CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 455 of 500
CVE-2026-19342
HIGH

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation o...

CVSS 7.3 2026-08-09
CVE-2026-19341
HIGH

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of th...

CVSS 8.8 2026-08-09
CVE-2026-18464
HIGH

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restric...

CVSS 7.5 2026-08-09
CVE-2026-18357
HIGH

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers ...

CVSS 7.5 2026-08-09
CVE-2026-17044
HIGH

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable ...

CVSS 8.6 2026-08-09
CVE-2026-18032
HIGH

The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does...

CVSS 7.5 2026-08-09
CVE-2026-17017
HIGH

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not includ...

CVSS 8.1 2026-08-09
CVE-2026-16988
HIGH

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated u...

CVSS 7.5 2026-08-09
CVE-2026-10595
HIGH

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises fro...

CVSS 7.5 2026-08-09
CVE-2026-17510
HIGH

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destina...

CVSS 7.5 2026-08-09
CVE-2026-67620
HIGH

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infr...

CVSS 7.7 Flowiseai flowise 2026-08-08
CVE-2026-42170
HIGH

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-p...

CVSS 7.8 Redhat enterprise_linux 2026-08-08
CVE-2026-16948
HIGH

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable b...

CVSS 8.1 2026-08-08
CVE-2026-19263
HIGH

A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the ...

CVSS 7.3 2026-08-08
CVE-2026-16589
HIGH

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which ...

CVSS 7.7 2026-08-08
CVE-2026-16594
HIGH

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as ...

CVSS 7.5 2026-08-08
CVE-2026-16578
HIGH

The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpo...

CVSS 7.5 2026-08-08
CVE-2026-16267
HIGH

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attacker...

CVSS 8.1 2026-08-08
CVE-2026-13505
HIGH

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engi...

CVSS 8.7 2026-08-08
CVE-2026-8798
HIGH

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSEED and R...

CVSS 8.7 2026-08-08
1 453 454 455 456 457 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.