CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 34 of 500
CVE-2026-81897
MEDIUM

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated admini...

CVSS 5.4 Concretecms concrete_cms 2026-09-15
CVE-2026-81896
MEDIUM

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions rep...

CVSS 5.4 Concretecms concrete_cms 2026-09-15
CVE-2026-81894
MEDIUM

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbo...

CVSS 5.4 Concretecms concrete_cms 2026-09-15
CVE-2026-55863
MEDIUM

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.pos...

CVSS 5.3 2026-09-15
CVE-2026-54561
MEDIUM

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath ...

CVSS 6.2 2026-09-15
CVE-2026-53658
MEDIUM

Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts...

CVSS 6.3 2026-09-15
CVE-2026-91992
MEDIUM

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can ob...

CVSS 5.9 2026-09-15
CVE-2026-91991
MEDIUM

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword ...

CVSS 5.4 2026-09-15
CVE-2026-91987
MEDIUM

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers...

CVSS 6.5 2026-09-15
CVE-2026-91986
MEDIUM

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers...

CVSS 5.4 2026-09-15
CVE-2026-91979
MEDIUM

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that...

CVSS 6.5 2026-09-15
CVE-2026-91971
MEDIUM

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to exce...

CVSS 6.5 2026-09-15
CVE-2026-91970
MEDIUM

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated...

CVSS 6.5 2026-09-15
CVE-2026-91969
MEDIUM

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticat...

CVSS 6.5 2026-09-15
CVE-2026-91968
MEDIUM

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. ...

CVSS 6.5 2026-09-15
CVE-2026-91967
MEDIUM

AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format va...

CVSS 5 2026-09-15
CVE-2026-91966
MEDIUM

AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers...

CVSS 5.8 2026-09-15
CVE-2026-91963
MEDIUM

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB tr...

CVSS 6.5 2026-09-15
CVE-2026-91962
MEDIUM

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted Fra...

CVSS 6.3 2026-09-15
CVE-2026-91961
MEDIUM

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb...

CVSS 6.5 2026-09-15
1 32 33 34 35 36 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.