CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 33 of 500
CVE-2026-81237
MEDIUM

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially explo...

CVSS 6.5 2026-09-15
CVE-2026-57442
MEDIUM

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list...

CVSS 6.9 2026-09-15
CVE-2026-56831
MEDIUM

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_disc...

CVSS 6.5 2026-09-15
CVE-2026-56830
MEDIUM

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Medi...

CVSS 6.5 2026-09-15
CVE-2026-55375
MEDIUM

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code ...

CVSS 5.3 2026-09-15
CVE-2026-55226
MEDIUM

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operat...

CVSS 5.4 2026-09-15
CVE-2026-54689
MEDIUM

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/...

CVSS 6.3 2026-09-15
CVE-2026-54688
MEDIUM

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-suppli...

CVSS 6.5 2026-09-15
CVE-2026-54050
MEDIUM

Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete...

CVSS 6.5 2026-09-15
CVE-2026-53941
MEDIUM

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe l...

CVSS 6.9 2026-09-15
CVE-2026-39038
MEDIUM

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

CVSS 6.1 2026-09-15
CVE-2026-12910
MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have a...

CVSS 5.4 2026-09-15
CVE-2026-12751
MEDIUM

IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web ...

CVSS 5.4 2026-09-15
CVE-2026-12750
MEDIUM

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI...

CVSS 6.4 2026-09-15
CVE-2026-12749
MEDIUM

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI...

CVSS 6.4 2026-09-15
CVE-2026-12742
MEDIUM

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

CVSS 5.4 2026-09-15
CVE-2026-11927
MEDIUM

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

CVSS 6.5 2026-09-15
CVE-2026-11918
MEDIUM

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payl...

CVSS 5.4 2026-09-15
CVE-2026-11864
MEDIUM

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0...

CVSS 6.5 2026-09-15
CVE-2026-91855
MEDIUM

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the component PFCP Message ...

CVSS 5.3 2026-09-15
1 31 32 33 34 35 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.