CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,657 result(s) · page 179 of 183
CVE-2026-90500
MEDIUM

A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This ...

CVSS 6.3 2026-09-13
CVE-2026-90499
MEDIUM

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. ...

CVSS 5.4 2026-09-13
CVE-2026-90498
HIGH

A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credent...

CVSS 7.3 2026-09-13
CVE-2026-89080
HIGH

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an ...

CVSS 7.5 2026-09-13
CVE-2026-88995
MEDIUM

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated ...

CVSS 5.3 2026-09-13
CVE-2026-88764
MEDIUM

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid ...

CVSS 5.4 2026-09-13
CVE-2026-86406
HIGH

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method o...

CVSS 7.5 2026-09-13
CVE-2026-80071
HIGH

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own acco...

CVSS 7.2 2026-09-13
CVE-2026-77773
MEDIUM

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, al...

CVSS 5.3 2026-09-13
CVE-2026-90678
HIGH

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and confi...

CVSS 7.5 2026-09-13
CVE-2026-90495
HIGH

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class...

CVSS 7.3 2026-09-13
CVE-2026-90494
MEDIUM

A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. Th...

CVSS 5.3 2026-09-13
CVE-2026-90493
HIGH

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component ...

CVSS 8.8 2026-09-13
CVE-2026-90668
HIGH

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory c...

CVSS 7.5 2026-09-13
CVE-2026-90492
MEDIUM

A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. T...

CVSS 6.3 2026-09-13
CVE-2026-90491
MEDIUM

A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a m...

CVSS 6.3 2026-09-13
CVE-2026-90490
MEDIUM

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deseri...

CVSS 6.3 2026-09-13
CVE-2026-90651
HIGH

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_ve...

CVSS 8.1 2026-09-13
CVE-2026-90648
HIGH

wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return ...

CVSS 7.1 2026-09-13
CVE-2026-90488
MEDIUM

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/G...

CVSS 6.3 2026-09-13
1 177 178 179 180 181 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.