CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 37 of 500
CVE-2026-91954
MEDIUM

FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can ...

CVSS 6.5 2026-09-15
CVE-2026-91953
MEDIUM

FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before w...

CVSS 6.5 2026-09-15
CVE-2026-91952
MEDIUM

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than prealloc...

CVSS 6.5 2026-09-15
CVE-2026-91951
MEDIUM

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server c...

CVSS 6.5 2026-09-15
CVE-2026-91950
MEDIUM

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malici...

CVSS 6.5 2026-09-15
CVE-2026-91946
MEDIUM

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fix...

CVSS 6.5 2026-09-15
CVE-2026-91945
MEDIUM

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authe...

CVSS 6.5 2026-09-15
CVE-2026-91944
MEDIUM

crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to in...

CVSS 6.1 2026-09-15
CVE-2026-91942
MEDIUM

crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can c...

CVSS 5.4 2026-09-15
CVE-2026-91936
MEDIUM

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run block...

CVSS 6.8 2026-09-15
CVE-2026-91849
MEDIUM

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar ...

CVSS 6.3 2026-09-15
CVE-2026-89307
MEDIUM

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redire...

CVSS 5.1 2026-09-15
CVE-2026-87793
MEDIUM

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute a...

CVSS 5.1 2026-09-15
CVE-2026-59157
MEDIUM

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authenticat...

CVSS 6.5 2026-09-15
CVE-2026-55828
MEDIUM

qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-dis...

CVSS 6 2026-09-15
CVE-2026-55776
MEDIUM

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server p...

CVSS 6.5 2026-09-15
CVE-2026-55770
MEDIUM

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 L...

CVSS 6.8 2026-09-15
CVE-2026-55701
MEDIUM

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/confi...

CVSS 6.9 2026-09-15
CVE-2026-55636
MEDIUM

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with n...

CVSS 5.7 2026-09-15
CVE-2026-55591
MEDIUM

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, u...

CVSS 5.8 2026-09-15
1 35 36 37 38 39 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.