CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,690 result(s) · page 3 of 85
CVE-2026-60137
KEV MEDIUM

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a...

CVSS 5.9 Wordpress wordpress 2026-07-17
CVE-2026-9198
KEV CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (execut...

CVSS 9.8 Langflow langflow 2026-07-17
CVE-2026-9586
KEV CRITICAL

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and dire...

CVSS 9.8 Sangoma switchvox 2026-07-17
CVE-2021-27137
KEV HIGH

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a re...

CVSS 8.1 Dd-wrt dd-wrt 2026-07-16
CVE-2026-15410
KEV HIGH

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific ...

CVSS 7.2 Sonicwall sma6210_firmware 2026-07-14
CVE-2026-15409
KEV CRITICAL

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the ...

CVSS 10 Sonicwall sma6210_firmware 2026-07-14
CVE-2026-55040
KEV CRITICAL

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

CVSS 9.1 Microsoft sharepoint_server 2026-07-14
CVE-2026-58644
KEV CRITICAL

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 Microsoft sharepoint_server 2026-07-14
CVE-2026-56164
KEV CRITICAL

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS 9.8 Microsoft sharepoint_server 2026-07-14
CVE-2026-56155
KEV HIGH

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 Microsoft windows_10_1607 2026-07-14
CVE-2026-50522
KEV CRITICAL

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 Microsoft sharepoint_server 2026-07-14
CVE-2026-56291
KEV CRITICAL

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary f...

CVSS 9.8 Balbooa forms 2026-07-09
CVE-2026-59822
KEV HIGH

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to...

CVSS 8.2 Litellm litellm 2026-07-08
CVE-2026-53362
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branc...

CVSS 7.8 Linux linux_kernel 2026-07-04
CVE-2026-48282
KEV CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a...

CVSS 10 Adobe coldfusion 2026-06-30
CVE-2026-8452
KEV CRITICAL

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (...

CVSS 9.8 Citrix netscaler_application_delivery_controller 2026-06-30
CVE-2026-56290
KEV CRITICAL

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitra...

CVSS 9.8 Joomlack page_builder_ck 2026-06-29
CVE-2026-49869
KEV CRITICAL

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whiteli...

CVSS 10 Kestra kestra 2026-06-26
CVE-2026-53266
KEV HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source addre...

CVSS 8.8 Linux linux_kernel 2026-06-25
CVE-2026-55255
KEV HIGH

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoin...

CVSS 8.4 Langflow langflow 2026-06-23
1 2 3 4 5 85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.