CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 2 of 500
CVE-2026-54647
HIGH

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter i...

CVSS 7.2 2026-09-17
CVE-2026-54646
HIGH

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, ...

CVSS 7.2 2026-09-17
CVE-2026-54634
HIGH

Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches rigctl_send_raw() ...

CVSS 7.3 2026-09-17
CVE-2026-54612
HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/gl...

CVSS 8.8 2026-09-17
CVE-2026-54608
HIGH

MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_...

CVSS 7.1 2026-09-17
CVE-2026-54520
HIGH

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backen...

CVSS 8.1 2026-09-17
CVE-2026-54519
HIGH

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authe...

CVSS 8.8 2026-09-17
CVE-2026-54507
HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/edito...

CVSS 8.4 2026-09-17
CVE-2026-54506
HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] fiel...

CVSS 7.6 2026-09-17
CVE-2026-54343
HIGH

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handl...

CVSS 8.7 2026-09-17
CVE-2026-53557
HIGH

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel...

CVSS 7.7 2026-09-17
CVE-2026-53554
HIGH

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/d...

CVSS 7.3 2026-09-17
CVE-2026-53534
HIGH

JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/ca...

CVSS 7.5 2026-09-17
CVE-2026-50158
HIGH

yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/capti...

CVSS 7.7 2026-09-17
CVE-2026-93393
HIGH

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects ...

CVSS 8.1 2026-09-17
CVE-2026-86049
HIGH

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON hea...

CVSS 7.1 2026-09-17
CVE-2026-77615
HIGH

Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS att...

CVSS 8.7 2026-09-17
CVE-2026-76154
HIGH

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session b...

CVSS 7.3 2026-09-17
CVE-2026-68537
HIGH

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolv...

CVSS 7.5 2026-09-17
CVE-2026-68523
HIGH

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolv...

CVSS 7.5 2026-09-17
1 2 3 4 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.