CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 4 of 500
CVE-2026-54571
HIGH

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp ...

CVSS 8.7 2026-09-17
CVE-2026-54524
HIGH

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Pa...

CVSS 7.1 2026-09-17
CVE-2026-54504
HIGH

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/ser...

CVSS 8.8 2026-09-17
CVE-2026-54451
HIGH

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be ta...

CVSS 8.2 2026-09-17
CVE-2026-54253
HIGH

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled po...

CVSS 8.2 2026-09-17
CVE-2026-54239
HIGH

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initializat...

CVSS 8.8 2026-09-17
CVE-2026-52851
HIGH

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/perm...

CVSS 7.1 2026-09-17
CVE-2026-52727
HIGH

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the sam...

CVSS 7.2 2026-09-17
CVE-2026-19477
HIGH

There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code exec...

CVSS 7.8 2026-09-17
CVE-2026-92926
HIGH

A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipula...

CVSS 7.3 2026-09-17
CVE-2026-54446
HIGH

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network...

CVSS 8.1 2026-09-17
CVE-2026-52836
HIGH

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior to 3.34.0, a network attacker can crash a reachable OpenDDS...

CVSS 8.7 2026-09-17
CVE-2026-44236
HIGH

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), an...

CVSS 7.1 2026-09-17
CVE-2026-93292
HIGH

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHo...

CVSS 8.5 2026-09-17
CVE-2026-92980
HIGH

HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user b...

CVSS 7.2 2026-09-17
CVE-2026-54583
HIGH

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing pa...

CVSS 8.3 2026-09-17
CVE-2026-54581
HIGH

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification...

CVSS 8.3 2026-09-17
CVE-2026-54580
HIGH

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmpor...

CVSS 8.3 2026-09-17
CVE-2026-28326
HIGH

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

CVSS 8.8 2026-09-17
CVE-2026-93014
HIGH

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path tr...

CVSS 7.1 2026-09-17
1 2 3 4 5 6 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.