CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 40 of 500
CVE-2026-91857
MEDIUM

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPi...

CVSS 5.3 2026-09-15
CVE-2026-62280
MEDIUM

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values...

CVSS 6.1 2026-09-15
CVE-2026-44202
MEDIUM

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbi...

CVSS 5.3 2026-09-15
CVE-2025-5802
MEDIUM

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an ex...

CVSS 5.3 2026-09-15
CVE-2026-91851
MEDIUM

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when ...

CVSS 5.3 2026-09-15
CVE-2026-91819
MEDIUM

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-...

CVSS 6.9 2026-09-15
CVE-2026-91089
MEDIUM

A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after f...

CVSS 6.3 2026-09-15
CVE-2026-91086
MEDIUM

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MP...

CVSS 6.3 2026-09-15
CVE-2026-91005
MEDIUM

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the compone...

CVSS 6.3 2026-09-15
CVE-2026-89141
MEDIUM

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via...

CVSS 6.5 2026-09-15
CVE-2026-18063
MEDIUM

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficie...

CVSS 6.4 2026-09-15
CVE-2026-15402
MEDIUM

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' sched...

CVSS 6.4 2026-09-15
CVE-2026-91002
MEDIUM

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. E...

CVSS 5.3 2026-09-15
CVE-2026-81320
MEDIUM

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS ...

CVSS 5.5 2026-09-15
CVE-2026-81303
MEDIUM

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio cu...

CVSS 6.3 2026-09-15
CVE-2026-18232
MEDIUM

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowin...

CVSS 5.3 2026-09-15
CVE-2026-17495
MEDIUM

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to ...

CVSS 5.9 2026-09-15
CVE-2026-16593
MEDIUM

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access...

CVSS 6.8 2026-09-15
CVE-2026-15758
MEDIUM

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...

CVSS 5.3 2026-09-15
CVE-2026-90881
MEDIUM

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation ca...

CVSS 5.3 2026-09-15
1 38 39 40 41 42 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.