CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,696 result(s) · page 34 of 85
CVE-2023-21715
KEV HIGH

Microsoft Publisher Security Feature Bypass Vulnerability

CVSS 7.3 Microsoft 365_apps 2023-02-14
CVE-2023-21529
KEV HIGH

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 8.8 Microsoft exchange_server 2023-02-14
CVE-2023-25717
KEV CRITICAL

Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$...

CVSS 9.8 Ruckuswireless ruckus_wireless_admin 2023-02-13
CVE-2022-24990
KEV HIGH

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading...

CVSS 7.5 Terra-master terramaster_operating_system 2023-02-07
CVE-2023-0669
KEV HIGH

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary at...

CVSS 7.2 Fortra goanywhere_managed_file_transfer 2023-02-06
CVE-2023-0266
KEV HIGH

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that ca...

CVSS 7 Debian debian_linux 2023-01-30
CVE-2023-21608
KEV HIGH

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result...

CVSS 7.8 Adobe acrobat_dc 2023-01-18
CVE-2022-47966
KEV CRITICAL

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java...

CVSS 9.8 Zohocorp manageengine_access_manager_plus 2023-01-18
CVE-2023-21839
KEV HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0....

CVSS 7.5 Oracle weblogic_server 2023-01-18
CVE-2023-22952
KEV HIGH

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

CVSS 8.8 Sugarcrm sugarcrm 2023-01-11
CVE-2023-21674
KEV HIGH

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVSS 8.8 Microsoft windows_10_1507 2023-01-10
CVE-2022-44877
KEV CRITICAL

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the logi...

CVSS 9.8 Control-webpanel webpanel 2023-01-05
CVE-2022-42475
KEV CRITICAL

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an...

CVSS 9.8 Fortinet fortios 2023-01-02
CVE-2022-26486
KEV CRITICAL

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This ...

CVSS 9.6 Mozilla firefox 2022-12-22
CVE-2022-26485
KEV HIGH

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affe...

CVSS 8.8 Mozilla firefox 2022-12-22
CVE-2022-42856
KEV HIGH

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Proc...

CVSS 8.8 Apple safari 2022-12-15
CVE-2022-44698
KEV MEDIUM

Windows SmartScreen Security Feature Bypass Vulnerability

CVSS 5.4 Microsoft windows_10_1607 2022-12-13
CVE-2022-27518
KEV CRITICAL

Unauthenticated remote arbitrary code execution

CVSS 9.8 Citrix application_delivery_controller_firmware 2022-12-13
CVE-2022-46169
KEV CRITICAL

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu...

CVSS 9.8 Cacti cacti 2022-12-05
CVE-2022-4262
KEV HIGH

Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: ...

CVSS 8.8 Google chrome 2022-12-02
1 32 33 34 35 36 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.