CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,576 result(s) · page 9 of 179
CVE-2026-54583
HIGH

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing pa...

CVSS 8.3 2026-09-17
CVE-2026-54582
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected...

CVSS 6 2026-09-17
CVE-2026-54581
HIGH

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification...

CVSS 8.3 2026-09-17
CVE-2026-54580
HIGH

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmpor...

CVSS 8.3 2026-09-17
CVE-2026-54576
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations...

CVSS 5.8 2026-09-17
CVE-2026-54575
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/cle...

CVSS 5.8 2026-09-17
CVE-2026-28326
HIGH

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

CVSS 8.8 2026-09-17
CVE-2026-93015
MEDIUM

BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVE...

CVSS 6.3 2026-09-17
CVE-2026-93014
HIGH

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path tr...

CVSS 7.1 2026-09-17
CVE-2026-91039
CRITICAL

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be...

CVSS 9.1 2026-09-17
CVE-2026-89036
HIGH

Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by ...

CVSS 8.8 2026-09-17
CVE-2026-86864
HIGH

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argumen...

CVSS 8.8 2026-09-17
CVE-2026-86863
CRITICAL

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI enviro...

CVSS 9.8 2026-09-17
CVE-2026-86862
MEDIUM

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a dat...

CVSS 6.5 2026-09-17
CVE-2026-86861
MEDIUM

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened...

CVSS 5.9 2026-09-17
CVE-2026-86040
HIGH

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.a...

CVSS 7.5 2026-09-17
CVE-2026-86039
HIGH

libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to ver...

CVSS 8.2 2026-09-17
CVE-2026-86038
HIGH

libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils...

CVSS 7.5 2026-09-17
CVE-2026-86000
MEDIUM

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent qu...

CVSS 5.3 2026-09-17
CVE-2026-85999
MEDIUM

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an...

CVSS 5.3 2026-09-17
1 7 8 9 10 11 179
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.