CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 471 of 500
CVE-2026-6092
MEDIUM

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

CVSS 5.3 Wolfssl wolfssl 2026-06-25
CVE-2026-55962
MEDIUM

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The po...

CVSS 6.5 Wolfssl wolfssl 2026-06-25
CVE-2026-44622
MEDIUM

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

CVSS 6.5 2026-06-25
CVE-2026-13282
MEDIUM

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (C...

CVSS 6.8 Google chrome 2026-06-25
CVE-2026-10098
MEDIUM

OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the ...

CVSS 5.3 Wolfssl wolfssl 2026-06-25
CVE-2020-37256
MEDIUM

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can...

CVSS 5.4 Getgrav grav 2026-06-25
CVE-2026-6681
MEDIUM

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSS...

CVSS 5.3 Wolfssl wolfssl 2026-06-25
CVE-2026-6678
MEDIUM

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

CVSS 5.3 Wolfssl wolfssl 2026-06-25
CVE-2026-6450
MEDIUM

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to be...

CVSS 5.3 Wolfssl wolfssl 2026-06-25
CVE-2026-57522
MEDIUM

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integr...

CVSS 5 Bitwarden server 2026-06-25
CVE-2026-55964
MEDIUM

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage extension is p...

CVSS 5.3 Wolfssl wolfssl 2026-06-25
CVE-2026-10592
MEDIUM

Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rejected by the issuing CA's permi...

CVSS 5.3 Wolfssl wolfssl 2026-06-25
CVE-2025-60465
MEDIUM

A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via s...

CVSS 6.1 Gpac gpac 2026-06-25
CVE-2026-56789
MEDIUM

RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allows attackers to trigger memory corruption by failing to clamp...

CVSS 6.5 Rtklib rtklib 2026-06-25
CVE-2026-56779
MEDIUM

MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by ...

CVSS 6.4 2026-06-25
CVE-2026-56774
MEDIUM

Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, ...

CVSS 5.4 2026-06-25
CVE-2026-54250
MEDIUM

K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot d...

CVSS 5.8 2026-06-25
CVE-2026-54093
MEDIUM

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, filebrowser builds the dow...

CVSS 6.8 2026-06-25
CVE-2026-54092
MEDIUM

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximu...

CVSS 6.5 2026-06-25
CVE-2026-46611
MEDIUM

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTT...

CVSS 5.3 2026-06-25
1 469 470 471 472 473 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.