CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 54 of 85
CVE-2020-9715
KEV HIGH

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Succe...

CVSS 7.8 Adobe acrobat_dc 2020-08-19
CVE-2020-1472
KEV MEDIUM

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc...

CVSS 5.5 Fedoraproject fedora 2020-08-17
CVE-2020-1464
KEV HIGH

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and loa...

CVSS 7.8 Microsoft windows_10_1507 2020-08-17
CVE-2020-1380
KEV HIGH

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a w...

CVSS 7.8 Microsoft internet_explorer 2020-08-17
CVE-2020-3433
KEV HIGH

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL...

CVSS 7.8 Cisco anyconnect_secure_mobility_client 2020-08-17
CVE-2019-5591
KEV MEDIUM

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

CVSS 6.5 Fortinet fortios 2020-08-14
CVE-2020-17463
KEV CRITICAL

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

CVSS 9.8 Thedaylightstudio fuel_cms 2020-08-13
CVE-2020-17496
KEV CRITICAL

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists becaus...

CVSS 9.8 Vbulletin vbulletin 2020-08-12
CVE-2020-8218
KEV HIGH

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CVSS 7.2 Ivanti connect_secure 2020-07-30
CVE-2020-12812
KEV CRITICAL

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted ...

CVSS 9.8 Fortinet fortios 2020-07-24
CVE-2020-3452
KEV HIGH

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, ...

CVSS 7.5 Cisco adaptive_security_appliance_software 2020-07-22
CVE-2020-11978
KEV HIGH

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which ...

CVSS 8.8 Apache airflow 2020-07-17
CVE-2020-14644
KEV CRITICAL

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. E...

CVSS 9.8 Oracle weblogic_server 2020-07-15
CVE-2020-1350
KEV CRITICAL

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnera...

CVSS 10 Microsoft windows_server_2008 2020-07-14
CVE-2020-1147
KEV HIGH

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '....

CVSS 7.8 Microsoft .net_core 2020-07-14
CVE-2020-1040
KEV CRITICAL

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, ak...

CVSS 9 Microsoft windows_server_2008 2020-07-14
CVE-2020-6287
KEV CRITICAL

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication t...

CVSS 10 Sap netweaver_application_server_java 2020-07-14
CVE-2020-10987
KEV CRITICAL

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

CVSS 9.8 Tenda ac15_firmware 2020-07-13
CVE-2020-8195
KEV MEDIUM

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11....

CVSS 6.5 Citrix application_delivery_controller_firmware 2020-07-10
CVE-2020-8193
KEV MEDIUM

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1....

CVSS 6.5 Citrix application_delivery_controller_firmware 2020-07-10
1… 52 53 54 55 56 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.