CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 48 of 85
CVE-2021-28799
KEV CRITICAL

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in ...

CVSS 9.8 Qnap hybrid_backup_sync 2021-05-13
CVE-2021-31207
KEV MEDIUM

Microsoft Exchange Server Security Feature Bypass Vulnerability

CVSS 6.6 Microsoft exchange_server 2021-05-11
CVE-2021-31166
KEV CRITICAL

HTTP Protocol Stack Remote Code Execution Vulnerability

CVSS 9.8 Microsoft windows_10_2004 2021-05-11
CVE-2021-28664
KEV HIGH

The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages....

CVSS 8.8 Arm bifrost_gpu_kernel_driver 2021-05-10
CVE-2021-28663
KEV HIGH

The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost...

CVSS 8.8 Arm bifrost_gpu_kernel_driver 2021-05-10
CVE-2021-31755
KEV CRITICAL

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary c...

CVSS 9.8 Tenda ac11_firmware 2021-05-07
CVE-2021-1906
KEV MEDIUM

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C...

CVSS 5.5 Qualcomm apq8009_firmware 2021-05-07
CVE-2021-1905
KEV HIGH

Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon...

CVSS 7.8 Qualcomm apq8009_firmware 2021-05-07
CVE-2021-32030
KEV CRITICAL

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input fr...

CVSS 9.8 Asus lyra_mini_firmware 2021-05-06
CVE-2021-1498
KEV CRITICAL

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an...

CVSS 9.8 Cisco hyperflex_hx_data_platform 2021-05-06
CVE-2021-1497
KEV CRITICAL

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an...

CVSS 9.8 Cisco hyperflex_hx_data_platform 2021-05-06
CVE-2021-21551
KEV HIGH

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local aut...

CVSS 7.8 Dell dbutil 2021-05-04
CVE-2021-20090
KEV CRITICAL

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote ...

CVSS 9.8 Buffalo wsr-2533dhpl2-bk_firmware 2021-04-29
CVE-2021-21224
KEV HIGH

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVSS 8.8 Google chrome 2021-04-26
CVE-2021-21220
KEV HIGH

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2021-04-26
CVE-2021-21206
KEV HIGH

Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2021-04-26
CVE-2021-22205
KEV CRITICAL

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resul...

CVSS 10 Gitlab gitlab 2021-04-23
CVE-2021-22204
KEV HIGH

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

CVSS 7.8 Debian debian_linux 2021-04-23
CVE-2021-22893
KEV CRITICAL

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration feature...

CVSS 10 Ivanti connect_secure 2021-04-23
CVE-2021-3493
KEV HIGH

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. D...

CVSS 7.8 Canonical ubuntu_linux 2021-04-17
1… 46 47 48 49 50 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.