CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 41 of 85
CVE-2022-23131
KEV CRITICAL

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session w...

CVSS 9.8 Zabbix zabbix 2022-01-13
CVE-2022-21919
KEV HIGH

Windows User Profile Service Elevation of Privilege Vulnerability

CVSS 7 Microsoft windows_10_1507 2022-01-11
CVE-2022-21882
KEV HIGH

Win32k Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1809 2022-01-11
CVE-2022-22265
KEV HIGH

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

CVSS 7.8 Google android 2022-01-10
CVE-2021-35247
KEV MEDIUM

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional valida...

CVSS 5.3 Solarwinds serv-u 2022-01-10
CVE-2021-44168
KEV HIGH

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbit...

CVSS 7.8 Fortinet fortios 2022-01-04
CVE-2021-44207
KEV HIGH

Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

CVSS 8.1 Acclaimsystems usaherds 2021-12-21
CVE-2021-22054
KEV HIGH

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. Thi...

CVSS 7.5 Vmware workspace_one_uem_console 2021-12-17
CVE-2021-1048
KEV HIGH

In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional executi...

CVSS 7.8 Google android 2021-12-15
CVE-2021-0920
KEV MEDIUM

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges n...

CVSS 6.4 Linux linux_kernel 2021-12-15
CVE-2021-43890
KEV HIGH

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability ...

CVSS 7.1 Microsoft app_installer 2021-12-15
CVE-2021-43226
KEV HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2021-12-15
CVE-2021-45046
KEV CRITICAL

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Threa...

CVSS 9 Apache log4j 2021-12-14
CVE-2021-39935
KEV HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5...

CVSS 7.5 Gitlab gitlab 2021-12-13
CVE-2021-44515
KEV CRITICAL

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise ...

CVSS 9.8 Zohocorp manageengine_desktop_central 2021-12-12
CVE-2021-44228
KEV CRITICAL

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai...

CVSS 10 Apache log4j 2021-12-10
CVE-2021-44529
KEV CRITICAL

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

CVSS 9.8 Ivanti endpoint_manager_cloud_services_appliance 2021-12-08
CVE-2021-27860
KEV HIGH

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker ...

CVSS 8.8 Fatpipeinc ipvpn_firmware 2021-12-08
CVE-2021-20038
KEV CRITICAL

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute cod...

CVSS 9.8 Sonicwall sma_200_firmware 2021-12-08
CVE-2021-43798
KEV HIGH

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal,...

CVSS 7.5 Grafana grafana 2021-12-07
1… 39 40 41 42 43 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.