CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 470 of 500
CVE-2026-1869
MEDIUM

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vul...

CVSS 6.5 2026-06-26
CVE-2026-8380
MEDIUM

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users wit...

CVSS 6.5 2026-06-26
CVE-2025-10268
MEDIUM

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the ...

CVSS 5.3 2026-06-26
CVE-2026-50745
MEDIUM

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the outpu...

CVSS 6.1 Revive-adserver revive_adserver 2026-06-26
CVE-2026-50742
MEDIUM

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names bein...

CVSS 5.4 Revive-adserver revive_adserver 2026-06-26
CVE-2026-50740
MEDIUM

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh param...

CVSS 5.4 Revive-adserver revive_adserver 2026-06-26
CVE-2026-48928
MEDIUM

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**...

CVSS 5.4 Nodejs node.js 2026-06-26
CVE-2026-48618
MEDIUM

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname ...

CVSS 6.5 Nodejs node.js 2026-06-26
CVE-2026-13226
MEDIUM

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and includi...

CVSS 6.5 2026-06-26
CVE-2026-9219
MEDIUM

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authenti...

CVSS 6.5 2026-06-26
CVE-2026-43920
MEDIUM

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible withou...

CVSS 6.9 2026-06-26
CVE-2026-13318
MEDIUM

A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api ...

CVSS 6.4 Kubevirt kubevirt 2026-06-26
CVE-2026-13083
MEDIUM

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrat...

CVSS 6.9 Redhat pen_drive 2026-06-26
CVE-2026-12993
MEDIUM

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECUR...

CVSS 6.5 Redhat build_of_apicurio_registry 2026-06-26
CVE-2026-40941
MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed pack...

CVSS 6.5 Cacti cacti 2026-06-25
CVE-2026-40084
MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing ar...

CVSS 6.5 Cacti cacti 2026-06-25
CVE-2026-40082
MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session...

CVSS 5.4 Cacti cacti 2026-06-25
CVE-2026-40080
MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at ...

CVSS 6.1 Cacti cacti 2026-06-25
CVE-2026-6330
MEDIUM

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that co...

CVSS 6.5 Wolfssl wolfssl 2026-06-25
CVE-2026-6329
MEDIUM

PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify pa...

CVSS 6.5 Wolfssl wolfssl 2026-06-25
1 468 469 470 471 472 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.