CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 3 of 500
CVE-2026-54594
MEDIUM

OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edit...

CVSS 5.3 2026-09-17
CVE-2026-92992
MEDIUM

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component ...

CVSS 6.3 2026-09-17
CVE-2026-52852
MEDIUM

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarch...

CVSS 6.5 2026-09-17
CVE-2026-92927
MEDIUM

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulati...

CVSS 5.3 2026-09-17
CVE-2026-89038
MEDIUM

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlle...

CVSS 6.2 2026-09-17
CVE-2026-54677
MEDIUM

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can create content in questions belonging to...

CVSS 6.5 2026-09-17
CVE-2026-54676
MEDIUM

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve replies from questions in private spaces they cannot access...

CVSS 6.5 2026-09-17
CVE-2026-54546
MEDIUM

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an att...

CVSS 5 2026-09-17
CVE-2026-44235
MEDIUM

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause un...

CVSS 6.5 2026-09-17
CVE-2026-93296
MEDIUM

MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card (event_general.ctp) and the server/feed preview car...

CVSS 5.1 2026-09-17
CVE-2026-93295
MEDIUM

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv o...

CVSS 5.1 2026-09-17
CVE-2026-8674
MEDIUM

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in th...

CVSS 5.3 2026-09-17
CVE-2026-85720
MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request ...

CVSS 5.9 2026-09-17
CVE-2026-54587
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_...

CVSS 5.8 2026-09-17
CVE-2026-54586
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HT...

CVSS 6 2026-09-17
CVE-2026-54585
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from th...

CVSS 6 2026-09-17
CVE-2026-54582
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected...

CVSS 6 2026-09-17
CVE-2026-54576
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations...

CVSS 5.8 2026-09-17
CVE-2026-54575
MEDIUM

mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/cle...

CVSS 5.8 2026-09-17
CVE-2026-93015
MEDIUM

BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVE...

CVSS 6.3 2026-09-17
1 2 3 4 5 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.