CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,576 result(s) · page 4 of 179
CVE-2026-54613
MEDIUM

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php ...

CVSS 5.4 2026-09-17
CVE-2026-54612
HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/gl...

CVSS 8.8 2026-09-17
CVE-2026-54608
HIGH

MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_...

CVSS 7.1 2026-09-17
CVE-2026-54520
HIGH

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backen...

CVSS 8.1 2026-09-17
CVE-2026-54519
HIGH

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authe...

CVSS 8.8 2026-09-17
CVE-2026-54507
HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/edito...

CVSS 8.4 2026-09-17
CVE-2026-54506
HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] fiel...

CVSS 7.6 2026-09-17
CVE-2026-54343
HIGH

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handl...

CVSS 8.7 2026-09-17
CVE-2026-53557
HIGH

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel...

CVSS 7.7 2026-09-17
CVE-2026-53556
MEDIUM

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud...

CVSS 6 2026-09-17
CVE-2026-53555
MEDIUM

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through ...

CVSS 5.1 2026-09-17
CVE-2026-53554
HIGH

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/d...

CVSS 7.3 2026-09-17
CVE-2026-53534
HIGH

JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/ca...

CVSS 7.5 2026-09-17
CVE-2026-50291
MEDIUM

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processin...

CVSS 5.5 2026-09-17
CVE-2026-50158
HIGH

yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/capti...

CVSS 7.7 2026-09-17
CVE-2026-16750
MEDIUM

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_lo...

CVSS 5.3 2026-09-17
CVE-2026-16582
MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This ...

CVSS 5.3 2026-09-17
CVE-2026-14311
MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification...

CVSS 5.4 2026-09-17
CVE-2026-93395
MEDIUM

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function rea...

CVSS 5.3 2026-09-17
CVE-2026-93393
HIGH

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects ...

CVSS 8.1 2026-09-17
1 2 3 4 5 6 179
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.