CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 26 of 500
CVE-2026-92257
MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and poli...

CVSS 5.4 2026-09-15
CVE-2026-92256
MEDIUM

NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attac...

CVSS 6.5 2026-09-15
CVE-2026-92255
MEDIUM

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an...

CVSS 5.4 2026-09-15
CVE-2026-92114
MEDIUM

A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of t...

CVSS 5.3 2026-09-15
CVE-2026-82567
MEDIUM

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network...

CVSS 6.3 2026-09-15
CVE-2026-76873
MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields...

CVSS 5.2 2026-09-15
CVE-2026-76872
MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_statici...

CVSS 5.4 2026-09-15
CVE-2026-76871
MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tp...

CVSS 6.5 2026-09-15
CVE-2026-76867
MEDIUM

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, rout...

CVSS 5.4 2026-09-15
CVE-2026-76859
MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ...

CVSS 6.5 2026-09-15
CVE-2026-76857
MEDIUM

Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHand...

CVSS 6.5 2026-09-15
CVE-2026-76855
MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_...

CVSS 6.5 2026-09-15
CVE-2026-76854
MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers c...

CVSS 6.5 2026-09-15
CVE-2026-92237
MEDIUM

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log re...

CVSS 6.5 2026-09-15
CVE-2026-92234
MEDIUM

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-...

CVSS 5.4 2026-09-15
CVE-2026-91744
MEDIUM

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engi...

CVSS 5.3 Google chrome 2026-09-15
CVE-2026-91725
MEDIUM

Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: ...

CVSS 5.3 Google chrome 2026-09-15
CVE-2026-91714
MEDIUM

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML pag...

CVSS 5.3 Google chrome 2026-09-15
CVE-2026-91717
MEDIUM

Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium se...

CVSS 5.1 Google chrome 2026-09-15
CVE-2026-81927
MEDIUM

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potent...

CVSS 5.4 Concretecms concrete_cms 2026-09-15
1 24 25 26 27 28 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.