CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 23 of 85
CVE-2024-37085
KEV HIGH

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previ...

CVSS 7.2 Vmware cloud_foundation 2024-06-25
CVE-2024-37079
KEV CRITICAL

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnera...

CVSS 9.8 Vmware cloud_foundation 2024-06-18
CVE-2024-6047
KEV CRITICAL

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execu...

CVSS 9.8 Geovision gv-dsp_lpr_firmware 2024-06-17
CVE-2024-32896
KEV HIGH

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVSS 7.8 Google android 2024-06-13
CVE-2024-34102
KEV CRITICAL

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could re...

CVSS 9.8 Adobe commerce 2024-06-13
CVE-2024-35250
KEV HIGH

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2024-06-11
CVE-2024-30088
KEV HIGH

Windows Kernel Elevation of Privilege Vulnerability

CVSS 7 Microsoft windows_10_1507 2024-06-11
CVE-2024-36971
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_c...

CVSS 7.8 Debian debian_linux 2024-06-10
CVE-2024-4577
KEV CRITICAL

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m...

CVSS 9.8 Php php 2024-06-09
CVE-2024-4610
KEV HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing opera...

CVSS 7.8 Arm bifrost_gpu_kernel_driver 2024-06-07
CVE-2024-37383
KEV MEDIUM

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

CVSS 6.1 Debian debian_linux 2024-06-07
CVE-2024-28995
KEV HIGH

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

CVSS 7.5 Solarwinds serv-u 2024-06-06
CVE-2024-29824
KEV HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVSS 8.8 Ivanti endpoint_manager 2024-05-31
CVE-2024-23692
KEV CRITICAL

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to exe...

CVSS 9.8 Rejetto http_file_server 2024-05-31
CVE-2024-4358
KEV CRITICAL

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality v...

CVSS 9.8 Telerik report_server_2024 2024-05-29
CVE-2024-24919
KEV HIGH

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Sof...

CVSS 8.6 Checkpoint quantum_spark_firmware 2024-05-28
CVE-2024-5274
KEV CRITICAL

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security sever...

CVSS 9.6 Google chrome 2024-05-28
CVE-2024-4978
KEV HIGH

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor m...

CVSS 8.4 Javs javs_viewer 2024-05-23
CVE-2024-4947
KEV CRITICAL

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severi...

CVSS 9.6 Google chrome 2024-05-15
CVE-2024-30051
KEV HIGH

Windows DWM Core Library Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2024-05-14
1 21 22 23 24 25 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.