CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 18 of 500
CVE-2026-92803
MEDIUM

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requir...

CVSS 5.3 2026-09-16
CVE-2026-92800
MEDIUM

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read a...

CVSS 6.8 2026-09-16
CVE-2026-92795
MEDIUM

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attacke...

CVSS 6.5 2026-09-16
CVE-2026-92790
MEDIUM

Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI toke...

CVSS 6.5 2026-09-16
CVE-2026-92789
MEDIUM

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or ev...

CVSS 6.5 2026-09-16
CVE-2026-92781
MEDIUM

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters ...

CVSS 6.3 2026-09-16
CVE-2026-92778
MEDIUM

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form e...

CVSS 5.4 2026-09-16
CVE-2026-92775
MEDIUM

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validatio...

CVSS 6.5 2026-09-16
CVE-2026-92771
MEDIUM

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers w...

CVSS 6.5 2026-09-16
CVE-2026-92770
MEDIUM

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on t...

CVSS 6.5 2026-09-16
CVE-2026-92765
MEDIUM

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizati...

CVSS 6.5 2026-09-16
CVE-2026-92760
MEDIUM

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author...

CVSS 6.5 2026-09-16
CVE-2026-92759
MEDIUM

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API confi...

CVSS 6.5 2026-09-16
CVE-2026-92750
MEDIUM

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces the...

CVSS 6.5 2026-09-16
CVE-2026-92527
MEDIUM

A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads...

CVSS 6.3 2026-09-16
CVE-2026-81872
MEDIUM

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker...

CVSS 6.3 2026-09-16
CVE-2026-81871
MEDIUM

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_...

CVSS 6.3 2026-09-16
CVE-2026-81869
MEDIUM

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLeng...

CVSS 5.1 2026-09-16
CVE-2026-76447
MEDIUM

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative...

CVSS 5.3 2026-09-16
CVE-2026-76444
MEDIUM

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affect...

CVSS 5.3 2026-09-16
1 16 17 18 19 20 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.