CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 21 of 500
CVE-2026-92615
MEDIUM

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custo...

CVSS 6.6 2026-09-16
CVE-2026-76104
MEDIUM

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote acces...

CVSS 5.5 2026-09-16
CVE-2026-26947
MEDIUM

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with ...

CVSS 6.7 2026-09-16
CVE-2026-19607
MEDIUM

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an...

CVSS 5.3 2026-09-16
CVE-2026-92616
MEDIUM

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploit...

CVSS 6.8 2026-09-16
CVE-2026-92570
MEDIUM

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration...

CVSS 6.5 2026-09-16
CVE-2026-92568
MEDIUM

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary H...

CVSS 5.4 2026-09-16
CVE-2026-92567
MEDIUM

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other ...

CVSS 6.5 2026-09-16
CVE-2026-92565
MEDIUM

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthentica...

CVSS 5.3 2026-09-16
CVE-2026-89031
MEDIUM

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in in...

CVSS 5.4 2026-09-16
CVE-2026-88976
MEDIUM

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse ...

CVSS 6.1 2026-09-16
CVE-2026-84859
MEDIUM

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The v...

CVSS 6.5 2026-09-16
CVE-2026-77401
MEDIUM

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Pytho...

CVSS 6.8 2026-09-16
CVE-2026-77119
MEDIUM

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This iss...

CVSS 5.9 2026-09-16
CVE-2026-75029
MEDIUM

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the r...

CVSS 5.3 2026-09-16
CVE-2026-61709
MEDIUM

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization ...

CVSS 5.3 2026-09-16
CVE-2026-19668
MEDIUM

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-record...

CVSS 5.3 2026-09-16
CVE-2026-19033
MEDIUM

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. Th...

CVSS 6.5 2026-09-16
CVE-2026-92468
MEDIUM

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsear...

CVSS 6.5 2026-09-16
CVE-2026-92364
MEDIUM

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The m...

CVSS 6.3 2026-09-16
1 19 20 21 22 23 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.