CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,576 result(s) · page 7 of 179
CVE-2026-54594
MEDIUM

OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edit...

CVSS 5.3 2026-09-17
CVE-2026-50285
HIGH

Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an o...

CVSS 7.5 2026-09-17
CVE-2026-50125
HIGH

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_...

CVSS 7.5 2026-09-17
CVE-2026-45726
HIGH

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets res...

CVSS 7.6 2026-09-17
CVE-2026-45720
HIGH

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks S...

CVSS 7 2026-09-17
CVE-2026-92992
MEDIUM

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component ...

CVSS 6.3 2026-09-17
CVE-2026-90997
HIGH

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic ...

CVSS 7.4 2026-09-17
CVE-2026-55062
HIGH

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the...

CVSS 8.4 2026-09-17
CVE-2026-54617
CRITICAL

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading s...

CVSS 9.8 2026-09-17
CVE-2026-54571
HIGH

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp ...

CVSS 8.7 2026-09-17
CVE-2026-54524
HIGH

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Pa...

CVSS 7.1 2026-09-17
CVE-2026-54504
HIGH

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/ser...

CVSS 8.8 2026-09-17
CVE-2026-54451
HIGH

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be ta...

CVSS 8.2 2026-09-17
CVE-2026-54253
HIGH

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled po...

CVSS 8.2 2026-09-17
CVE-2026-54239
HIGH

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initializat...

CVSS 8.8 2026-09-17
CVE-2026-52852
MEDIUM

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarch...

CVSS 6.5 2026-09-17
CVE-2026-52851
HIGH

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/perm...

CVSS 7.1 2026-09-17
CVE-2026-52727
HIGH

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the sam...

CVSS 7.2 2026-09-17
CVE-2026-47252
CRITICAL

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-syst...

CVSS 9 2026-09-17
CVE-2026-19477
HIGH

There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code exec...

CVSS 7.8 2026-09-17
1 5 6 7 8 9 179
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.