CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 15 of 500
CVE-2026-92952
MEDIUM

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross...

CVSS 6.8 2026-09-17
CVE-2026-92936
MEDIUM

vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source tran...

CVSS 5.8 2026-09-17
CVE-2026-92933
MEDIUM

vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, u...

CVSS 5.8 2026-09-17
CVE-2026-86522
MEDIUM

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password...

CVSS 6.3 2026-09-17
CVE-2026-81829
MEDIUM

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provide...

CVSS 5.3 2026-09-17
CVE-2026-81453
MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low pr...

CVSS 6.5 2026-09-17
CVE-2026-81443
MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could po...

CVSS 6.4 2026-09-17
CVE-2026-80355
MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could p...

CVSS 5.4 2026-09-17
CVE-2026-78528
MEDIUM

Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.

CVSS 5.3 2026-09-17
CVE-2026-78294
MEDIUM

Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

CVSS 6.5 2026-09-17
CVE-2026-78223
MEDIUM

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write ...

CVSS 6.9 2026-09-17
CVE-2026-74017
MEDIUM

Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.

CVSS 5.3 2026-09-17
CVE-2026-74005
MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.

CVSS 5.4 2026-09-17
CVE-2026-74002
MEDIUM

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

CVSS 5.3 2026-09-17
CVE-2026-74000
MEDIUM

Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.

CVSS 5.3 2026-09-17
CVE-2026-73999
MEDIUM

Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.

CVSS 5.4 2026-09-17
CVE-2026-71568
MEDIUM

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the a...

CVSS 5.3 2026-09-17
CVE-2026-66676
MEDIUM

Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.

CVSS 5.3 2026-09-17
CVE-2026-66617
MEDIUM

Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.

CVSS 6.5 2026-09-17
CVE-2026-66608
MEDIUM

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

CVSS 6.4 2026-09-17
1 13 14 15 16 17 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.