CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 7 of 85
CVE-2026-20131
KEV CRITICAL

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary...

CVSS 10 Cisco secure_firewall_management_center 2026-03-04
CVE-2026-20079
KEV CRITICAL

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute ...

CVSS 10 Cisco secure_firewall_management_center 2026-03-04
CVE-2026-21385
KEV HIGH

Memory corruption while using alignments for memory allocation.

CVSS 7.8 Qualcomm sm7675p_firmware 2026-03-02
CVE-2026-22719
KEV HIGH

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote c...

CVSS 8.1 Vmware aria_operations 2026-02-25
CVE-2026-20133
KEV HIGH

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due ...

CVSS 7.5 Cisco catalyst_sd-wan_manager 2026-02-25
CVE-2026-20128
KEV HIGH

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affect...

CVSS 7.5 Cisco catalyst_sd-wan_manager 2026-02-25
CVE-2026-20127
KEV CRITICAL

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalys...

CVSS 10 Cisco catalyst_sd-wan_manager 2026-02-25
CVE-2026-20122
KEV MEDIUM

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vul...

CVSS 5.4 Cisco catalyst_sd-wan_manager 2026-02-25
CVE-2026-22769
KEV CRITICAL

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attack...

CVSS 10 Dell recoverpoint_for_virtual_machines 2026-02-17
CVE-2026-2441
KEV HIGH

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security sever...

CVSS 8.8 Google chrome 2026-02-13
CVE-2026-25108
KEV HIGH

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arb...

CVSS 8.8 Soliton filezen 2026-02-13
CVE-2026-20700
KEV HIGH

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. A...

CVSS 7.8 Apple ipados 2026-02-11
CVE-2026-21533
KEV HIGH

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1607 2026-02-10
CVE-2026-21525
KEV MEDIUM

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

CVSS 6.2 Microsoft windows_10_1607 2026-02-10
CVE-2026-21519
KEV HIGH

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1607 2026-02-10
CVE-2026-21514
KEV HIGH

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

CVSS 7.8 Microsoft 365_apps 2026-02-10
CVE-2026-21513
KEV HIGH

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

CVSS 8.8 Microsoft windows_10_1607 2026-02-10
CVE-2026-21510
KEV HIGH

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

CVSS 8.8 Microsoft windows_10_1607 2026-02-10
CVE-2026-1603
KEV HIGH

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

CVSS 7.5 Ivanti endpoint_manager 2026-02-10
CVE-2025-68686
KEV MEDIUM

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7....

CVSS 5.9 Fortinet fortios 2026-02-10
1 5 6 7 8 9 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.