CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 38 of 500
CVE-2026-54724
MEDIUM

Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to...

CVSS 6.1 2026-09-15
CVE-2026-50024
MEDIUM

GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD an...

CVSS 5.3 2026-09-15
CVE-2026-44163
MEDIUM

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incomin...

CVSS 5.3 2026-09-15
CVE-2024-58384
MEDIUM

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can ...

CVSS 5.4 2026-09-15
CVE-2026-92082
MEDIUM

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes b...

CVSS 6.3 2026-09-15
CVE-2026-90439
MEDIUM

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a lim...

CVSS 6.5 2026-09-15
CVE-2026-88618
MEDIUM

1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.

CVSS 6.5 2026-09-15
CVE-2026-55617
MEDIUM

Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a re...

CVSS 6.9 2026-09-15
CVE-2026-54637
MEDIUM

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-co...

CVSS 5.5 2026-09-15
CVE-2026-54254
MEDIUM

Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler uses substring host matching instead of requiring the input ...

CVSS 5.9 2026-09-15
CVE-2026-54168
MEDIUM

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation toke...

CVSS 6.5 2026-09-15
CVE-2026-52724
MEDIUM

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp ...

CVSS 5.8 2026-09-15
CVE-2026-50166
MEDIUM

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manua...

CVSS 5.5 2026-09-15
CVE-2026-49446
MEDIUM

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/p...

CVSS 6.1 2026-09-15
CVE-2026-48987
MEDIUM

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to t...

CVSS 6.5 2026-09-15
CVE-2026-48722
MEDIUM

Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:...

CVSS 5.5 2026-09-15
CVE-2026-47780
MEDIUM

free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_da...

CVSS 6.9 2026-09-15
CVE-2026-92078
MEDIUM

Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

CVSS 6.5 2026-09-15
CVE-2026-92077
MEDIUM

Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

CVSS 6.5 2026-09-15
CVE-2026-92063
MEDIUM

Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

CVSS 6.5 2026-09-15
1 36 37 38 39 40 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.