CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 39 of 500
CVE-2026-92005
MEDIUM

Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, an...

CVSS 5.3 2026-09-15
CVE-2026-15609
MEDIUM

The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, and...

CVSS 6.4 2026-09-15
CVE-2026-92003
MEDIUM

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:...

CVSS 6.9 2026-09-15
CVE-2026-92002
MEDIUM

Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentica...

CVSS 5.1 2026-09-15
CVE-2026-91997
MEDIUM

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metr...

CVSS 5.3 2026-09-15
CVE-2026-91994
MEDIUM

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all p...

CVSS 6.5 2026-09-15
CVE-2026-91922
MEDIUM

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query param...

CVSS 6.1 2026-09-15
CVE-2026-91786
MEDIUM

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data ...

CVSS 6.1 2026-09-15
CVE-2026-80489
MEDIUM

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter...

CVSS 5.9 2026-09-15
CVE-2026-77117
MEDIUM

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the convert...

CVSS 5.9 2026-09-15
CVE-2026-52828
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level...

CVSS 5.3 2026-09-15
CVE-2026-52826
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/a...

CVSS 5.3 2026-09-15
CVE-2026-52825
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead ma...

CVSS 5.3 2026-09-15
CVE-2026-52823
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an a...

CVSS 5.3 2026-09-15
CVE-2026-52822
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can der...

CVSS 5.3 2026-09-15
CVE-2026-52821
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only...

CVSS 5.3 2026-09-15
CVE-2026-52820
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through Timeshee...

CVSS 5.3 2026-09-15
CVE-2026-52819
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_...

CVSS 6.3 2026-09-15
CVE-2026-1759
MEDIUM

Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.62551507...

CVSS 6.5 2026-09-15
CVE-2026-91859
MEDIUM

Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering...

CVSS 5.3 2026-09-15
1 37 38 39 40 41 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.