CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,657 result(s) · page 178 of 183
CVE-2026-90516
HIGH

A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing...

CVSS 7.3 2026-09-13
CVE-2026-90515
HIGH

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Exec...

CVSS 7.3 2026-09-13
CVE-2026-90774
HIGH

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers ca...

CVSS 7.5 2026-09-13
CVE-2026-90772
HIGH

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers ...

CVSS 7.6 2026-09-13
CVE-2026-90770
HIGH

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without ...

CVSS 8.8 2026-09-13
CVE-2026-90769
HIGH

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. At...

CVSS 7.7 2026-09-13
CVE-2026-90768
HIGH

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers c...

CVSS 8.1 2026-09-13
CVE-2026-90767
MEDIUM

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files....

CVSS 6.5 2026-09-13
CVE-2026-90562
HIGH

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers k...

CVSS 8.1 2026-09-13
CVE-2026-90561
HIGH

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip sc...

CVSS 8.7 2026-09-13
CVE-2026-90514
HIGH

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation ...

CVSS 7.3 2026-09-13
CVE-2026-90513
MEDIUM

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml ...

CVSS 6.5 2026-09-13
CVE-2026-90511
MEDIUM

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servl...

CVSS 6.3 2026-09-13
CVE-2026-90510
HIGH

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-m...

CVSS 8.3 2026-09-13
CVE-2026-90509
HIGH

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executin...

CVSS 7.3 2026-09-13
CVE-2026-90507
MEDIUM

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subsc...

CVSS 6.3 2026-09-13
CVE-2026-90506
MEDIUM

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This m...

CVSS 5 2026-09-13
CVE-2026-90505
MEDIUM

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race ...

CVSS 5 2026-09-13
CVE-2026-90504
HIGH

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the a...

CVSS 7.3 2026-09-13
CVE-2026-90501
MEDIUM

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the a...

CVSS 6.3 2026-09-13
1 176 177 178 179 180 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.