CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,657 result(s) · page 176 of 183
CVE-2026-90593
HIGH

A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of ...

CVSS 7.3 2026-09-13
CVE-2026-90584
MEDIUM

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the co...

CVSS 5.3 2026-09-13
CVE-2026-88802
HIGH

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the recor...

CVSS 7.5 2026-09-13
CVE-2026-88793
HIGH

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page,...

CVSS 8.8 2026-09-13
CVE-2026-85129
HIGH

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before s...

CVSS 8.8 2026-09-13
CVE-2026-81648
CRITICAL

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administ...

CVSS 10 2026-09-13
CVE-2026-74933
HIGH

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, a...

CVSS 8.8 2026-09-13
CVE-2026-37008
HIGH

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of modu...

CVSS 8.1 2026-09-13
CVE-2026-36989
MEDIUM

A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.

CVSS 5.8 2026-09-13
CVE-2026-36453
HIGH

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.

CVSS 7.4 2026-09-13
CVE-2026-90582
MEDIUM

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipul...

CVSS 5.3 2026-09-13
CVE-2026-90581
MEDIUM

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulatio...

CVSS 6.3 2026-09-13
CVE-2026-90580
MEDIUM

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of t...

CVSS 6.3 Flowiseai flowise 2026-09-13
CVE-2026-29811
HIGH

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query fil...

CVSS 7.7 2026-09-13
CVE-2026-90579
HIGH

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. Th...

CVSS 7.3 2026-09-13
CVE-2026-90578
MEDIUM

A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can le...

CVSS 5.3 2026-09-13
CVE-2026-90577
MEDIUM

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4B...

CVSS 5.3 2026-09-13
CVE-2025-70819
MEDIUM

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose f...

CVSS 6.3 2026-09-13
CVE-2020-15875
MEDIUM

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in t...

CVSS 5 2026-09-13
CVE-2026-90574
MEDIUM

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation...

CVSS 6.3 2026-09-13
1 174 175 176 177 178 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.