CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 37 of 85
CVE-2022-32893
KEV HIGH

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing mali...

CVSS 8.8 Apple safari 2022-08-24
CVE-2022-37042
KEV CRITICAL

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having a...

CVSS 9.8 Synacor zimbra_collaboration_suite 2022-08-12
CVE-2022-0028
KEV HIGH

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would ap...

CVSS 8.6 Paloaltonetworks pan-os 2022-08-10
CVE-2022-34713
KEV HIGH

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2022-08-09
CVE-2022-2294
KEV HIGH

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2022-07-28
CVE-2022-1364
KEV HIGH

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2022-07-26
CVE-2022-1096
KEV HIGH

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2022-07-23
CVE-2022-26138
KEV CRITICAL

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuse...

CVSS 9.8 Atlassian questions_for_confluence 2022-07-20
CVE-2022-35405
KEV CRITICAL

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager P...

CVSS 9.8 Zohocorp manageengine_access_manager_plus 2022-07-19
CVE-2022-33891
KEV HIGH

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permi...

CVSS 8.8 Apache spark 2022-07-18
CVE-2022-26352
KEV CRITICAL

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitize...

CVSS 9.8 Dotcms dotcms 2022-07-17
CVE-2022-22047
KEV HIGH

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2022-07-12
CVE-2022-22071
KEV HIGH

Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Conn...

CVSS 7.8 Qualcomm apq8053_firmware 2022-06-14
CVE-2022-26134
KEV CRITICAL

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu...

CVSS 9.8 Atlassian confluence_data_center 2022-06-03
CVE-2022-30190
KEV HIGH

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerab...

CVSS 7.8 Microsoft windows_10_1507 2022-06-01
CVE-2022-22675
KEV HIGH

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and...

CVSS 7.8 Apple ipados 2022-05-26
CVE-2022-22674
KEV MEDIUM

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Se...

CVSS 5.5 Apple mac_os_x 2022-05-26
CVE-2022-20821
KEV MEDIUM

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi contai...

CVSS 6.5 Cisco ios_xr 2022-05-26
CVE-2022-29303
KEV CRITICAL

SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

CVSS 9.8 Contec sv-cpt-mc310_firmware 2022-05-12
CVE-2022-30525
KEV CRITICAL

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch...

CVSS 9.8 Zyxel usg_flex_100w_firmware 2022-05-12
1… 35 36 37 38 39 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.