CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 469 of 500
CVE-2026-48529
MEDIUM

GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-...

CVSS 6 2026-06-26
CVE-2026-45407
MEDIUM

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creat...

CVSS 5.5 Dokku dokku 2026-06-26
CVE-2026-28385
MEDIUM

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_imag...

CVSS 5 Canonical lxd 2026-06-26
CVE-2026-11779
MEDIUM

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

CVSS 5.3 2026-06-26
CVE-2025-32423
MEDIUM

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractT...

CVSS 5.3 2026-06-26
CVE-2025-32394
MEDIUM

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSu...

CVSS 5.3 2026-06-26
CVE-2026-9639
MEDIUM

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause...

CVSS 6.5 Canonical lxd 2026-06-26
CVE-2023-20572
MEDIUM

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an...

CVSS 5.6 2026-06-26
CVE-2026-9699
MEDIUM

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or s...

CVSS 6.8 2026-06-26
CVE-2026-57665
MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.

CVSS 5.3 2026-06-26
CVE-2026-57661
MEDIUM

Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.

CVSS 5.4 2026-06-26
CVE-2026-57660
MEDIUM

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.

CVSS 5.3 2026-06-26
CVE-2026-57656
MEDIUM

Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.

CVSS 5.9 2026-06-26
CVE-2026-57654
MEDIUM

Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

CVSS 6.5 2026-06-26
CVE-2026-57652
MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.

CVSS 5.3 2026-06-26
CVE-2026-57651
MEDIUM

Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.

CVSS 6.5 2026-06-26
CVE-2026-57650
MEDIUM

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.

CVSS 6.5 2026-06-26
CVE-2026-57646
MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.

CVSS 5.4 2026-06-26
CVE-2026-57641
MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

CVSS 6.5 2026-06-26
CVE-2026-57638
MEDIUM

Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

CVSS 6.5 2026-06-26
1 467 468 469 470 471 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.