CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 23 of 500
CVE-2026-77190
MEDIUM

On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured...

CVSS 6.5 2026-09-16
CVE-2026-73469
MEDIUM

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification dr...

CVSS 5.8 2026-09-16
CVE-2026-73468
MEDIUM

A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the...

CVSS 6.5 2026-09-16
CVE-2026-73438
MEDIUM

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a spe...

CVSS 5.3 2026-09-16
CVE-2026-73436
MEDIUM

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to resta...

CVSS 6.5 2026-09-16
CVE-2026-92081
MEDIUM

fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fa...

CVSS 5.9 2026-09-16
CVE-2026-86465
MEDIUM

Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one...

CVSS 6.5 Apache apache-airflow-providers-akeyless 2026-09-16
CVE-2026-89186
MEDIUM

Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credentia...

CVSS 6.3 2026-09-16
CVE-2026-88255
MEDIUM

Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transact...

CVSS 6.3 2026-09-16
CVE-2026-86338
MEDIUM

Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expre...

CVSS 6 2026-09-16
CVE-2026-85501
MEDIUM

Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones a...

CVSS 5.3 2026-09-16
CVE-2026-82720
MEDIUM

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths...

CVSS 5.9 2026-09-16
CVE-2026-80225
MEDIUM

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A ...

CVSS 5.3 2026-09-16
CVE-2026-78227
MEDIUM

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an ou...

CVSS 6.5 2026-09-16
CVE-2026-73463
MEDIUM

On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a pol...

CVSS 5.3 2026-09-16
CVE-2026-92091
MEDIUM

A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of ...

CVSS 5.9 2026-09-16
CVE-2026-89207
MEDIUM

A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly vali...

CVSS 6.5 2026-09-16
CVE-2026-81326
MEDIUM

QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator ...

CVSS 5.5 2026-09-16
CVE-2026-27553
MEDIUM

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclos...

CVSS 6.5 2026-09-16
CVE-2026-86475
MEDIUM

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unau...

CVSS 5.3 2026-09-16
1 21 22 23 24 25 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.