CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
10,000 result(s) · page 15 of 500
CVE-2026-94056
HIGH

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

CVSS 7.5 2026-09-19
CVE-2026-94054
HIGH

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

CVSS 7 2026-09-19
CVE-2026-93993
HIGH

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a r...

CVSS 8.8 2026-09-19
CVE-2026-93992
HIGH

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers...

CVSS 8.1 2026-09-19
CVE-2026-93991
HIGH

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadat...

CVSS 7.7 2026-09-19
CVE-2026-93990
HIGH

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encod...

CVSS 7.5 2026-09-19
CVE-2026-93988
MEDIUM

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Atta...

CVSS 6.5 2026-09-19
CVE-2026-82672
MEDIUM

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict interm...

CVSS 6.3 2026-09-19
CVE-2026-94001
MEDIUM

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check...

CVSS 6.5 2026-09-19
CVE-2026-94000
MEDIUM

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fail...

CVSS 6.6 2026-09-19
CVE-2026-93985
CRITICAL

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to cons...

CVSS 9.9 2026-09-19
CVE-2026-93984
MEDIUM

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering....

CVSS 5.3 2026-09-19
CVE-2026-93983
MEDIUM

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted fi...

CVSS 5 2026-09-19
CVE-2026-9289
MEDIUM

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API e...

CVSS 5.3 2026-09-19
CVE-2026-93742
CRITICAL

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument ...

CVSS 9.9 2026-09-19
CVE-2026-8354
MEDIUM

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insuff...

CVSS 6.4 2026-09-19
CVE-2026-5410
MEDIUM

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient inp...

CVSS 6.4 2026-09-19
CVE-2026-1256
MEDIUM

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 du...

CVSS 6.4 2026-09-19
CVE-2026-1255
HIGH

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action...

CVSS 7.5 2026-09-19
CVE-2026-18346
MEDIUM

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not properly verifying that a user is a...

CVSS 5.3 2026-09-19
1 13 14 15 16 17 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.