CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 3 of 500
CVE-2026-54916
HIGH

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib...

CVSS 8.8 2026-09-17
CVE-2026-54597
HIGH

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write pe...

CVSS 8.3 2026-09-17
CVE-2026-54596
HIGH

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access ...

CVSS 8.1 2026-09-17
CVE-2026-54510
HIGH

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app...

CVSS 7.1 2026-09-17
CVE-2026-54354
HIGH

MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFil...

CVSS 8.2 2026-09-17
CVE-2026-54339
HIGH

Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), ...

CVSS 7.7 2026-09-17
CVE-2026-50277
HIGH

dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD...

CVSS 7.5 2026-09-17
CVE-2026-50275
HIGH

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers....

CVSS 7.5 2026-09-17
CVE-2026-48977
HIGH

OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositiv...

CVSS 7.7 2026-09-17
CVE-2026-15815
HIGH

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escap...

CVSS 8.8 2026-09-17
CVE-2026-93337
HIGH

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supp...

CVSS 7.8 2026-09-17
CVE-2026-92943
HIGH

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might all...

CVSS 8.1 2026-09-17
CVE-2026-54716
HIGH

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an excl...

CVSS 7.5 2026-09-17
CVE-2026-54692
HIGH

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-co...

CVSS 7.8 2026-09-17
CVE-2026-50285
HIGH

Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an o...

CVSS 7.5 2026-09-17
CVE-2026-50125
HIGH

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_...

CVSS 7.5 2026-09-17
CVE-2026-45726
HIGH

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets res...

CVSS 7.6 2026-09-17
CVE-2026-45720
HIGH

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks S...

CVSS 7 2026-09-17
CVE-2026-90997
HIGH

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic ...

CVSS 7.4 2026-09-17
CVE-2026-55062
HIGH

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the...

CVSS 8.4 2026-09-17
1 2 3 4 5 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.