CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 51 of 85
CVE-2021-25296
KEV HIGH

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php d...

CVSS 8.8 Nagios nagios_xi 2021-02-15
CVE-2021-21311
KEV HIGH

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Ad...

CVSS 7.2 Debian debian_linux 2021-02-11
CVE-2021-21017
KEV HIGH

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnera...

CVSS 8.8 Adobe acrobat 2021-02-11
CVE-2021-23874
KEV HIGH

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP...

CVSS 7.8 Mcafee total_protection 2021-02-10
CVE-2021-21148
KEV HIGH

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2021-02-09
CVE-2021-22502
KEV CRITICAL

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execu...

CVSS 9.8 Microfocus operation_bridge_reporter 2021-02-08
CVE-2021-20016
KEV CRITICAL

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session rel...

CVSS 9.8 Sonicwall sma_100_firmware 2021-02-04
CVE-2020-2506
KEV CRITICAL

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of...

CVSS 9.8 Qnap helpdesk 2021-02-03
CVE-2020-25506
KEV CRITICAL

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.

CVSS 9.8 Dlink dns-320_firmware 2021-02-02
CVE-2020-29557
KEV CRITICAL

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote c...

CVSS 9.8 Dlink dir-825_r1_firmware 2021-01-29
CVE-2021-3156
KEV HIGH

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg...

CVSS 7.8 Fedoraproject fedora 2021-01-26
CVE-2020-36193
KEV HIGH

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS 7.5 Php archive_tar 2021-01-18
CVE-2020-6572
KEV HIGH

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVSS 8.8 Google chrome 2021-01-14
CVE-2021-1647
KEV HIGH

Microsoft Defender Remote Code Execution Vulnerability

CVSS 7.8 Microsoft windows_defender 2021-01-12
CVE-2021-3129
KEV CRITICAL

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and...

CVSS 9.8 Facade ignition 2021-01-12
CVE-2020-16017
KEV CRITICAL

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape ...

CVSS 9.6 Google chrome 2021-01-08
CVE-2020-16013
KEV HIGH

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2021-01-08
CVE-2020-17519
KEV HIGH

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST ...

CVSS 7.5 Apache flink 2021-01-05
CVE-2020-10148
KEV CRITICAL

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to b...

CVSS 9.8 Solarwinds orion_platform 2020-12-29
CVE-2020-35730
KEV MEDIUM

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in ...

CVSS 6.1 Fedoraproject fedora 2020-12-28
1… 49 50 51 52 53 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.