CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 464 of 500
CVE-2026-16620
HIGH

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an u...

CVSS 7.5 2026-08-06
CVE-2026-16619
HIGH

The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that...

CVSS 7.5 2026-08-06
CVE-2026-13399
HIGH

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass pay...

CVSS 7.5 2026-08-06
CVE-2026-12584
HIGH

The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment m...

CVSS 7.5 2026-08-06
CVE-2026-11803
HIGH

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to ca...

CVSS 7.8 Autodesk revit 2026-08-06
CVE-2026-10599
HIGH

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it v...

CVSS 7.5 2026-08-06
CVE-2026-10524
HIGH

The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public R...

CVSS 7.5 2026-08-06
CVE-2024-39024
HIGH

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

CVSS 8.8 2026-08-06
CVE-2026-68750
HIGH

Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a...

CVSS 7.5 Rrrene htmlsanitizeex 2026-08-06
CVE-2026-68749
HIGH

Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CS...

CVSS 7.5 Rrrene htmlsanitizeex 2026-08-06
CVE-2026-5423
HIGH

@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As...

CVSS 8.2 2026-08-06
CVE-2026-53985
HIGH

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated ne...

CVSS 7.5 2026-08-06
CVE-2026-53977
HIGH

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /ap...

CVSS 7.5 2026-08-06
CVE-2026-43622
HIGH

llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() dea...

CVSS 7.8 Ggml llama.cpp 2026-08-06
CVE-2026-3430
HIGH

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when t...

CVSS 8.6 2026-08-06
CVE-2026-18427
HIGH

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not ...

CVSS 7.5 Fastify fastify-static 2026-08-06
CVE-2026-18359
HIGH

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary H...

CVSS 8.5 Escriptorium escriptorium 2026-08-06
CVE-2026-18277
HIGH

Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another ...

CVSS 7.1 Escriptorium escriptorium 2026-08-06
CVE-2026-18258
HIGH

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to ...

CVSS 8.8 Escriptorium escriptorium 2026-08-06
CVE-2026-70646
HIGH

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMA...

CVSS 7.5 2026-08-06
1 462 463 464 465 466 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.