CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 469 of 500
CVE-2026-71314
HIGH

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArr...

CVSS 7.5 2026-08-05
CVE-2026-71312
HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShel...

CVSS 8 2026-08-05
CVE-2026-71309
HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly rejec...

CVSS 8.6 2026-08-05
CVE-2026-34966
HIGH

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in mig...

CVSS 7.6 2026-08-05
CVE-2026-18411
HIGH

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth ran...

CVSS 8.1 2026-08-05
CVE-2026-17583
HIGH

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DN...

CVSS 8.4 Thermofisher abi_prism_310_data_collection_software 2026-08-05
CVE-2026-15996
HIGH

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of req...

CVSS 7.5 Github enterprise_server 2026-08-05
CVE-2026-70617
HIGH

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by send...

CVSS 8.1 2026-08-05
CVE-2026-69111
HIGH

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP G...

CVSS 7.5 2026-08-05
CVE-2026-68746
HIGH

Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces ident...

CVSS 8.8 Livebook livebook 2026-08-05
CVE-2026-66881
HIGH

Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livem...

CVSS 8.1 Livebook livebook 2026-08-05
CVE-2026-66298
HIGH

Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation o...

CVSS 8.8 Livebook livebook 2026-08-05
CVE-2026-66297
HIGH

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment s...

CVSS 8 Livebook livebook 2026-08-05
CVE-2026-55524
HIGH

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be b...

CVSS 7.5 2026-08-05
CVE-2026-55523
HIGH

PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request for...

CVSS 7.7 2026-08-05
CVE-2026-55522
HIGH

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerabl...

CVSS 7.8 2026-08-05
CVE-2026-18958
HIGH

A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnera...

CVSS 7.3 2026-08-05
CVE-2026-18953
HIGH

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent ...

CVSS 8.8 Amazon aws_transform_mcp_server 2026-08-05
CVE-2026-9201
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. ...

CVSS 8.8 Langflow langflow 2026-08-05
CVE-2026-9196
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated...

CVSS 8.8 Langflow langflow 2026-08-05
1 467 468 469 470 471 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.