CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 472 of 500
CVE-2026-48834
HIGH

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial ...

CVSS 7.5 Apache answer 2026-08-05
CVE-2026-39923
HIGH

Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them dir...

CVSS 8.1 2026-08-05
CVE-2026-15572
HIGH

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers...

CVSS 8.8 Redhat build_of_keycloak 2026-08-05
CVE-2026-13477
HIGH

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privil...

CVSS 8.8 Ibm qradar_security_information_and_event_manager 2026-08-05
CVE-2026-54876
HIGH

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response e...

CVSS 7.5 2026-08-05
CVE-2026-17613
HIGH

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscri...

CVSS 7.5 2026-08-05
CVE-2026-16102
HIGH

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the c...

CVSS 8.1 Redhat build_of_keycloak 2026-08-05
CVE-2026-15573
HIGH

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs befo...

CVSS 8.1 Redhat build_of_keycloak 2026-08-05
CVE-2026-12410
HIGH

Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a s...

CVSS 7.8 2026-08-05
CVE-2026-7529
HIGH

The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoin...

CVSS 7.5 2026-08-05
CVE-2026-67623
HIGH

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repo...

CVSS 8.8 2026-08-05
CVE-2026-17506
HIGH

The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. T...

CVSS 7.2 2026-08-05
CVE-2026-15979
HIGH

The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11....

CVSS 8.1 2026-08-05
CVE-2025-70962
HIGH

Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with netwo...

CVSS 7.5 2026-08-05
CVE-2026-71294
HIGH

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a ...

CVSS 7.6 2026-08-05
CVE-2026-71292
HIGH

Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists the (ASC/DESC) request parameter via in_array, but falls back ...

CVSS 7.2 2026-08-05
CVE-2026-71291
HIGH

Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTw...

CVSS 8.8 2026-08-05
CVE-2026-71288
HIGH

Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-named parameter, and concatenates both directly into an SQL ORDE...

CVSS 8.8 2026-08-05
CVE-2026-71287
HIGH

Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parenthe...

CVSS 8.8 2026-08-05
CVE-2026-71285
HIGH

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted JavaScript expression inside a <sc...

CVSS 8.1 2026-08-05
1 470 471 472 473 474 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.