CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,655 result(s) · page 168 of 183
CVE-2026-16187
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

CVSS 6.5 2026-09-14
CVE-2026-16186
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

CVSS 5.4 2026-09-14
CVE-2026-16185
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

CVSS 6.4 2026-09-14
CVE-2026-16147
MEDIUM

The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transf...

CVSS 6.8 2026-09-14
CVE-2026-15955
HIGH

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

CVSS 7.5 2026-09-14
CVE-2026-15924
MEDIUM

Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket co...

CVSS 5.9 2026-09-14
CVE-2026-15887
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

CVSS 5.4 2026-09-14
CVE-2026-15634
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transf...

CVSS 6.5 2026-09-14
CVE-2026-15412
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attac...

CVSS 6.5 2026-09-14
CVE-2026-15396
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transf...

CVSS 6.5 2026-09-14
CVE-2026-90810
MEDIUM

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-age...

CVSS 6.3 2026-09-14
CVE-2026-90809
HIGH

A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py o...

CVSS 7.3 2026-09-14
CVE-2026-90808
MEDIUM

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the compon...

CVSS 6.3 2026-09-14
CVE-2026-89023
HIGH

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to acc...

CVSS 8.6 2026-09-14
CVE-2026-89021
MEDIUM

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container...

CVSS 6.9 2026-09-14
CVE-2026-86830
HIGH

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user wit...

CVSS 7.2 2026-09-14
CVE-2026-82049
HIGH

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may ca...

CVSS 8.4 2026-09-14
CVE-2026-82035
HIGH

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is co...

CVSS 7.1 2026-09-14
CVE-2026-77884
HIGH

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and direct...

CVSS 7.1 2026-09-14
CVE-2026-59178
CRITICAL

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME...

CVSS 9.8 2026-09-14
1 166 167 168 169 170 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.