CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 42 of 85
CVE-2021-23758
KEV CRITICAL

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to ga...

CVSS 9.8 Ajaxpro.2_project ajaxpro.2 2021-12-03
CVE-2021-44077
KEV CRITICAL

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. Thi...

CVSS 9.8 Zohocorp manageengine_servicedesk_plus 2021-11-29
CVE-2021-38003
KEV HIGH

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2021-11-23
CVE-2021-38000
KEV MEDIUM

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a cr...

CVSS 6.1 Google chrome 2021-11-23
CVE-2021-44026
KEV CRITICAL

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

CVSS 9.8 Fedoraproject fedora 2021-11-19
CVE-2021-41277
KEV HIGH

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add ...

CVSS 7.5 Metabase metabase 2021-11-17
CVE-2021-42321
KEV HIGH

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 8.8 Microsoft exchange_server 2021-11-10
CVE-2021-42292
KEV HIGH

Microsoft Excel Security Feature Bypass Vulnerability

CVSS 7.8 Microsoft 365_apps 2021-11-10
CVE-2021-42287
KEV HIGH

Active Directory Domain Services Elevation of Privilege Vulnerability

CVSS 7.5 Microsoft windows_server_2004 2021-11-10
CVE-2021-42278
KEV HIGH

Active Directory Domain Services Elevation of Privilege Vulnerability

CVSS 7.5 Microsoft windows_server_2004 2021-11-10
CVE-2021-41379
KEV MEDIUM

Windows Installer Elevation of Privilege Vulnerability

CVSS 5.5 Microsoft windows_10_1507 2021-11-10
CVE-2021-42237
KEV CRITICAL

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the mach...

CVSS 9.8 Sitecore experience_platform 2021-11-05
CVE-2021-42258
KEV CRITICAL

BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware in...

CVSS 9.8 Bqe billquick_web_suite 2021-10-22
CVE-2021-30807
KEV HIGH

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may ...

CVSS 7.8 Apple ipados 2021-10-19
CVE-2021-27561
KEV CRITICAL

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

CVSS 9.8 Yealink device_management 2021-10-15
CVE-2021-20124
KEV HIGH

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could levera...

CVSS 7.5 Draytek vigorconnect 2021-10-13
CVE-2021-20123
KEV HIGH

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker cou...

CVSS 7.5 Draytek vigorconnect 2021-10-13
CVE-2021-41357
KEV HIGH

Win32k Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_2004 2021-10-13
CVE-2021-40450
KEV HIGH

Win32k Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1809 2021-10-13
CVE-2021-40449
KEV HIGH

Win32k Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2021-10-13
1… 40 41 42 43 44 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.