CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 10 of 500
CVE-2026-24081
HIGH

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

CVSS 7.4 2026-09-17
CVE-2026-24075
HIGH

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

CVSS 7.8 2026-09-17
CVE-2026-24074
HIGH

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

CVSS 7.8 2026-09-17
CVE-2026-24073
HIGH

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

CVSS 7.8 2026-09-17
CVE-2025-59607
HIGH

Memory Corruption when copying large input data exceeds normal allocation limits.

CVSS 7.8 2026-09-17
CVE-2026-92838
HIGH

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search pat...

CVSS 7.8 2026-09-17
CVE-2026-81546
HIGH

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffe...

CVSS 7.7 2026-09-17
CVE-2026-65388
HIGH

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credential...

CVSS 7.5 2026-09-16
CVE-2026-61599
HIGH

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveVie...

CVSS 8.8 2026-09-16
CVE-2026-61596
HIGH

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object...

CVSS 7.1 2026-09-16
CVE-2026-92599
HIGH

joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation r...

CVSS 7.5 2026-09-16
CVE-2026-92596
HIGH

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a cra...

CVSS 7.5 2026-09-16
CVE-2026-92594
HIGH

Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by G...

CVSS 7.5 2026-09-16
CVE-2026-92593
HIGH

Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandb...

CVSS 8.8 2026-09-16
CVE-2026-92592
HIGH

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed r...

CVSS 8.8 2026-09-16
CVE-2026-92582
HIGH

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skip...

CVSS 7.1 2026-09-16
CVE-2026-92580
HIGH

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substitut...

CVSS 8.8 2026-09-16
CVE-2026-92578
HIGH

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths i...

CVSS 8.1 2026-09-16
CVE-2026-92577
HIGH

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner...

CVSS 7.5 2026-09-16
CVE-2026-92576
HIGH

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges a...

CVSS 8.6 2026-09-16
1 8 9 10 11 12 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.