CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,576 result(s) · page 5 of 179
CVE-2026-86049
HIGH

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON hea...

CVSS 7.1 2026-09-17
CVE-2026-77615
HIGH

Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS att...

CVSS 8.7 2026-09-17
CVE-2026-77281
MEDIUM

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. I...

CVSS 6.5 2026-09-17
CVE-2026-76154
HIGH

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session b...

CVSS 7.3 2026-09-17
CVE-2026-68537
HIGH

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolv...

CVSS 7.5 2026-09-17
CVE-2026-68523
HIGH

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolv...

CVSS 7.5 2026-09-17
CVE-2026-67071
MEDIUM

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure prope...

CVSS 6.5 2026-09-17
CVE-2026-54918
MEDIUM

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests...

CVSS 5.3 2026-09-17
CVE-2026-54916
HIGH

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib...

CVSS 8.8 2026-09-17
CVE-2026-54907
MEDIUM

Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration ...

CVSS 5.3 2026-09-17
CVE-2026-54604
MEDIUM

OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c a...

CVSS 5.3 2026-09-17
CVE-2026-54597
HIGH

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write pe...

CVSS 8.3 2026-09-17
CVE-2026-54596
HIGH

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access ...

CVSS 8.1 2026-09-17
CVE-2026-54521
MEDIUM

FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/Act...

CVSS 6.1 2026-09-17
CVE-2026-54510
HIGH

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app...

CVSS 7.1 2026-09-17
CVE-2026-54501
CRITICAL

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Br...

CVSS 9.4 2026-09-17
CVE-2026-54460
CRITICAL

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId an...

CVSS 9.8 2026-09-17
CVE-2026-54355
MEDIUM

MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlaye...

CVSS 5.3 2026-09-17
CVE-2026-54354
HIGH

MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFil...

CVSS 8.2 2026-09-17
CVE-2026-54339
HIGH

Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), ...

CVSS 7.7 2026-09-17
1 3 4 5 6 7 179
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.