CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,643 result(s) · page 173 of 183
CVE-2026-55235
MEDIUM

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is deli...

CVSS 5.9 2026-09-14
CVE-2026-54529
MEDIUM

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query par...

CVSS 5.3 2026-09-14
CVE-2026-53708
MEDIUM

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/g...

CVSS 6.6 2026-09-14
CVE-2026-4103
MEDIUM

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the i...

CVSS 6.4 2026-09-14
CVE-2026-47701
HIGH

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusC...

CVSS 7.7 2026-09-14
CVE-2025-24890
MEDIUM

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an ad...

CVSS 6.8 2026-09-14
CVE-2026-90791
MEDIUM

A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Th...

CVSS 6.3 2026-09-14
CVE-2026-90790
MEDIUM

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notific...

CVSS 6.3 2026-09-14
CVE-2026-90789
HIGH

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of...

CVSS 7.3 2026-09-14
CVE-2026-82438
HIGH

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer refl...

CVSS 8.1 2026-09-14
CVE-2026-82435
CRITICAL

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place....

CVSS 9.8 2026-09-14
CVE-2026-82434
MEDIUM

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it....

CVSS 6.5 2026-09-14
CVE-2026-82433
MEDIUM

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, th...

CVSS 6.5 2026-09-14
CVE-2026-82432
HIGH

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a s...

CVSS 8.1 2026-09-14
CVE-2026-82431
CRITICAL

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who res...

CVSS 9.8 2026-09-14
CVE-2026-82430
HIGH

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and onl...

CVSS 7.8 2026-09-14
CVE-2026-82429
HIGH

Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each ...

CVSS 7.8 2026-09-14
CVE-2026-82428
HIGH

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was t...

CVSS 8.8 2026-09-14
CVE-2026-82427
HIGH

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the ...

CVSS 7.8 2026-09-14
CVE-2026-82426
MEDIUM

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that i...

CVSS 6.5 2026-09-14
1 171 172 173 174 175 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.