CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 11 of 500
CVE-2026-92616
MEDIUM

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploit...

CVSS 6.8 2026-09-16
CVE-2026-92570
MEDIUM

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration...

CVSS 6.5 2026-09-16
CVE-2026-92568
MEDIUM

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary H...

CVSS 5.4 2026-09-16
CVE-2026-92567
MEDIUM

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other ...

CVSS 6.5 2026-09-16
CVE-2026-92565
MEDIUM

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthentica...

CVSS 5.3 2026-09-16
CVE-2026-89031
MEDIUM

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in in...

CVSS 5.4 2026-09-16
CVE-2026-88976
MEDIUM

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse ...

CVSS 6.1 2026-09-16
CVE-2026-84859
MEDIUM

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The v...

CVSS 6.5 2026-09-16
CVE-2026-77401
MEDIUM

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Pytho...

CVSS 6.8 2026-09-16
CVE-2026-77119
MEDIUM

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This iss...

CVSS 5.9 2026-09-16
CVE-2026-75029
MEDIUM

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the r...

CVSS 5.3 2026-09-16
CVE-2026-61709
MEDIUM

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization ...

CVSS 5.3 2026-09-16
CVE-2026-19668
MEDIUM

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-record...

CVSS 5.3 2026-09-16
CVE-2026-19033
MEDIUM

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. Th...

CVSS 6.5 2026-09-16
CVE-2026-92468
MEDIUM

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsear...

CVSS 6.5 2026-09-16
CVE-2026-92364
MEDIUM

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The m...

CVSS 6.3 2026-09-16
CVE-2026-92140
MEDIUM

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XS...

CVSS 6.8 2026-09-16
CVE-2026-92139
MEDIUM

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to...

CVSS 6.5 2026-09-16
CVE-2026-92133
MEDIUM

Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentia...

CVSS 5.4 2026-09-16
CVE-2026-92132
MEDIUM

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is config...

CVSS 5.4 2026-09-16
1 9 10 11 12 13 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.