CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 458 of 500
CVE-2026-20339
HIGH

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result o...

CVSS 7.5 2026-08-07
CVE-2026-20338
HIGH

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to ...

CVSS 7.5 2026-08-07
CVE-2026-20337
HIGH

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to ...

CVSS 7.5 2026-08-07
CVE-2026-19211
HIGH

A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the a...

CVSS 7.3 2026-08-07
CVE-2026-17603
HIGH

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-up...

CVSS 8.7 2026-08-07
CVE-2026-17601
HIGH

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authori...

CVSS 8.9 2026-08-07
CVE-2026-17600
HIGH

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had...

CVSS 8.7 2026-08-07
CVE-2026-17594
HIGH

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user acc...

CVSS 8.2 2026-08-07
CVE-2026-17593
HIGH

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary ...

CVSS 7.2 2026-08-07
CVE-2026-14644
HIGH

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role c...

CVSS 8.6 2026-08-07
CVE-2026-18497
HIGH

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the ...

CVSS 7.1 2026-08-07
CVE-2026-15570
HIGH

An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 ...

CVSS 7.1 2026-08-07
CVE-2026-66838
HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex....

CVSS 8.2 Elixir-ecto postgrex 2026-08-07
CVE-2026-66494
HIGH

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joom...

CVSS 8.7 2026-08-07
CVE-2026-15816
HIGH

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it....

CVSS 7.5 2026-08-07
CVE-2026-71559
HIGH

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malform...

CVSS 7.5 Apache fory 2026-08-07
CVE-2026-54218
HIGH

Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only...

CVSS 8.8 2026-08-07
CVE-2026-54209
HIGH

Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new pas...

CVSS 8.9 2026-08-07
CVE-2026-54208
HIGH

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the ser...

CVSS 8.5 2026-08-07
CVE-2026-54204
HIGH

Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”...

CVSS 7.7 2026-08-07
1 456 457 458 459 460 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.