CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 40 of 85
CVE-2022-24086
KEV CRITICAL

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of th...

CVSS 9.8 Adobe commerce 2022-02-16
CVE-2021-4102
KEV HIGH

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2022-02-11
CVE-2022-0185
KEV HIGH

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters ...

CVSS 8.4 Linux linux_kernel 2022-02-11
CVE-2022-24112
KEV CRITICAL

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne...

CVSS 9.8 Apache apisix 2022-02-11
CVE-2022-20708
KEV HIGH

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr...

CVSS 8 Cisco rv340_firmware 2022-02-10
CVE-2022-20703
KEV HIGH

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr...

CVSS 8 Cisco rv340_firmware 2022-02-10
CVE-2022-20701
KEV HIGH

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr...

CVSS 7.8 Cisco rv340_firmware 2022-02-10
CVE-2022-20700
KEV CRITICAL

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr...

CVSS 9.8 Cisco rv340_firmware 2022-02-10
CVE-2022-20699
KEV CRITICAL

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr...

CVSS 9.8 Cisco rv340_firmware 2022-02-10
CVE-2022-22536
KEV CRITICAL

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and...

CVSS 10 Sap content_server 2022-02-09
CVE-2022-22718
KEV HIGH

Windows Print Spooler Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2022-02-09
CVE-2022-21999
KEV HIGH

Windows Print Spooler Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2022-02-09
CVE-2022-21971
KEV HIGH

Windows Runtime Remote Code Execution Vulnerability

CVSS 7.8 Microsoft windows_10_1809 2022-02-09
CVE-2022-24682
KEV MEDIUM

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attack...

CVSS 6.1 Synacor zimbra_collaboration_suite 2022-02-09
CVE-2021-4034
KEV HIGH

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri...

CVSS 7.8 Redhat enterprise_linux_server_update_services_for_sap_solutions 2022-01-28
CVE-2021-40407
KEV HIGH

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->doma...

CVSS 7.2 Reolink rlc-410w_firmware 2022-01-28
CVE-2021-22600
KEV HIGH

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgr...

CVSS 7 Linux linux_kernel 2022-01-26
CVE-2021-35587
KEV CRITICAL

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2....

CVSS 9.8 Oracle access_manager 2022-01-19
CVE-2022-23227
KEV CRITICAL

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_us...

CVSS 9.8 Nuuo nvrmini2_firmware 2022-01-14
CVE-2022-23134
KEV MEDIUM

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step ch...

CVSS 5.3 Fedoraproject fedora 2022-01-13
1… 38 39 40 41 42 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.