CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
10,000 result(s) · page 33 of 500
CVE-2026-86553
HIGH

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parame...

CVSS 8.5 2026-09-20
CVE-2026-93959
HIGH

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course...

CVSS 7.3 2026-09-20
CVE-2026-94084
CRITICAL

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

CVSS 9.4 2026-09-20
CVE-2026-94083
CRITICAL

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when the...

CVSS 9.4 2026-09-20
CVE-2026-93958
CRITICAL

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argumen...

CVSS 9.1 2026-09-20
CVE-2026-94056
HIGH

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

CVSS 7.5 2026-09-19
CVE-2026-94054
HIGH

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

CVSS 7 2026-09-19
CVE-2026-93993
HIGH

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a r...

CVSS 8.8 2026-09-19
CVE-2026-93992
HIGH

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers...

CVSS 8.1 2026-09-19
CVE-2026-93991
HIGH

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadat...

CVSS 7.7 2026-09-19
CVE-2026-93990
HIGH

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encod...

CVSS 7.5 2026-09-19
CVE-2026-93988
MEDIUM

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Atta...

CVSS 6.5 2026-09-19
CVE-2026-82672
MEDIUM

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict interm...

CVSS 6.3 2026-09-19
CVE-2026-94001
MEDIUM

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check...

CVSS 6.5 2026-09-19
CVE-2026-94000
MEDIUM

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fail...

CVSS 6.6 2026-09-19
CVE-2026-93985
CRITICAL

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to cons...

CVSS 9.9 2026-09-19
CVE-2026-93984
MEDIUM

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering....

CVSS 5.3 2026-09-19
CVE-2026-93983
MEDIUM

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted fi...

CVSS 5 2026-09-19
CVE-2026-78030
CRITICAL

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attribu...

CVSS 9.8 2026-09-19
CVE-2026-9289
MEDIUM

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API e...

CVSS 5.3 2026-09-19
1 31 32 33 34 35 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.