVSS 7.2 Ivanti endpoint_manager_cloud_services_appliance 2024-10-08
CVE-2024-43047
KEV HIGH

Memory corruption while maintaining memory maps of HLOS memory.

CVSS 7.8 Qualcomm fastconnect_6700_firmware 2024-10-07
CVE-2024-45519
KEV CRITICAL

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated use...

CVSS 9.8 Synacor zimbra_collaboration_suite 2024-10-02
CVE-2024-8963
KEV CRITICAL

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

CVSS 9.1 Ivanti endpoint_manager_cloud_services_appliance 2024-09-19
CVE-2024-8957
KEV HIGH

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which m...

CVSS 7.2 Ptzoptics pt30x-sdi_firmware 2024-09-17
CVE-2024-8956
KEV CRITICAL

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi w...

CVSS 9.1 Ptzoptics pt30x-sdi_firmware 2024-09-17
CVE-2024-38813
KEV CRITICAL

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to r...

CVSS 9.8 Vmware cloud_foundation 2024-09-17
CVE-2024-38812
KEV CRITICAL

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vul...

CVSS 9.8 Vmware cloud_foundation 2024-09-17
CVE-2024-8190
KEV HIGH

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. T...

CVSS 7.2 Ivanti cloud_services_appliance 2024-09-10
CVE-2024-43461
KEV HIGH

Windows MSHTML Platform Spoofing Vulnerability

CVSS 8.8 Microsoft windows_10_1507 2024-09-10
1 18 19 20 21 22 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.