CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 8 of 85
CVE-2026-1731
KEV CRITICAL

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending s...

CVSS 9.8 Beyondtrust privileged_remote_access 2026-02-06
CVE-2026-21643
KEV CRITICAL

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to exec...

CVSS 9.8 Fortinet forticlientems 2026-02-06
CVE-2025-15556
KEV HIGH

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cry...

CVSS 7.5 Notepad-plus-plus notepad\+\+ 2026-02-03
CVE-2026-1340
KEV CRITICAL

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

CVSS 9.8 Ivanti endpoint_manager_mobile 2026-01-29
CVE-2026-1281
KEV CRITICAL

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

CVSS 9.8 Ivanti endpoint_manager_mobile 2026-01-29
CVE-2025-40551
KEV CRITICAL

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to r...

CVSS 9.8 Solarwinds web_help_desk 2026-01-28
CVE-2025-40536
KEV CRITICAL

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain...

CVSS 9.8 Solarwinds web_help_desk 2026-01-28
CVE-2026-24858
KEV CRITICAL

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, ...

CVSS 9.8 Fortinet fortianalyzer 2026-01-27
CVE-2026-21509
KEV HIGH

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVSS 7.8 Microsoft 365_apps 2026-01-26
CVE-2026-24423
KEV CRITICAL

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the Sm...

CVSS 9.8 Smartertools smartermail 2026-01-23
CVE-2026-0770
KEV CRITICAL

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary ...

CVSS 9.8 Langflow langflow 2026-01-23
CVE-2026-23760
KEV CRITICAL

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous ...

CVSS 9.8 Smartertools smartermail 2026-01-22
CVE-2026-20045
KEV CRITICAL

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications...

CVSS 9.8 Cisco unified_communications_manager 2026-01-21
CVE-2026-24061
KEV CRITICAL

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

CVSS 9.8 Debian debian_linux 2026-01-21
CVE-2026-21962
KEV CRITICAL

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, ...

CVSS 10 Oracle http_server 2026-01-20
CVE-2026-20963
KEV CRITICAL

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 Microsoft sharepoint_server 2026-01-13
CVE-2026-20805
KEV MEDIUM

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CVSS 5.5 Microsoft windows_10_1607 2026-01-13
CVE-2025-25249
KEV CRITICAL

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS...

CVSS 9.8 Fortinet fortios 2026-01-13
CVE-2025-66376
KEV MEDIUM

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

CVSS 6.1 Synacor zimbra_collaboration_suite 2026-01-05
CVE-2025-52691
KEV CRITICAL

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code ...

CVSS 10 Smartertools smartermail 2025-12-29
1 6 7 8 9 10 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.