CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Critical
10,000 result(s) · page 2 of 500
CVE-2026-45143
CRITICAL

Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders...

CVSS 9 2026-09-17
CVE-2026-45140
CRITICAL

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authori...

CVSS 9.8 2026-09-17
CVE-2026-54752
CRITICAL

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled ...

CVSS 9.6 2026-09-17
CVE-2026-54627
CRITICAL

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src...

CVSS 9.8 2026-09-17
CVE-2026-54626
CRITICAL

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by i...

CVSS 9.8 2026-09-17
CVE-2026-54618
CRITICAL

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /o...

CVSS 9.4 2026-09-17
CVE-2026-54617
CRITICAL

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading s...

CVSS 9.8 2026-09-17
CVE-2026-47252
CRITICAL

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-syst...

CVSS 9 2026-09-17
CVE-2026-54053
CRITICAL

Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts arch...

CVSS 9.6 2026-09-17
CVE-2026-91039
CRITICAL

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be...

CVSS 9.1 2026-09-17
CVE-2026-86863
CRITICAL

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI enviro...

CVSS 9.8 2026-09-17
CVE-2026-88952
CRITICAL

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not t...

CVSS 9.1 2026-09-17
CVE-2026-79752
CRITICAL

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, a...

CVSS 9.2 2026-09-17
CVE-2026-63472
CRITICAL

Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authenticati...

CVSS 9.1 2026-09-17
CVE-2026-92960
CRITICAL

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. ...

CVSS 10 2026-09-17
CVE-2026-92957
CRITICAL

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM...

CVSS 9.9 2026-09-17
CVE-2026-92956
CRITICAL

vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.ins...

CVSS 10 2026-09-17
CVE-2026-92955
CRITICAL

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. At...

CVSS 10 2026-09-17
CVE-2026-92953
CRITICAL

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and...

CVSS 10 2026-09-17
CVE-2026-92951
CRITICAL

vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boun...

CVSS 9.9 2026-09-17
1 2 3 4 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.