CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 22 of 500
CVE-2026-92140
MEDIUM

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XS...

CVSS 6.8 2026-09-16
CVE-2026-92139
MEDIUM

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to...

CVSS 6.5 2026-09-16
CVE-2026-92133
MEDIUM

Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentia...

CVSS 5.4 2026-09-16
CVE-2026-92132
MEDIUM

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is config...

CVSS 5.4 2026-09-16
CVE-2026-85104
MEDIUM

In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters.

CVSS 5.3 2026-09-16
CVE-2026-78301
MEDIUM

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g...

CVSS 5.8 2026-09-16
CVE-2026-56719
MEDIUM

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request b...

CVSS 6.5 2026-09-16
CVE-2026-19941
MEDIUM

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name ...

CVSS 5.9 2026-09-16
CVE-2026-19662
MEDIUM

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an author...

CVSS 5.9 2026-09-16
CVE-2026-92360
MEDIUM

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application ...

CVSS 6.3 2026-09-16
CVE-2026-73169
MEDIUM

Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management in...

CVSS 6.3 2026-09-16
CVE-2026-92463
MEDIUM

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticate...

CVSS 6.5 2026-09-16
CVE-2026-92462
MEDIUM

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary appr...

CVSS 6.5 2026-09-16
CVE-2026-92460
MEDIUM

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wi...

CVSS 6.5 2026-09-16
CVE-2026-92459
MEDIUM

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales...

CVSS 6.5 2026-09-16
CVE-2026-92457
MEDIUM

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitr...

CVSS 6.5 2026-09-16
CVE-2026-86107
MEDIUM

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impact...

CVSS 5.9 2026-09-16
CVE-2026-86443
MEDIUM

Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the cre...

CVSS 6.9 2026-09-16
CVE-2026-84439
MEDIUM

When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentic...

CVSS 5.3 Apache zookeeper 2026-09-16
CVE-2026-84501
MEDIUM

An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline ch...

CVSS 5.3 Apache zookeeper 2026-09-16
1 20 21 22 23 24 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.