CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 446 of 500
CVE-2026-72538
HIGH

An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The bra...

CVSS 8.8 2026-08-11
CVE-2026-72537
HIGH

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account ...

CVSS 8.8 2026-08-11
CVE-2026-72536
HIGH

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIn...

CVSS 8.6 2026-08-11
CVE-2026-72535
HIGH

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the strip...

CVSS 8.6 2026-08-11
CVE-2026-72534
HIGH

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges b...

CVSS 8.8 2026-08-11
CVE-2026-72533
HIGH

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL no...

CVSS 8.8 2026-08-11
CVE-2026-50237
HIGH

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitra...

CVSS 7.4 2026-08-11
CVE-2026-50236
HIGH

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutraliz...

CVSS 7.4 2026-08-11
CVE-2026-73160
HIGH

Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied...

CVSS 8.7 2026-08-11
CVE-2026-72694
HIGH

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) f...

CVSS 7.1 2026-08-11
CVE-2026-72693
HIGH

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the owner...

CVSS 7.8 2026-08-11
CVE-2026-71217
HIGH

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`...

CVSS 7.5 2026-08-11
CVE-2026-15567
HIGH

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bound...

CVSS 7.5 2026-08-11
CVE-2026-15565
HIGH

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. T...

CVSS 7.5 2026-08-11
CVE-2026-15563
HIGH

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a ma...

CVSS 7.4 2026-08-11
CVE-2026-15562
HIGH

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM...

CVSS 7.5 2026-08-11
CVE-2026-15561
HIGH

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM...

CVSS 7.5 2026-08-11
CVE-2026-15560
HIGH

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to lo...

CVSS 8.1 2026-08-11
CVE-2026-15556
HIGH

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML resp...

CVSS 8.1 2026-08-11
CVE-2026-15555
HIGH

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filte...

CVSS 8.8 2026-08-11
1 444 445 446 447 448 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.