CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,691 result(s) · page 29 of 85
CVE-2023-36761
KEV MEDIUM

Microsoft Word Information Disclosure Vulnerability

CVSS 6.5 Microsoft 365_apps 2023-09-12
CVE-2023-4863
KEV HIGH

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag...

CVSS 8.8 Google chrome 2023-09-12
CVE-2023-41990
KEV HIGH

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iP...

CVSS 7.8 Apple ipados 2023-09-12
CVE-2023-35674
KEV HIGH

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no ...

CVSS 7.8 Google android 2023-09-11
CVE-2023-39780
KEV HIGH

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token...

CVSS 8.8 Asus rt-ax55_firmware 2023-09-11
CVE-2023-41064
KEV HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 an...

CVSS 7.8 Apple ipados 2023-09-07
CVE-2023-41061
KEV HIGH

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary c...

CVSS 7.8 Apple ipados 2023-09-07
CVE-2023-20269
KEV CRITICAL

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticate...

CVSS 9.1 Cisco adaptive_security_appliance_software 2023-09-06
CVE-2023-4762
KEV HIGH

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8 Google chrome 2023-09-05
CVE-2023-41266
KEV MEDIUM

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and e...

CVSS 6.5 Qlik qlik_sense 2023-08-29
CVE-2023-41265
KEV CRITICAL

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch...

CVSS 9.9 Qlik qlik_sense 2023-08-29
CVE-2023-4346
KEV HIGH

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain...

CVSS 7.5 Knx connection_authorization 2023-08-29
CVE-2023-38831
KEV HIGH

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may inc...

CVSS 7.8 Rarlab winrar 2023-08-23
CVE-2023-38035
KEV CRITICAL

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administra...

CVSS 9.8 Ivanti mobileiron_sentry 2023-08-21
CVE-2023-36847
KEV MEDIUM

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to ...

CVSS 5.3 Juniper junos 2023-08-17
CVE-2023-36846
KEV MEDIUM

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to...

CVSS 5.3 Juniper junos 2023-08-17
CVE-2023-36845
KEV CRITICAL

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remote...

CVSS 9.8 Juniper junos 2023-08-17
CVE-2023-36844
KEV MEDIUM

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, importan...

CVSS 5.3 Juniper junos 2023-08-17
CVE-2023-35082
KEV CRITICAL

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper a...

CVSS 9.8 Ivanti endpoint_manager_mobile 2023-08-15
CVE-2022-48503
KEV HIGH

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web conte...

CVSS 8.8 Apple safari 2023-08-14
1 27 28 29 30 31 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.