CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 25 of 500
CVE-2026-77702
MEDIUM

The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthentic...

CVSS 5.3 2026-09-16
CVE-2026-76558
MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM of one of its administrat...

CVSS 6.8 2026-09-16
CVE-2026-76557
MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users ...

CVSS 6.8 2026-09-16
CVE-2026-76556
MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, allowing users holding...

CVSS 6.8 2026-09-16
CVE-2026-76555
MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing...

CVSS 6.8 2026-09-16
CVE-2026-76553
MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, al...

CVSS 6.5 2026-09-16
CVE-2026-5920
MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to...

CVSS 6.4 2026-09-16
CVE-2026-18555
MEDIUM

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all ve...

CVSS 6.1 2026-09-16
CVE-2026-16588
MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping...

CVSS 6.5 2026-09-16
CVE-2026-11996
MEDIUM

The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insuff...

CVSS 6.4 2026-09-16
CVE-2026-11984
MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check...

CVSS 5.3 2026-09-16
CVE-2026-92220
MEDIUM

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._h...

CVSS 5.3 2026-09-16
CVE-2026-86109
MEDIUM

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used ...

CVSS 6.6 2026-09-16
CVE-2026-73450
MEDIUM

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send...

CVSS 6.9 2026-09-16
CVE-2026-92217
MEDIUM

A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts ...

CVSS 6.3 2026-09-16
CVE-2026-92213
MEDIUM

A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component ...

CVSS 5.5 2026-09-16
CVE-2026-92184
MEDIUM

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/uti...

CVSS 6.3 2026-09-16
CVE-2026-73460
MEDIUM

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS gracef...

CVSS 6.1 2026-09-16
CVE-2025-11395
MEDIUM

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user ru...

CVSS 5.5 2026-09-15
CVE-2026-92259
MEDIUM

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow...

CVSS 5.5 2026-09-15
1 23 24 25 26 27 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.