CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 460 of 500
CVE-2026-14206
HIGH

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read ...

CVSS 7.5 2026-08-10
CVE-2026-13133
HIGH

A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, a...

CVSS 8.4 2026-08-10
CVE-2026-19389
HIGH

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WM...

CVSS 7.1 2026-08-10
CVE-2026-19387
HIGH

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sam...

CVSS 7.6 2026-08-10
CVE-2026-19384
HIGH

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointme...

CVSS 7.3 2026-08-10
CVE-2026-19381
HIGH

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the componen...

CVSS 7.8 2026-08-10
CVE-2026-19379
HIGH

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument...

CVSS 7.3 2026-08-10
CVE-2026-19376
HIGH

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The...

CVSS 7.3 2026-08-10
CVE-2026-19374
HIGH

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.t...

CVSS 7.3 2026-08-09
CVE-2026-19355
HIGH

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. ...

CVSS 7.3 2026-08-09
CVE-2026-19351
HIGH

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library l...

CVSS 7.3 2026-08-09
CVE-2026-19346
HIGH

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument N...

CVSS 8.8 2026-08-09
CVE-2026-19344
HIGH

A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manip...

CVSS 7.3 2026-08-09
CVE-2026-19343
HIGH

A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipul...

CVSS 7.3 2026-08-09
CVE-2026-19342
HIGH

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation o...

CVSS 7.3 2026-08-09
CVE-2026-19341
HIGH

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of th...

CVSS 8.8 2026-08-09
CVE-2026-18464
HIGH

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restric...

CVSS 7.5 2026-08-09
CVE-2026-18357
HIGH

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers ...

CVSS 7.5 2026-08-09
CVE-2026-17044
HIGH

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable ...

CVSS 8.6 2026-08-09
CVE-2026-18032
HIGH

The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does...

CVSS 7.5 2026-08-09
1 458 459 460 461 462 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.