CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 27 of 85
CVE-2023-49105
KEV CRITICAL

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, an...

CVSS 9.8 Owncloud owncloud_server 2023-11-21
CVE-2023-49103
KEV HIGH

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL...

CVSS 7.5 Owncloud graph_api 2023-11-21
CVE-2023-48365
KEV CRITICAL

Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attack...

CVSS 9.9 Qlik qlik_sense 2023-11-15
CVE-2023-36424
KEV HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2023-11-14
CVE-2023-36036
KEV HIGH

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2023-11-14
CVE-2023-36033
KEV HIGH

Windows DWM Core Library Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1809 2023-11-14
CVE-2023-36025
KEV HIGH

Windows SmartScreen Security Feature Bypass Vulnerability

CVSS 8.8 Microsoft windows_10_1507 2023-11-14
CVE-2023-47246
KEV CRITICAL

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in Novem...

CVSS 9.8 Sysaid sysaid 2023-11-10
CVE-2023-22518
KEV CRITICAL

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to re...

CVSS 9.8 Atlassian confluence_data_center 2023-10-31
CVE-2023-46604
KEV CRITICAL

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire b...

CVSS 9.8 Apache activemq 2023-10-27
CVE-2023-46748
KEV HIGH

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility...

CVSS 8.8 F5 big-ip_access_policy_manager 2023-10-26
CVE-2023-46747
KEV CRITICAL

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre...

CVSS 9.8 F5 big-ip_access_policy_manager 2023-10-26
CVE-2023-43208
KEV CRITICAL

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-...

CVSS 9.8 Nextgen mirth_connect 2023-10-26
CVE-2023-34048
KEV CRITICAL

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou...

CVSS 9.8 Vmware vcenter_server 2023-10-25
CVE-2023-20273
KEV HIGH

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is d...

CVSS 7.2 Cisco ios_xe 2023-10-25
CVE-2023-5631
KEV MEDIUM

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_...

CVSS 5.4 Debian debian_linux 2023-10-18
CVE-2023-45727
KEV HIGH

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthent...

CVSS 7.5 Northgrid proself 2023-10-18
CVE-2023-20198
KEV CRITICAL

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and...

CVSS 10 Cisco ios_xe 2023-10-16
CVE-2023-41763
KEV MEDIUM

Skype for Business Elevation of Privilege Vulnerability

CVSS 5.3 Microsoft skype_for_business_server 2023-10-10
CVE-2023-36584
KEV MEDIUM

Windows Mark of the Web Security Feature Bypass Vulnerability

CVSS 5.4 Microsoft windows_10_1507 2023-10-10
1 25 26 27 28 29 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.