CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 4 of 500
CVE-2026-86862
MEDIUM

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a dat...

CVSS 6.5 2026-09-17
CVE-2026-86861
MEDIUM

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened...

CVSS 5.9 2026-09-17
CVE-2026-86000
MEDIUM

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent qu...

CVSS 5.3 2026-09-17
CVE-2026-85999
MEDIUM

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an...

CVSS 5.3 2026-09-17
CVE-2026-85718
MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConn...

CVSS 5.9 2026-09-17
CVE-2026-85717
MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11...

CVSS 6.8 2026-09-17
CVE-2026-81868
MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certifi...

CVSS 6.5 2026-09-17
CVE-2026-76781
MEDIUM

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs wh...

CVSS 5.5 2026-09-17
CVE-2026-75523
MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actua...

CVSS 5.9 2026-09-17
CVE-2026-92880
MEDIUM

A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This...

CVSS 6.3 2026-09-17
CVE-2026-85078
MEDIUM

Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating ze...

CVSS 6.5 2026-09-17
CVE-2026-81447
MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network acces...

CVSS 6.8 2026-09-17
CVE-2026-63461
MEDIUM

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-...

CVSS 5.3 2026-09-17
CVE-2026-61793
MEDIUM

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults securit...

CVSS 6.9 2026-09-17
CVE-2026-92973
MEDIUM

ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controllin...

CVSS 6.1 2026-09-17
CVE-2026-92963
MEDIUM

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state obje...

CVSS 5.3 2026-09-17
CVE-2026-92952
MEDIUM

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross...

CVSS 6.8 2026-09-17
CVE-2026-92936
MEDIUM

vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source tran...

CVSS 5.8 2026-09-17
CVE-2026-92933
MEDIUM

vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, u...

CVSS 5.8 2026-09-17
CVE-2026-86522
MEDIUM

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password...

CVSS 6.3 2026-09-17
1 2 3 4 5 6 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.