CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 50 of 85
CVE-2021-21166
KEV HIGH

Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2021-03-09
CVE-2021-25337
KEV HIGH

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

CVSS 7.1 Samsung android 2021-03-04
CVE-2021-22681
KEV CRITICAL

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell ...

CVSS 9.8 Rockwellautomation factorytalk_services_platform 2021-03-03
CVE-2021-27065
KEV HIGH

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8 Microsoft exchange_server 2021-03-03
CVE-2021-26858
KEV HIGH

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8 Microsoft exchange_server 2021-03-03
CVE-2021-26857
KEV HIGH

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8 Microsoft exchange_server 2021-03-03
CVE-2021-26855
KEV CRITICAL

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 9.1 Microsoft exchange_server 2021-03-03
CVE-2021-27878
KEV HIGH

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a ...

CVSS 8.8 Veritas backup_exec 2021-03-01
CVE-2021-27877
KEV CRITICAL

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer...

CVSS 9.8 Veritas backup_exec 2021-03-01
CVE-2021-27876
KEV HIGH

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a ...

CVSS 8.1 Veritas backup_exec 2021-03-01
CVE-2021-1732
KEV HIGH

Windows Win32k Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1803 2021-02-25
CVE-2021-21973
KEV MEDIUM

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with networ...

CVSS 5.3 Vmware cloud_foundation 2021-02-24
CVE-2021-21972
KEV CRITICAL

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to ex...

CVSS 9.8 Vmware cloud_foundation 2021-02-24
CVE-2021-27104
KEV CRITICAL

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.

CVSS 9.8 Accellion fta 2021-02-16
CVE-2021-27103
KEV CRITICAL

Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

CVSS 9.8 Accellion fta 2021-02-16
CVE-2021-27102
KEV HIGH

Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

CVSS 7.8 Accellion fta 2021-02-16
CVE-2021-27101
KEV CRITICAL

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

CVSS 9.8 Accellion fta 2021-02-16
CVE-2021-21315
KEV HIGH

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In ...

CVSS 7.8 Apache cordova 2021-02-16
CVE-2021-25298
KEV HIGH

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due t...

CVSS 8.8 Nagios nagios_xi 2021-02-15
CVE-2021-25297
KEV HIGH

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to im...

CVSS 8.8 Nagios nagios_xi 2021-02-15
1… 48 49 50 51 52 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.