VulnSea

Tagged “kev”

CVEs tagged kev, newest first.

338 CVEsRSS

CVE-2012-1710Critical· 9.8CISA KEV
14y ago

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a …

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a …

▾ Hadaloracle · fusion_middlewareEPSS 7.8%via NVD
CVE-2010-2861Critical· 9.8CISA KEVPoC
16y ago

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2)…

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2)…

▾ Hadaladobe · coldfusionEPSS 100%via NVD
CVE-2010-1428High· 7.5CISA KEVPoC
16y ago

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allow…

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allow…

▾ Abyssalredhat · jboss_enterprise_application_platformEPSS 62%via NVD
CVE-2010-0738Medium· 5.3CISA KEVPoC
16y ago

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows …

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows …

▾ Midnightredhat · jboss_enterprise_application_platformEPSS 79%via NVD
CVE-2010-0188High· 7.8CISA KEVPoC
16y ago

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

▾ Abyssaladobe · acrobatEPSS 88%via NVD
CVE-2009-3960Medium· 6.5CISA KEVPoC
16y ago

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers…

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers…

▾ Midnightadobe · blazedsEPSS 90%via NVD
CVE-2025-31200High· 7.5CISA KEV0dayPoC

Memory corruption in CoreAudio via crafted media file

A maliciously crafted media file processed by Apple CoreAudio can trigger heap corruption leading to remote code execution. Reported as exploited in the wild against targeted individuals.

▾ AbyssalApple · CoreAudioiOS, iPadOS, macOSEPSS 19%via NVD
CVE-2021-44228Critical· 10.0CISA KEV0dayPoC

Log4Shell: JNDI RCE in Apache Log4j 2

Log4j 2 evaluates ${jndi:...} lookups in logged strings, allowing an attacker who controls any logged value to load and execute remote code via LDAP/RMI. Trivial to exploit, ubiquitous, and mass-exploited within hours of disclosure.

▾ HadalApache · Log4j 2JavaEPSS 100%via NVD
CVEs tagged “kev” — page 12 · VulnSea