CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 22 of 85
CVE-2024-38106
KEV HIGH

Windows Kernel Elevation of Privilege Vulnerability

CVSS 7 Microsoft windows_10_1507 2024-08-13
CVE-2024-41710
KEV HIGH

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated...

CVSS 7.2 Mitel 6970_firmware 2024-08-12
CVE-2024-27443
KEV MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic us...

CVSS 6.1 Zimbra collaboration 2024-08-12
CVE-2024-7694
KEV HIGH

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload...

CVSS 7.2 Teamt5 threatsonar_anti-ransomware 2024-08-12
CVE-2024-7399
KEV CRITICAL

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system au...

CVSS 9.8 Samsung magicinfo_9_server 2024-08-12
CVE-2024-42009
KEV CRITICAL

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message t...

CVSS 9.3 Roundcube webmail 2024-08-05
CVE-2024-38856
KEV CRITICAL

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the is...

CVSS 9.8 Apache ofbiz 2024-08-05
CVE-2023-45249
KEV CRITICAL

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructur...

CVSS 9.8 Acronis cyber_infrastructure 2024-07-24
CVE-2024-21182
KEV HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily expl...

CVSS 7.5 Oracle weblogic_server 2024-07-16
CVE-2024-5910
KEV CRITICAL

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. N...

CVSS 9.8 Paloaltonetworks expedition 2024-07-10
CVE-2024-5217
KEV CRITICAL

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a...

CVSS 9.8 Servicenow servicenow 2024-07-10
CVE-2024-4879
KEV CRITICAL

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthentica...

CVSS 9.8 Servicenow servicenow 2024-07-10
CVE-2024-38112
KEV HIGH

Windows MSHTML Platform Spoofing Vulnerability

CVSS 7.5 Microsoft windows_10_1507 2024-07-09
CVE-2024-38094
KEV HIGH

Microsoft SharePoint Remote Code Execution Vulnerability

CVSS 7.2 Microsoft sharepoint_server 2024-07-09
CVE-2024-38080
KEV HIGH

Windows Hyper-V Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_11_21h2 2024-07-09
CVE-2024-39891
KEV MEDIUM

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited...

CVSS 5.3 Twilio authy 2024-07-02
CVE-2024-38475
KEV CRITICAL

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the se...

CVSS 9.1 Apache http_server 2024-07-01
CVE-2024-20399
KEV MEDIUM

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underly...

CVSS 6.7 Cisco nx-os 2024-07-01
CVE-2024-36401
KEV CRITICAL

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow ...

CVSS 9.8 Geoserver geoserver 2024-07-01
CVE-2024-4885
KEV CRITICAL

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWith...

CVSS 9.8 Progress whatsup_gold 2024-06-25
1 20 21 22 23 24 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.