CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 1 of 500
CVE-2026-17086
HIGH

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via des...

CVSS 8.8 2026-09-18
CVE-2026-93468
HIGH

The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.

CVSS 7.5 2026-09-18
CVE-2026-93371
HIGH

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/gen...

CVSS 8.3 2026-09-18
CVE-2026-93456
HIGH

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed...

CVSS 8.2 2026-09-18
CVE-2026-93331
HIGH

A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketize...

CVSS 7.3 2026-09-18
CVE-2026-79954
HIGH

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing...

CVSS 8.7 2026-09-18
CVE-2026-93453
HIGH

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to atta...

CVSS 8.3 2026-09-18
CVE-2026-93452
HIGH

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can s...

CVSS 7.5 2026-09-18
CVE-2026-93450
HIGH

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote una...

CVSS 7.5 2026-09-18
CVE-2026-85887
HIGH

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

CVSS 7.7 2026-09-18
CVE-2026-83946
HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

CVSS 8.2 2026-09-18
CVE-2026-93436
HIGH

vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit request...

CVSS 7.5 2026-09-17
CVE-2026-93435
HIGH

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounde...

CVSS 7.5 2026-09-17
CVE-2026-87886
KEV HIGH

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Ba...

CVSS 7.8 2026-09-17
CVE-2026-85917
HIGH

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

CVSS 7.5 2026-09-17
CVE-2026-78501
HIGH

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information...

CVSS 7.4 2026-09-17
CVE-2026-68791
HIGH

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

CVSS 8.6 2026-09-17
CVE-2026-93426
HIGH

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with V...

CVSS 8.5 2026-09-17
CVE-2026-86688
HIGH

Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once ...

CVSS 7.4 2026-09-17
CVE-2026-54671
HIGH

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web...

CVSS 8.8 2026-09-17
1 2 3 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.