CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 461 of 500
CVE-2026-67687
HIGH

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/updat...

CVSS 8.8 2026-08-06
CVE-2026-67621
HIGH

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unpr...

CVSS 7.6 Flowiseai flowise 2026-08-06
CVE-2026-67434
HIGH

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vu...

CVSS 7.3 2026-08-06
CVE-2026-67422
HIGH

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclin...

CVSS 7.5 2026-08-06
CVE-2026-64665
HIGH

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified ema...

CVSS 8.1 2026-08-06
CVE-2026-63725
HIGH

sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-concatenating the backup directory...

CVSS 7.2 2026-08-06
CVE-2026-63637
HIGH

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without q...

CVSS 8.6 2026-08-06
CVE-2026-62857
HIGH

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance line...

CVSS 8.8 2026-08-06
CVE-2026-5857
HIGH

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic...

CVSS 8.1 2026-08-06
CVE-2026-5856
HIGH

Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in...

CVSS 7.1 2026-08-06
CVE-2026-5855
HIGH

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer w...

CVSS 7.5 2026-08-06
CVE-2026-53983
HIGH

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated S...

CVSS 8.6 2026-08-06
CVE-2026-48084
HIGH

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts....

CVSS 7.4 2026-08-06
CVE-2026-48081
HIGH

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in t...

CVSS 8.1 2026-08-06
CVE-2026-48080
HIGH

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the...

CVSS 8 2026-08-06
CVE-2026-48079
HIGH

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the...

CVSS 7.4 2026-08-06
CVE-2026-48054
HIGH

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test...

CVSS 8.8 2026-08-06
CVE-2026-47765
HIGH

Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, all...

CVSS 7.1 2026-08-06
CVE-2026-47194
HIGH

Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing ...

CVSS 8.6 2026-08-06
CVE-2026-45414
HIGH

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the ...

CVSS 8.5 2026-08-06
1 459 460 461 462 463 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.