CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 5 of 85
CVE-2026-48027
KEV CRITICAL

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, l...

CVSS 9.8 Nx nx_console 2026-05-27
CVE-2026-48710
KEV MEDIUM

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because ...

CVSS 6.5 Encode starlette 2026-05-26
CVE-2026-45247
KEV CRITICAL

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code exec...

CVSS 9.8 Mirasvit full_page_cache_warmer 2026-05-26
CVE-2026-45659
KEV HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 Microsoft sharepoint_server 2026-05-22
CVE-2026-34910
KEV CRITICAL

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

CVSS 10 Ui unifi_os_server 2026-05-22
CVE-2026-34909
KEV CRITICAL

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulat...

CVSS 10 Ui unifi_os_server 2026-05-22
CVE-2026-34908
KEV CRITICAL

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

CVSS 10 Ui unifi_os_server 2026-05-22
CVE-2026-34926
KEV MEDIUM

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code ...

CVSS 6.7 Trendmicro apex_one 2026-05-21
CVE-2026-48172
KEV CRITICAL

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of gre...

CVSS 9.8 Litespeedtech litespeed_cpanel_plugin 2026-05-21
CVE-2026-9082
KEV CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from...

CVSS 9.8 Drupal drupal 2026-05-20
CVE-2026-45498
KEV HIGH

Microsoft Defender Denial of Service Vulnerability

CVSS 7.5 Microsoft defender_antimalware_platform 2026-05-20
CVE-2026-41091
KEV HIGH

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft malware_protection_engine 2026-05-20
CVE-2026-8398
KEV CRITICAL

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate websit...

CVSS 9.8 Disc-soft daemon_tools 2026-05-15
CVE-2026-42897
KEV MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network...

CVSS 6.1 Microsoft exchange_server 2026-05-14
CVE-2026-20182
KEV CRITICAL

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advi...

CVSS 10 Cisco catalyst_sd-wan_manager 2026-05-14
CVE-2026-0257
KEV CRITICAL

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establi...

CVSS 9.1 Paloaltonetworks pan-os 2026-05-13
CVE-2026-45321
KEV CRITICAL

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated ...

CVSS 9.6 Mistral mistralai 2026-05-12
CVE-2026-42271
KEV HIGH

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server befo...

CVSS 8.8 Redhat openshift_ai 2026-05-08
CVE-2026-42208
KEV CRITICAL

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key chec...

CVSS 9.8 Litellm litellm 2026-05-08
CVE-2026-6973
KEV HIGH

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code ...

CVSS 7.2 Ivanti endpoint_manager_mobile 2026-05-07
1 3 4 5 6 7 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.