CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 472 of 500
CVE-2026-28898
MEDIUM

swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1....

CVSS 5.3 Apple swiftnio_http\/2 2026-06-25
CVE-2026-6291
MEDIUM

Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes depe...

CVSS 6.5 Wolfssl wolfssl 2026-06-25
CVE-2026-6091
MEDIUM

Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted anchor. An attacker could prese...

CVSS 6.5 Wolfssl wolfssl 2026-06-25
CVE-2026-55699
MEDIUM

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed glob...

CVSS 6.5 Pnpm pnpm 2026-06-25
CVE-2026-55180
MEDIUM

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry re...

CVSS 6.5 Pnpm pnpm 2026-06-25
CVE-2026-54679
MEDIUM

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. Thi...

CVSS 5.5 Jqlang jq 2026-06-25
CVE-2026-50017
MEDIUM

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a repository-local .npmrc file. In ...

CVSS 6.5 Pnpm pnpm 2026-06-25
CVE-2026-47770
MEDIUM

jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface...

CVSS 5.5 Jqlang jq 2026-06-25
CVE-2026-9705
MEDIUM

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to r...

CVSS 6.5 Redhat build_of_keycloak 2026-06-25
CVE-2026-55439
MEDIUM

Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated administrators to read arbitrary ...

CVSS 5.5 2026-06-25
CVE-2026-55411
MEDIUM

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint P...

CVSS 6.8 2026-06-25
CVE-2026-54573
MEDIUM

Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to verify if an API key or OAuth ...

CVSS 5.3 2026-06-25
CVE-2026-54448
MEDIUM

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attac...

CVSS 6.5 Aquasec trivy 2026-06-25
CVE-2026-54037
MEDIUM

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-7105 added forkIpLimiter and forkUserLimiter rate limiters to P...

CVSS 6.5 Librechat librechat 2026-06-25
CVE-2026-54033
MEDIUM

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-compatible API endpoints by settin...

CVSS 6.5 Librechat librechat 2026-06-25
CVE-2026-54029
MEDIUM

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticate...

CVSS 6.5 Librechat librechat 2026-06-25
CVE-2026-54027
MEDIUM

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files in...

CVSS 6.5 Librechat librechat 2026-06-25
CVE-2026-54025
MEDIUM

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown artifact preview pipeline. The mark...

CVSS 5.4 Librechat librechat 2026-06-25
CVE-2026-54024
MEDIUM

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-11171 (commit bb58a2d0) added limits: { fileSize } to createMul...

CVSS 6.5 Librechat librechat 2026-06-25
CVE-2026-9718
MEDIUM

CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially...

CVSS 6.5 Schneider-electric powerlogic_p7_firmware 2026-06-25
1 470 471 472 473 474 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.