CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,576 result(s) · page 6 of 179
CVE-2026-54237
CRITICAL

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation ...

CVSS 9.3 2026-09-17
CVE-2026-50277
HIGH

dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD...

CVSS 7.5 2026-09-17
CVE-2026-50275
HIGH

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers....

CVSS 7.5 2026-09-17
CVE-2026-50022
MEDIUM

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter th...

CVSS 5.8 2026-09-17
CVE-2026-48977
HIGH

OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositiv...

CVSS 7.7 2026-09-17
CVE-2026-45143
CRITICAL

Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders...

CVSS 9 2026-09-17
CVE-2026-45140
CRITICAL

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authori...

CVSS 9.8 2026-09-17
CVE-2026-15815
HIGH

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escap...

CVSS 8.8 2026-09-17
CVE-2026-93337
HIGH

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supp...

CVSS 7.8 2026-09-17
CVE-2026-92993
MEDIUM

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of t...

CVSS 6.3 2026-09-17
CVE-2026-92943
HIGH

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might all...

CVSS 8.1 2026-09-17
CVE-2026-92758
MEDIUM

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure ac...

CVSS 5.5 2026-09-17
CVE-2026-92757
MEDIUM

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

CVSS 5.5 2026-09-17
CVE-2026-92756
MEDIUM

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-...

CVSS 5.5 2026-09-17
CVE-2026-54752
CRITICAL

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled ...

CVSS 9.6 2026-09-17
CVE-2026-54716
HIGH

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an excl...

CVSS 7.5 2026-09-17
CVE-2026-54692
HIGH

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-co...

CVSS 7.8 2026-09-17
CVE-2026-54627
CRITICAL

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src...

CVSS 9.8 2026-09-17
CVE-2026-54626
CRITICAL

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by i...

CVSS 9.8 2026-09-17
CVE-2026-54618
CRITICAL

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /o...

CVSS 9.4 2026-09-17
1 4 5 6 7 8 179
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.