CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 467 of 500
CVE-2026-28177
HIGH

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

CVSS 7.1 2026-08-06
CVE-2026-28172
HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

CVSS 7.1 2026-08-06
CVE-2026-28143
HIGH

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

CVSS 7.1 2026-08-06
CVE-2026-28141
HIGH

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

CVSS 7.1 2026-08-06
CVE-2026-28140
HIGH

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

CVSS 7.5 2026-08-06
CVE-2026-28111
HIGH

Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

CVSS 8.8 2026-08-06
CVE-2026-28082
HIGH

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

CVSS 7.1 2026-08-06
CVE-2025-49506
HIGH

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via ...

CVSS 7.5 Apache apr-util 2026-08-06
CVE-2026-16731
HIGH

OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attack...

CVSS 8.3 2026-08-06
CVE-2026-16315
HIGH

OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attack...

CVSS 8.7 2026-08-06
CVE-2026-66733
HIGH

Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to c...

CVSS 7.5 2026-08-06
CVE-2026-65551
HIGH

Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2....

CVSS 7.5 2026-08-06
CVE-2026-19036
HIGH

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom re...

CVSS 7.2 2026-08-06
CVE-2026-68481
HIGH

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh...

CVSS 7.5 Apache cxf 2026-08-06
CVE-2026-57818
HIGH

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple di...

CVSS 8.1 Apache cxf 2026-08-06
CVE-2026-19035
HIGH

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new...

CVSS 7.2 2026-08-06
CVE-2025-15028
HIGH

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submissio...

CVSS 7.2 2026-08-06
CVE-2026-65432
HIGH

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from tha...

CVSS 7.5 Apache cxf 2026-08-06
CVE-2026-64958
HIGH

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users ar...

CVSS 7.5 Apache cxf 2026-08-06
CVE-2026-57819
HIGH

Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which m...

CVSS 7.5 Apache cxf 2026-08-06
1 465 466 467 468 469 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.