CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 457 of 500
CVE-2026-47659
HIGH

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` e...

CVSS 8.7 2026-08-07
CVE-2026-15972
HIGH

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external g...

CVSS 7.5 2026-08-07
CVE-2026-71847
HIGH

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start,...

CVSS 8.7 2026-08-07
CVE-2026-48098
HIGH

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using...

CVSS 7.3 2026-08-07
CVE-2026-48097
HIGH

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability d...

CVSS 7.8 2026-08-07
CVE-2026-19231
HIGH

A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appoi...

CVSS 7.3 2026-08-07
CVE-2026-11430
HIGH

Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound ...

CVSS 7.3 2026-08-07
CVE-2025-71412
HIGH

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic con...

CVSS 7.1 2026-08-07
CVE-2025-71409
HIGH

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential...

CVSS 7.1 2026-08-07
CVE-2025-63235
HIGH

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - ei...

CVSS 7.5 2026-08-07
CVE-2026-64638
HIGH

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possibl...

CVSS 8.9 2026-08-07
CVE-2026-64636
HIGH

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

CVSS 7.7 2026-08-07
CVE-2026-19082
HIGH

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags()...

CVSS 7.5 2026-08-07
CVE-2026-71556
HIGH

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic...

CVSS 7.1 2026-08-07
CVE-2026-68772
HIGH

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute a...

CVSS 8 2026-08-07
CVE-2026-67585
HIGH

Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _e...

CVSS 8.7 2026-08-07
CVE-2026-20348
HIGH

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&n...

CVSS 7.5 Cisco secure_endpoint 2026-08-07
CVE-2026-20347
HIGH

A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result o...

CVSS 7.5 2026-08-07
CVE-2026-20346
HIGH

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&n...

CVSS 7.5 2026-08-07
CVE-2026-20345
HIGH

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&n...

CVSS 7.5 2026-08-07
1 455 456 457 458 459 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.