CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 26 of 85
CVE-2023-6548
KEV HIGH

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to p...

CVSS 8.8 Citrix netscaler_application_delivery_controller 2024-01-17
CVE-2024-0519
KEV HIGH

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur...

CVSS 8.8 Google chrome 2024-01-16
CVE-2023-22527
KEV CRITICAL

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using...

CVSS 9.8 Atlassian confluence_data_center 2024-01-16
CVE-2024-21887
KEV CRITICAL

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send special...

CVSS 9.1 Ivanti connect_secure 2024-01-12
CVE-2023-46805
KEV HIGH

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing co...

CVSS 8.2 Ivanti connect_secure 2024-01-12
CVE-2023-7028
KEV CRITICAL

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5....

CVSS 9.8 Gitlab gitlab 2024-01-12
CVE-2023-41974
KEV HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbit...

CVSS 7.8 Apple ipados 2024-01-10
CVE-2022-48618
KEV HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write...

CVSS 7 Apple ipados 2024-01-09
CVE-2023-7101
KEV HIGH

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to ...

CVSS 7.8 Debian debian_linux 2023-12-24
CVE-2023-7024
KEV HIGH

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security...

CVSS 8.8 Google chrome 2023-12-21
CVE-2023-47565
KEV HIGH

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated us...

CVSS 8.8 Qnap qvr_firmware 2023-12-08
CVE-2023-49897
KEV HIGH

An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an ar...

CVSS 8.8 Fxc ae1021_firmware 2023-12-06
CVE-2023-44221
KEV HIGH

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary comm...

CVSS 7.2 Sonicwall sma_200_firmware 2023-12-05
CVE-2023-6448
KEV CRITICAL

Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take...

CVSS 9.8 Unitronics vision1210_firmware 2023-12-05
CVE-2023-33107
KEV HIGH

Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

CVSS 7.8 Qualcomm 315_5g_iot_modem_firmware 2023-12-05
CVE-2023-33106
KEV HIGH

Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

CVSS 7.8 Qualcomm ar8035_firmware 2023-12-05
CVE-2023-33063
KEV HIGH

Memory corruption in DSP Services during a remote call from HLOS to DSP.

CVSS 7.8 Qualcomm 315_5g_iot_modem_firmware 2023-12-05
CVE-2023-42917
KEV HIGH

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web conte...

CVSS 8.8 Apple safari 2023-11-30
CVE-2023-42916
KEV MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content ...

CVSS 6.5 Apple safari 2023-11-30
CVE-2023-6345
KEV CRITICAL

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a m...

CVSS 9.6 Google chrome 2023-11-29
1 24 25 26 27 28 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.