CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 55 of 85
CVE-2020-9377
KEV HIGH

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maint...

CVSS 8.8 Dlink dir-610_firmware 2020-07-09
CVE-2020-15505
KEV CRITICAL

A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sen...

CVSS 9.8 Mobileiron core 2020-07-07
CVE-2020-5902
KEV CRITICAL

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Co...

CVSS 9.8 F5 big-ip_access_policy_manager 2020-07-01
CVE-2020-15415
KEV CRITICAL

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename wh...

CVSS 9.8 Draytek vigor3900_firmware 2020-06-30
CVE-2020-15069
KEV CRITICAL

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was publishe...

CVSS 9.8 Sophos xg_firewall_firmware 2020-06-29
CVE-2020-2021
KEV CRITICAL

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of s...

CVSS 10 Paloaltonetworks pan-os 2020-06-29
CVE-2020-11899
KEV MEDIUM

The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

CVSS 5.4 Treck tcp\/ip 2020-06-17
CVE-2020-0986
KEV HIGH

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This C...

CVSS 7.8 Microsoft windows_10_1507 2020-06-09
CVE-2020-9818
KEV HIGH

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously craft...

CVSS 8.8 Apple ipados 2020-06-09
CVE-2020-13965
KEV MEDIUM

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a pre...

CVSS 6.1 Debian debian_linux 2020-06-09
CVE-2020-9859
KEV HIGH

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6...

CVSS 7.8 Apple ipados 2020-06-05
CVE-2020-5410
KEV HIGH

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through ...

CVSS 7.5 Vmware spring_cloud_config 2020-06-02
CVE-2020-8816
KEV HIGH

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

CVSS 7.2 Pi-hole pi-hole 2020-05-29
CVE-2020-1956
KEV HIGH

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute an...

CVSS 8.8 Apache kylin 2020-05-22
CVE-2020-1054
KEV HIGH

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited thi...

CVSS 7 Microsoft windows_10_1507 2020-05-21
CVE-2020-5741
KEV HIGH

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

CVSS 7.2 Plex media_server 2020-05-08
CVE-2020-4428
KEV CRITICAL

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.

CVSS 9.1 Ibm data_risk_manager 2020-05-07
CVE-2020-4427
KEV CRITICAL

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sendin...

CVSS 9.8 Ibm data_risk_manager 2020-05-07
CVE-2020-3259
KEV HIGH

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, ...

CVSS 7.5 Cisco secure_firewall_threat_defense 2020-05-06
CVE-2020-12641
KEV CRITICAL

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_...

CVSS 9.8 Roundcube webmail 2020-05-04
1… 53 54 55 56 57 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.