CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 448 of 500
CVE-2026-72910
HIGH

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, ...

CVSS 7.1 2026-08-10
CVE-2026-72909
HIGH

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/a...

CVSS 7.1 2026-08-10
CVE-2026-72903
HIGH

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tab...

CVSS 8.1 2026-08-10
CVE-2026-63622
HIGH

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFile...

CVSS 7.8 2026-08-10
CVE-2026-18982
HIGH

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Throug...

CVSS 8.8 2026-08-10
CVE-2026-18951
HIGH

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native ...

CVSS 8.8 2026-08-10
CVE-2026-18950
HIGH

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate...

CVSS 8.8 2026-08-10
CVE-2026-18949
HIGH

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions grante...

CVSS 8.8 2026-08-10
CVE-2026-18947
HIGH

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omit...

CVSS 8.5 2026-08-10
CVE-2026-18941
HIGH

A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This d...

CVSS 7.7 2026-08-10
CVE-2026-18621
HIGH

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 ...

CVSS 7.6 2026-08-10
CVE-2026-18620
HIGH

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifyin...

CVSS 7.1 2026-08-10
CVE-2026-18618
HIGH

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster att...

CVSS 7.5 2026-08-10
CVE-2026-18617
HIGH

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the in...

CVSS 8.8 2026-08-10
CVE-2026-18611
HIGH

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords ...

CVSS 7.5 2026-08-10
CVE-2026-18608
HIGH

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary fo...

CVSS 8.7 2026-08-10
CVE-2026-15581
HIGH

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API...

CVSS 8 2026-08-10
CVE-2026-15467
HIGH

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container...

CVSS 8.1 2026-08-10
CVE-2026-13717
HIGH

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to in...

CVSS 8.8 2026-08-10
CVE-2026-11810
HIGH

The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fi...

CVSS 7.5 2026-08-10
1 446 447 448 449 450 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.