CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 447 of 500
CVE-2026-15554
HIGH

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct...

CVSS 7.4 2026-08-11
CVE-2026-19418
HIGH

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool app...

CVSS 7.3 2026-08-11
CVE-2026-16053
HIGH

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

CVSS 8.5 2026-08-11
CVE-2026-4757
HIGH

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authentic...

CVSS 7.2 2026-08-11
CVE-2026-8917
HIGH

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary mem...

CVSS 8.4 2026-08-11
CVE-2026-19424
HIGH

Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other ...

CVSS 7.5 2026-08-11
CVE-2026-66763
HIGH

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high pri...

CVSS 7.9 2026-08-11
CVE-2026-58243
HIGH

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database oper...

CVSS 8.8 2026-08-11
CVE-2026-58230
HIGH

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitiv...

CVSS 7 Sap approuter 2026-08-11
CVE-2026-44765
HIGH

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application...

CVSS 7.3 2026-08-11
CVE-2026-44764
HIGH

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet us...

CVSS 7.3 2026-08-11
CVE-2026-44763
HIGH

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploit...

CVSS 7.6 2026-08-11
CVE-2026-8718
HIGH

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval d...

CVSS 8.4 2026-08-10
CVE-2025-30241
HIGH

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution fu...

CVSS 8.6 2026-08-10
CVE-2025-30239
HIGH

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to dev...

CVSS 8.5 2026-08-10
CVE-2025-30238
HIGH

In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may pe...

CVSS 8.6 2026-08-10
CVE-2025-30237
HIGH

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can s...

CVSS 8.7 2026-08-10
CVE-2026-72915
HIGH

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in ap...

CVSS 7.5 2026-08-10
CVE-2026-72914
HIGH

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api...

CVSS 7.5 2026-08-10
CVE-2026-73030
HIGH

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowi...

CVSS 8.1 2026-08-10
1 445 446 447 448 449 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.