CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 6 of 85
CVE-2026-0300
KEV CRITICAL

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execu...

CVSS 9.8 Paloaltonetworks pan-os 2026-05-06
CVE-2026-41940
KEV CRITICAL

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the...

CVSS 9.8 Cpanel wp_squared 2026-04-29
CVE-2026-31431
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c...

CVSS 7.8 Linux linux_kernel 2026-04-22
CVE-2026-33825
KEV HIGH

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft defender_antimalware_platform 2026-04-14
CVE-2026-33824
KEV CRITICAL

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVSS 9.8 Microsoft windows_10_1607 2026-04-14
CVE-2026-32201
KEV MEDIUM

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVSS 6.5 Microsoft sharepoint_server 2026-04-14
CVE-2026-39808
KEV CRITICAL

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execut...

CVSS 9.8 Fortinet fortisandbox 2026-04-14
CVE-2026-34621
KEV HIGH

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerab...

CVSS 8.6 Adobe acrobat_dc 2026-04-11
CVE-2026-34486
KEV HIGH

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomc...

CVSS 7.5 Apache tomcat 2026-04-09
CVE-2026-39987
KEV CRITICAL

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowi...

CVSS 9.8 Coreweave marimo 2026-04-09
CVE-2026-34197
KEV HIGH

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the ...

CVSS 8.8 Apache activemq 2026-04-07
CVE-2026-35616
KEV CRITICAL

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted re...

CVSS 9.8 Fortinet forticlientems 2026-04-04
CVE-2026-5281
KEV HIGH

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page...

CVSS 8.8 Google chrome 2026-04-01
CVE-2026-3502
KEV HIGH

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tam...

CVSS 7.8 Trueconf trueconf 2026-03-30
CVE-2026-33634
KEV HIGH

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquas...

CVSS 8.8 Aquasec trivy 2026-03-23
CVE-2026-3055
KEV CRITICAL

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

CVSS 9.8 Citrix netscaler_application_delivery_controller 2026-03-23
CVE-2026-33017
KEV CRITICAL

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building...

CVSS 9.8 Langflow langflow 2026-03-20
CVE-2026-3910
KEV HIGH

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium s...

CVSS 8.8 Google chrome 2026-03-13
CVE-2026-3909
KEV HIGH

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security sev...

CVSS 8.8 Google chrome 2026-03-13
CVE-2025-67038
KEV CRITICAL

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concat...

CVSS 9.8 Lantronix eds5008_firmware 2026-03-11
1 4 5 6 7 8 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.