CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 468 of 500
CVE-2026-53280
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu: Fix NULL group->domain dereference in pci_dev_reset_iommu_done() Local sashiko review pointed it out th...

CVSS 5.5 Linux linux_kernel 2026-06-26
CVE-2026-53279
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/gma500/oaktrail_lvds: fix hang on init failure The LVDS init code looks up an I2C adapter using i2c_get_ad...

CVSS 5.5 Linux linux_kernel 2026-06-26
CVE-2026-53278
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Check whether the config array is allocated before destroying it __destroy_component_cfg() is called...

CVSS 5.5 Linux linux_kernel 2026-06-26
CVE-2026-52781
MEDIUM

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants <macro> elements unrestricted data-* attributes via :data w...

CVSS 6.4 2026-06-26
CVE-2026-52779
MEDIUM

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion in the Calendar and Team Plann...

CVSS 5.4 2026-06-26
CVE-2026-44736
MEDIUM

OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the...

CVSS 6.5 2026-06-26
CVE-2026-44735
MEDIUM

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares endpoint returns share details for ALL work packages in a proj...

CVSS 6.5 2026-06-26
CVE-2026-44734
MEDIUM

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. ...

CVSS 6.5 2026-06-26
CVE-2026-44733
MEDIUM

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits...

CVSS 5.9 2026-06-26
CVE-2026-44696
MEDIUM

OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Sanitize::Config::RELAXED[:css] for i...

CVSS 5.7 2026-06-26
CVE-2026-29509
MEDIUM

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_withi...

CVSS 5.4 2026-06-26
CVE-2026-54753
MEDIUM

Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local HTTP server started by nx graph sent Access-Control-Allow-Ori...

CVSS 5.9 2026-06-26
CVE-2026-48090
MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can l...

CVSS 5.9 Envoyproxy envoy 2026-06-26
CVE-2026-47205
MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to...

CVSS 5.9 Envoyproxy envoy 2026-06-26
CVE-2026-55448
MEDIUM

mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local project config before any trust decis...

CVSS 6.3 2026-06-26
CVE-2026-54557
MEDIUM

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string...

CVSS 5.5 2026-06-26
CVE-2026-47775
MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() fu...

CVSS 6.8 Envoyproxy envoy 2026-06-26
CVE-2026-47207
MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server se...

CVSS 6.5 Envoyproxy envoy 2026-06-26
CVE-2026-56823
MEDIUM

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_...

CVSS 5.4 2026-06-26
CVE-2026-55686
MEDIUM

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory ...

CVSS 5.3 Podman_project podman 2026-06-26
1 466 467 468 469 470 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.