CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 30 of 500
CVE-2026-62597
MEDIUM

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and ...

CVSS 6.5 2026-09-15
CVE-2026-51133
MEDIUM

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pm...

CVSS 6.1 2026-09-15
CVE-2026-32599
MEDIUM

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct strin...

CVSS 5.3 2026-09-15
CVE-2026-90971
MEDIUM

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other user...

CVSS 6.5 2026-09-15
CVE-2026-90969
MEDIUM

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain c...

CVSS 6.5 2026-09-15
CVE-2026-84048
MEDIUM

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, howe...

CVSS 6.3 2026-09-15
CVE-2026-82191
MEDIUM

Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal no...

CVSS 5.3 2026-09-15
CVE-2026-82190
MEDIUM

Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can c...

CVSS 6.3 2026-09-15
CVE-2026-81921
MEDIUM

Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token wit...

CVSS 5.4 Concretecms concrete_cms 2026-09-15
CVE-2026-79409
MEDIUM

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

CVSS 6.5 2026-09-15
CVE-2026-73467
MEDIUM

On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) server...

CVSS 6.3 2026-09-15
CVE-2026-73466
MEDIUM

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debu...

CVSS 6.3 2026-09-15
CVE-2026-73465
MEDIUM

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standa...

CVSS 6.3 2026-09-15
CVE-2026-69216
MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of r...

CVSS 5.4 2026-09-15
CVE-2026-69214
MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it ...

CVSS 6.8 2026-09-15
CVE-2026-69212
MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a redirect cha...

CVSS 5.9 2026-09-15
CVE-2026-69201
MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal...

CVSS 5.9 2026-09-15
CVE-2026-58773
MEDIUM

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execut...

CVSS 6.7 Google android 2026-09-15
CVE-2026-58767
MEDIUM

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System e...

CVSS 6.7 Google android 2026-09-15
CVE-2026-58765
MEDIUM

In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User inter...

CVSS 6.7 Google android 2026-09-15
1 28 29 30 31 32 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.