CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,576 result(s) · page 2 of 179
CVE-2026-93452
HIGH

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can s...

CVSS 7.5 2026-09-18
CVE-2026-93451
MEDIUM

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by elemen...

CVSS 6.5 2026-09-18
CVE-2026-93450
HIGH

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote una...

CVSS 7.5 2026-09-18
CVE-2026-85887
HIGH

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

CVSS 7.7 2026-09-18
CVE-2026-85878
CRITICAL

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

CVSS 9.9 2026-09-18
CVE-2026-83946
HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

CVSS 8.2 2026-09-18
CVE-2026-69843
CRITICAL

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-18
CVE-2026-62874
CRITICAL

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-18
CVE-2026-2585
MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to in...

CVSS 6.4 2026-09-18
CVE-2026-93436
HIGH

vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit request...

CVSS 7.5 2026-09-17
CVE-2026-93435
HIGH

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounde...

CVSS 7.5 2026-09-17
CVE-2026-87886
KEV HIGH

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Ba...

CVSS 7.8 2026-09-17
CVE-2026-87701
CRITICAL

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a net...

CVSS 9.6 2026-09-17
CVE-2026-85917
HIGH

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

CVSS 7.5 2026-09-17
CVE-2026-85889
CRITICAL

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-17
CVE-2026-85885
CRITICAL

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

CVSS 9.9 2026-09-17
CVE-2026-83944
CRITICAL

Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-17
CVE-2026-78501
HIGH

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information...

CVSS 7.4 2026-09-17
CVE-2026-77903
CRITICAL

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

CVSS 9 2026-09-17
CVE-2026-70200
CRITICAL

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-17
1 2 3 4 179
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.