CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 11 of 500
CVE-2026-85469
HIGH

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pi...

CVSS 8 2026-09-16
CVE-2026-61592
HIGH

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-ch...

CVSS 7.4 2026-09-16
CVE-2026-61591
HIGH

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the ...

CVSS 8.1 2026-09-16
CVE-2026-92816
HIGH

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can lo...

CVSS 7.8 2026-09-16
CVE-2026-92815
HIGH

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbi...

CVSS 7.5 2026-09-16
CVE-2026-92806
HIGH

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visi...

CVSS 8.1 2026-09-16
CVE-2026-92804
HIGH

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply ...

CVSS 7.1 2026-09-16
CVE-2026-92801
HIGH

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by t...

CVSS 8.8 2026-09-16
CVE-2026-92796
HIGH

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized que...

CVSS 8.8 2026-09-16
CVE-2026-92794
HIGH

OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identif...

CVSS 7.5 2026-09-16
CVE-2026-92793
HIGH

GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query paramete...

CVSS 8.1 2026-09-16
CVE-2026-92792
HIGH

OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute ...

CVSS 7.5 2026-09-16
CVE-2026-92791
HIGH

Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Atta...

CVSS 7.5 2026-09-16
CVE-2026-92788
HIGH

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable...

CVSS 8.8 2026-09-16
CVE-2026-92786
HIGH

LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers c...

CVSS 7.8 2026-09-16
CVE-2026-92785
HIGH

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate a...

CVSS 8.1 2026-09-16
CVE-2026-92784
HIGH

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malic...

CVSS 7.5 2026-09-16
CVE-2026-92783
HIGH

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers...

CVSS 8.1 2026-09-16
CVE-2026-92782
HIGH

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing...

CVSS 8.1 2026-09-16
CVE-2026-92780
HIGH

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call ...

CVSS 8.8 2026-09-16
1 9 10 11 12 13 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.