CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 43 of 85
CVE-2021-37976
KEV MEDIUM

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafte...

CVSS 6.5 Google chrome 2021-10-08
CVE-2021-37975
KEV HIGH

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2021-10-08
CVE-2021-37973
KEV CRITICAL

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cr...

CVSS 9.6 Google chrome 2021-10-08
CVE-2021-30633
KEV CRITICAL

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v...

CVSS 9.6 Google chrome 2021-10-08
CVE-2021-30632
KEV HIGH

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2021-10-08
CVE-2021-42013
KEV CRITICAL

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori...

CVSS 9.8 Apache http_server 2021-10-07
CVE-2021-25489
KEV MEDIUM

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

CVSS 5.5 Samsung android 2021-10-06
CVE-2021-25487
KEV HIGH

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dere...

CVSS 7.8 Samsung android 2021-10-06
CVE-2021-39226
KEV HIGH

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by ac...

CVSS 7.3 Grafana grafana 2021-10-05
CVE-2021-41773
KEV CRITICAL

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con...

CVSS 9.8 Apache http_server 2021-10-05
CVE-2021-20035
KEV MEDIUM

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentia...

CVSS 6.5 Sonicwall sma_200_firmware 2021-09-27
CVE-2021-40655
KEV HIGH

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php ...

CVSS 7.5 Dlink dir-605l_firmware 2021-09-24
CVE-2021-22941
KEV CRITICAL

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CVSS 9.8 Citrix sharefile_storagezones_controller 2021-09-23
CVE-2021-22017
KEV MEDIUM

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Serve...

CVSS 5.3 Vmware vcenter_server 2021-09-23
CVE-2021-22005
KEV CRITICAL

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this is...

CVSS 9.8 Vmware cloud_foundation 2021-09-23
CVE-2021-36260
KEV CRITICAL

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command ...

CVSS 9.8 Hikvision ds-2cd2026g2-iu\/sl_firmware 2021-09-22
CVE-2021-38406
KEV HIGH

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bound...

CVSS 7.8 Deltaww dopsoft 2021-09-17
CVE-2021-40438
KEV CRITICAL

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS 9 Redhat enterprise_linux 2021-09-16
CVE-2021-33045
KEV CRITICAL

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing maliciou...

CVSS 9.8 Dahuasecurity ipc-hum7xxx_firmware 2021-09-15
CVE-2021-33044
KEV CRITICAL

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing maliciou...

CVSS 9.8 Dahuasecurity ipc-hum7xxx_firmware 2021-09-15
1… 41 42 43 44 45 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.