CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 10 of 500
CVE-2026-73462
MEDIUM

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated at...

CVSS 6.5 2026-09-16
CVE-2026-73457
MEDIUM

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in cl...

CVSS 5.3 2026-09-16
CVE-2026-59823
MEDIUM

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_...

CVSS 5.3 2026-09-16
CVE-2026-92605
MEDIUM

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any sing...

CVSS 6.5 2026-09-16
CVE-2026-84397
MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnera...

CVSS 5.4 2026-09-16
CVE-2026-69147
MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to...

CVSS 6.5 2026-09-16
CVE-2026-18120
MEDIUM

Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by th...

CVSS 6.3 2026-09-16
CVE-2026-92603
MEDIUM

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages ...

CVSS 6.5 2026-09-16
CVE-2026-92601
MEDIUM

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. ...

CVSS 6.5 2026-09-16
CVE-2026-92600
MEDIUM

Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, ca...

CVSS 6.5 2026-09-16
CVE-2026-92402
MEDIUM

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the ...

CVSS 6.3 2026-09-16
CVE-2026-87028
MEDIUM

Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authoriz...

CVSS 5.3 2026-09-16
CVE-2026-86358
MEDIUM

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could pote...

CVSS 6.5 2026-09-16
CVE-2026-84993
MEDIUM

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer validates the field key of an...

CVSS 6.5 2026-09-16
CVE-2026-59944
MEDIUM

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-5994...

CVSS 6.1 2026-09-16
CVE-2026-57173
MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMed...

CVSS 6.5 2026-09-16
CVE-2026-92615
MEDIUM

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custo...

CVSS 6.6 2026-09-16
CVE-2026-76104
MEDIUM

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote acces...

CVSS 5.5 2026-09-16
CVE-2026-26947
MEDIUM

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with ...

CVSS 6.7 2026-09-16
CVE-2026-19607
MEDIUM

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an...

CVSS 5.3 2026-09-16
1 8 9 10 11 12 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.