CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,655 result(s) · page 169 of 183
CVE-2026-19543
MEDIUM

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce th...

CVSS 6.2 2026-09-14
CVE-2026-15893
MEDIUM

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachab...

CVSS 6.5 2026-09-14
CVE-2026-91081
MEDIUM

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public d...

CVSS 5.8 2026-09-14
CVE-2026-91080
HIGH

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. A...

CVSS 7.5 2026-09-14
CVE-2026-91079
HIGH

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace member...

CVSS 8.5 2026-09-14
CVE-2026-91021
MEDIUM

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of use...

CVSS 5.4 2026-09-14
CVE-2026-90946
HIGH

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path wit...

CVSS 7.5 2026-09-14
CVE-2026-90945
CRITICAL

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can...

CVSS 9.8 2026-09-14
CVE-2026-90944
HIGH

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbo...

CVSS 8.2 2026-09-14
CVE-2026-90942
CRITICAL

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators ...

CVSS 9.6 2026-09-14
CVE-2026-90807
MEDIUM

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the compo...

CVSS 6.3 2026-09-14
CVE-2026-90806
MEDIUM

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the compone...

CVSS 6.3 2026-09-14
CVE-2026-90805
HIGH

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Exec...

CVSS 7.3 2026-09-14
CVE-2026-86836
HIGH

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and...

CVSS 8.4 2026-09-14
CVE-2026-85921
HIGH

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVSS 8.2 2026-09-14
CVE-2026-85892
HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges l...

CVSS 7.8 2026-09-14
CVE-2026-73494
HIGH

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in ...

CVSS 7.4 2026-09-14
CVE-2026-70658
HIGH

Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_c...

CVSS 7.4 2026-09-14
CVE-2026-57581
MEDIUM

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthentic...

CVSS 5.3 2026-09-14
CVE-2026-57578
CRITICAL

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explic...

CVSS 9.2 2026-09-14
1 167 168 169 170 171 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.