CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,576 result(s) · page 3 of 179
CVE-2026-70009
CRITICAL

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

CVSS 9.3 2026-09-17
CVE-2026-69865
CRITICAL

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-17
CVE-2026-69399
CRITICAL

Azure Arc Elevation of Privilege Vulnerability

CVSS 10 2026-09-17
CVE-2026-68791
HIGH

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

CVSS 8.6 2026-09-17
CVE-2026-55946
MEDIUM

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 6.1 2026-09-17
CVE-2026-93426
HIGH

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with V...

CVSS 8.5 2026-09-17
CVE-2026-86688
HIGH

Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once ...

CVSS 7.4 2026-09-17
CVE-2026-76949
CRITICAL

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victi...

CVSS 9.1 2026-09-17
CVE-2026-54767
CRITICAL

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave paramet...

CVSS 9.1 2026-09-17
CVE-2026-54734
CRITICAL

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using Http...

CVSS 10 2026-09-17
CVE-2026-54671
HIGH

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web...

CVSS 8.8 2026-09-17
CVE-2026-54670
CRITICAL

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled ...

CVSS 9.1 2026-09-17
CVE-2026-54648
MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM...

CVSS 6.5 2026-09-17
CVE-2026-54647
HIGH

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter i...

CVSS 7.2 2026-09-17
CVE-2026-54646
HIGH

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, ...

CVSS 7.2 2026-09-17
CVE-2026-54644
MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and w...

CVSS 6.1 2026-09-17
CVE-2026-54643
MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note par...

CVSS 5.4 2026-09-17
CVE-2026-54642
MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php us...

CVSS 5.3 2026-09-17
CVE-2026-54634
HIGH

Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches rigctl_send_raw() ...

CVSS 7.3 2026-09-17
CVE-2026-54633
MEDIUM

PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfCol...

CVSS 6.9 2026-09-17
1 2 3 4 5 179
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.