CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 24 of 85
CVE-2024-30040
KEV HIGH

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVSS 8.8 Microsoft windows_10_1507 2024-05-14
CVE-2024-4761
KEV HIGH

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security se...

CVSS 8.8 Google chrome 2024-05-14
CVE-2024-4671
KEV CRITICAL

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a ...

CVSS 9.6 Google chrome 2024-05-14
CVE-2024-32113
KEV CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommende...

CVSS 9.8 Apache ofbiz 2024-05-08
CVE-2023-50224
KEV MEDIUM

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information o...

CVSS 6.5 Tp-link tl-wr841n_firmware 2024-05-03
CVE-2024-20359
KEV MEDIUM

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software a...

CVSS 6 Cisco adaptive_security_appliance_software 2024-04-24
CVE-2024-20353
KEV HIGH

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthen...

CVSS 8.6 Cisco adaptive_security_appliance_software 2024-04-24
CVE-2024-4040
KEV CRITICAL

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the ...

CVSS 10 Crushftp crushftp 2024-04-22
CVE-2024-27348
KEV CRITICAL

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended t...

CVSS 9.8 Apache hugegraph 2024-04-22
CVE-2024-3400
KEV CRITICAL

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinc...

CVSS 10 Paloaltonetworks pan-os 2024-04-12
CVE-2024-29988
KEV HIGH

SmartScreen Prompt Security Feature Bypass Vulnerability

CVSS 8.8 Microsoft windows_10_1809 2024-04-09
CVE-2024-29748
KEV HIGH

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVSS 7.8 Google android 2024-04-05
CVE-2024-29745
KEV MEDIUM

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interacti...

CVSS 5.5 Google android 2024-04-05
CVE-2024-3273
KEV CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unkno...

CVSS 9.8 Dlink dns-320l_firmware 2024-04-04
CVE-2024-3272
KEV CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue...

CVSS 9.8 Dlink dns-320l_firmware 2024-04-04
CVE-2024-29059
KEV HIGH

.NET Framework Information Disclosure Vulnerability

CVSS 7.5 Microsoft .net_framework 2024-03-23
CVE-2024-20767
KEV HIGH

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage...

CVSS 7.4 Adobe coldfusion 2024-03-18
CVE-2024-26169
KEV HIGH

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2024-03-12
CVE-2023-48788
KEV CRITICAL

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 a...

CVSS 9.8 Fortinet forticlient_enterprise_management_server 2024-03-12
CVE-2024-23296
KEV HIGH

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma...

CVSS 7.8 Apple ipados 2024-03-05
1 22 23 24 25 26 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.