CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 52 of 85
CVE-2020-29583
KEV CRITICAL

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the fi...

CVSS 9.8 Zyxel usg20-vpn_firmware 2020-12-22
CVE-2020-29574
KEV CRITICAL

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

CVSS 9.8 Sophos cyberoamos 2020-12-11
CVE-2020-17530
KEV CRITICAL

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

CVSS 9.8 Apache struts 2020-12-11
CVE-2020-17144
KEV HIGH

Microsoft Exchange Remote Code Execution Vulnerability

CVSS 8.4 Microsoft exchange_server 2020-12-10
CVE-2020-27950
KEV MEDIUM

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Upd...

CVSS 5.5 Apple ipados 2020-12-08
CVE-2020-27932
KEV HIGH

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 Hig...

CVSS 7.8 Apple icloud 2020-12-08
CVE-2020-27930
KEV HIGH

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-00...

CVSS 7.8 Apple ipados 2020-12-08
CVE-2020-4006
KEV CRITICAL

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

CVSS 9.1 Vmware identity_manager 2020-11-23
CVE-2020-13671
KEV HIGH

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type o...

CVSS 8.8 Drupal drupal 2020-11-20
CVE-2020-28949
KEV HIGH

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succe...

CVSS 7.8 Php archive_tar 2020-11-19
CVE-2020-17087
KEV HIGH

Windows Kernel Local Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2020-11-11
CVE-2020-13927
KEV CRITICAL

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Ai...

CVSS 9.8 Apache airflow 2020-11-10
CVE-2020-16846
KEV CRITICAL

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

CVSS 9.8 Debian debian_linux 2020-11-06
CVE-2020-16010
KEV CRITICAL

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es...

CVSS 9.6 Google chrome 2020-11-03
CVE-2020-16009
KEV HIGH

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2020-11-03
CVE-2020-15999
KEV CRITICAL

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 9.6 Google chrome 2020-11-03
CVE-2020-14750
KEV CRITICAL

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 1...

CVSS 9.8 Oracle weblogic_server 2020-11-02
CVE-2018-19953
KEV MEDIUM

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4...

CVSS 6.1 Qnap qts 2020-10-28
CVE-2018-19949
KEV CRITICAL

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2...

CVSS 9.8 Qnap qts 2020-10-28
CVE-2018-19943
KEV MEDIUM

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS ...

CVSS 5.4 Qnap qts 2020-10-28
1… 50 51 52 53 54 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.