CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,696 result(s) · page 33 of 85
CVE-2022-43769
KEV HIGH

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring temp...

CVSS 7.2 Hitachi vantara_pentaho_business_analytics_server 2023-04-03
CVE-2023-20963
KEV HIGH

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVSS 7.8 Google android 2023-03-24
CVE-2022-42948
KEV CRITICAL

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the C...

CVSS 9.8 Helpsystems cobalt_strike 2023-03-24
CVE-2023-26360
KEV HIGH

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code ...

CVSS 8.6 Adobe coldfusion 2023-03-23
CVE-2023-26359
KEV CRITICAL

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitr...

CVSS 9.8 Adobe coldfusion 2023-03-23
CVE-2023-28434
KEV HIGH

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an obje...

CVSS 8.8 Minio minio 2023-03-22
CVE-2023-28432
KEV HIGH

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all env...

CVSS 7.5 Minio minio 2023-03-22
CVE-2023-0386
KEV HIGH

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a u...

CVSS 7.8 Debian debian_linux 2023-03-22
CVE-2023-25280
KEV CRITICAL

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVSS 9.8 Dlink dir-820l_firmware 2023-03-16
CVE-2023-28461
KEV CRITICAL

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in...

CVSS 9.8 Arraynetworks arrayos_ag 2023-03-15
CVE-2023-1389
KEV HIGH

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoin...

CVSS 8.8 Tp-link archer_ax21_firmware 2023-03-15
CVE-2023-23397
KEV CRITICAL

Microsoft Outlook Elevation of Privilege Vulnerability

CVSS 9.8 Microsoft 365_apps 2023-03-14
CVE-2023-27532
KEV HIGH

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backu...

CVSS 7.5 Veeam veeam_backup_\&_replication 2023-03-10
CVE-2022-41328
KEV HIGH

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and bef...

CVSS 7.1 Fortinet fortios 2023-03-07
CVE-2019-8720
KEV HIGH

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addre...

CVSS 8.8 Redhat codeready_linux_builder 2023-03-06
CVE-2023-23529
KEV HIGH

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Pro...

CVSS 8.8 Apple safari 2023-02-27
CVE-2022-47986
KEV CRITICAL

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a special...

CVSS 9.8 Ibm aspera_faspex 2023-02-17
CVE-2023-23752
KEV MEDIUM

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

CVSS 5.3 Joomla joomla\! 2023-02-16
CVE-2023-21823
KEV HIGH

Windows Graphics Component Remote Code Execution Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2023-02-14
CVE-2023-23376
KEV HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2023-02-14
1 31 32 33 34 35 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.