CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,657 result(s) · page 180 of 183
CVE-2026-90647
HIGH

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode)...

CVSS 7.4 2026-09-12
CVE-2026-90486
MEDIUM

A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file app...

CVSS 6.3 2026-09-12
CVE-2026-90485
MEDIUM

A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. Thi...

CVSS 5.5 2026-09-12
CVE-2026-90616
HIGH

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host,...

CVSS 7.4 2026-09-12
CVE-2026-90560
HIGH

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated a...

CVSS 8.2 2026-09-12
CVE-2026-90559
HIGH

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated again...

CVSS 7.5 2026-09-12
CVE-2026-90558
CRITICAL

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft ma...

CVSS 9.8 2026-09-12
CVE-2026-90557
MEDIUM

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An atta...

CVSS 6.1 2026-09-12
CVE-2026-90556
HIGH

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 ...

CVSS 7.8 2026-09-12
CVE-2026-90555
MEDIUM

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit...

CVSS 6.5 Vllm vllm 2026-09-12
CVE-2026-90554
MEDIUM

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _e...

CVSS 6.2 2026-09-12
CVE-2026-90553
HIGH

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor...

CVSS 7.8 Vllm vllm 2026-09-12
CVE-2026-90551
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to ...

CVSS 5.3 2026-09-12
CVE-2026-90550
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metad...

CVSS 5.3 2026-09-12
CVE-2026-90549
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to li...

CVSS 5.3 2026-09-12
CVE-2026-90548
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access t...

CVSS 5.3 2026-09-12
CVE-2026-90547
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticat...

CVSS 5.3 2026-09-12
CVE-2026-90543
MEDIUM

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessa...

CVSS 5.3 2026-09-12
CVE-2026-90542
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php...

CVSS 5.4 2026-09-12
CVE-2026-90541
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attacker...

CVSS 5.3 2026-09-12
1 178 179 180 181 182 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.