CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 9 of 85
CVE-2025-68645
KEV HIGH

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parame...

CVSS 8.8 Synacor zimbra_collaboration_suite 2025-12-22
CVE-2025-68613
KEV HIGH

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnera...

CVSS 8.8 N8n n8n 2025-12-19
CVE-2025-14847
KEV HIGH

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 ...

CVSS 7.5 Mongodb mongodb 2025-12-19
CVE-2025-14733
KEV CRITICAL

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects bo...

CVSS 9.8 Watchguard fireware 2025-12-19
CVE-2025-40602
KEV MEDIUM

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

CVSS 6.6 Sonicwall sma6200_firmware 2025-12-18
CVE-2025-68461
KEV MEDIUM

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS 6.1 Roundcube webmail 2025-12-18
CVE-2025-43529
KEV HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, ...

CVSS 8.8 Apple safari 2025-12-17
CVE-2025-20393
KEV CRITICAL

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remot...

CVSS 10 Cisco asyncos 2025-12-17
CVE-2025-59374
KEV CRITICAL

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modif...

CVSS 9.8 Asus live_update 2025-12-17
CVE-2025-37164
KEV CRITICAL

A remote code execution issue exists in HPE OneView.

CVSS 9.8 Hpe oneview 2025-12-16
CVE-2025-43520
KEV MEDIUM

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS So...

CVSS 5.5 Apple ipados 2025-12-12
CVE-2025-43510
KEV HIGH

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macO...

CVSS 7.8 Apple ipados 2025-12-12
CVE-2025-14611
KEV CRITICAL

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public expose...

CVSS 9.8 Gladinet centrestack 2025-12-12
CVE-2025-14174
KEV HIGH

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chro...

CVSS 8.8 Google chrome 2025-12-12
CVE-2025-8110
KEV HIGH

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

CVSS 8.8 Gogs gogs 2025-12-10
CVE-2025-62221
KEV HIGH

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1809 2025-12-09
CVE-2025-59718
KEV CRITICAL

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 t...

CVSS 9.8 Fortinet fortiproxy 2025-12-09
CVE-2025-48633
KEV MEDIUM

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to lo...

CVSS 5.5 Google android 2025-12-08
CVE-2025-48572
KEV HIGH

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additi...

CVSS 7.8 Google android 2025-12-08
CVE-2025-34291
KEV HIGH

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_...

CVSS 8.8 Langflow langflow 2025-12-05
1 7 8 9 10 11 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.