CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 2 of 500
CVE-2026-54613
MEDIUM

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php ...

CVSS 5.4 2026-09-17
CVE-2026-53556
MEDIUM

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud...

CVSS 6 2026-09-17
CVE-2026-53555
MEDIUM

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through ...

CVSS 5.1 2026-09-17
CVE-2026-50291
MEDIUM

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processin...

CVSS 5.5 2026-09-17
CVE-2026-16750
MEDIUM

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_lo...

CVSS 5.3 2026-09-17
CVE-2026-16582
MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This ...

CVSS 5.3 2026-09-17
CVE-2026-14311
MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification...

CVSS 5.4 2026-09-17
CVE-2026-93395
MEDIUM

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function rea...

CVSS 5.3 2026-09-17
CVE-2026-77281
MEDIUM

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. I...

CVSS 6.5 2026-09-17
CVE-2026-67071
MEDIUM

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure prope...

CVSS 6.5 2026-09-17
CVE-2026-54918
MEDIUM

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests...

CVSS 5.3 2026-09-17
CVE-2026-54907
MEDIUM

Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration ...

CVSS 5.3 2026-09-17
CVE-2026-54604
MEDIUM

OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c a...

CVSS 5.3 2026-09-17
CVE-2026-54521
MEDIUM

FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/Act...

CVSS 6.1 2026-09-17
CVE-2026-54355
MEDIUM

MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlaye...

CVSS 5.3 2026-09-17
CVE-2026-50022
MEDIUM

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter th...

CVSS 5.8 2026-09-17
CVE-2026-92993
MEDIUM

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of t...

CVSS 6.3 2026-09-17
CVE-2026-92758
MEDIUM

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure ac...

CVSS 5.5 2026-09-17
CVE-2026-92757
MEDIUM

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

CVSS 5.5 2026-09-17
CVE-2026-92756
MEDIUM

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-...

CVSS 5.5 2026-09-17
1 2 3 4 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.