CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 41 of 500
CVE-2026-91967
MEDIUM

AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format va...

CVSS 5 2026-09-15
CVE-2026-91966
MEDIUM

AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers...

CVSS 5.8 2026-09-15
CVE-2026-91963
MEDIUM

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB tr...

CVSS 6.5 2026-09-15
CVE-2026-91962
MEDIUM

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted Fra...

CVSS 6.3 2026-09-15
CVE-2026-91961
MEDIUM

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb...

CVSS 6.5 2026-09-15
CVE-2026-91960
MEDIUM

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious R...

CVSS 6.5 2026-09-15
CVE-2026-91959
MEDIUM

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU...

CVSS 6.5 2026-09-15
CVE-2026-91958
MEDIUM

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can cr...

CVSS 6.6 2026-09-15
CVE-2026-91956
MEDIUM

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol f...

CVSS 6.5 2026-09-15
CVE-2026-91954
MEDIUM

FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can ...

CVSS 6.5 2026-09-15
CVE-2026-91953
MEDIUM

FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before w...

CVSS 6.5 2026-09-15
CVE-2026-91952
MEDIUM

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than prealloc...

CVSS 6.5 2026-09-15
CVE-2026-91951
MEDIUM

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server c...

CVSS 6.5 2026-09-15
CVE-2026-91950
MEDIUM

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malici...

CVSS 6.5 2026-09-15
CVE-2026-91946
MEDIUM

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fix...

CVSS 6.5 2026-09-15
CVE-2026-91945
MEDIUM

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authe...

CVSS 6.5 2026-09-15
CVE-2026-91944
MEDIUM

crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to in...

CVSS 6.1 2026-09-15
CVE-2026-91942
MEDIUM

crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can c...

CVSS 5.4 2026-09-15
CVE-2026-91936
MEDIUM

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run block...

CVSS 6.8 2026-09-15
CVE-2026-91849
MEDIUM

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar ...

CVSS 6.3 2026-09-15
1 39 40 41 42 43 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.