CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 473 of 500
CVE-2026-9651
MEDIUM

CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an att...

CVSS 6.7 2026-06-25
CVE-2026-57454
MEDIUM

Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose offset and length point outside t...

CVSS 6.1 Vim vim 2026-06-25
CVE-2026-57452
MEDIUM

Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05! method (xchacha20poly1305, requires the +s...

CVSS 5.5 Vim vim 2026-06-25
CVE-2026-57451
MEDIUM

Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns i...

CVSS 6.1 Vim vim 2026-06-25
CVE-2026-57438
MEDIUM

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each...

CVSS 6.6 Nokogiri nokogiri 2026-06-25
CVE-2026-55892
MEDIUM

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter whil...

CVSS 5.5 Vim vim 2026-06-25
CVE-2026-4522
MEDIUM

Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR Passwordless: before 11.1.1.

CVSS 6.7 2026-06-25
CVE-2026-48946
MEDIUM

The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2...

CVSS 6.3 Joomlaworks k2 2026-06-25
CVE-2026-48945
MEDIUM

The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — no...

CVSS 5.3 Joomlaworks k2 2026-06-25
CVE-2026-48944
MEDIUM

The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT ...

CVSS 6.5 Joomlaworks k2 2026-06-25
CVE-2026-48943
MEDIUM

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `p...

CVSS 6.5 Joomlaworks k2 2026-06-25
CVE-2026-48942
MEDIUM

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

CVSS 6.1 Joomlaworks k2 2026-06-25
CVE-2026-48941
MEDIUM

The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/...

CVSS 6.5 Joomlaworks k2 2026-06-25
CVE-2026-6432
MEDIUM

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

CVSS 5.3 2026-06-25
CVE-2026-57587
MEDIUM

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results ...

CVSS 5.3 Tenable nessus 2026-06-25
CVE-2026-57536
MEDIUM

Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it ...

CVSS 6.3 2026-06-25
CVE-2026-57437
MEDIUM

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its source document alive for garbage c...

CVSS 5.3 Nokogiri nokogiri 2026-06-25
CVE-2026-57436
MEDIUM

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was a Nokogiri::X...

CVSS 5.3 Nokogiri nokogiri 2026-06-25
CVE-2026-49319
MEDIUM

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling...

CVSS 6.5 2026-06-25
CVE-2026-13225
MEDIUM

Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that orde...

CVSS 5.3 2026-06-25
1 471 472 473 474 475 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.