CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 474 of 500
CVE-2026-46581
HIGH

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to ...

CVSS 7.5 Eclipse mojarra 2026-08-05
CVE-2026-18933
HIGH

The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to uploa...

CVSS 7.2 2026-08-05
CVE-2026-71252
HIGH

toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed I...

CVSS 8.2 2026-08-05
CVE-2026-71245
HIGH

Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with InputHelper::clean (which HTML-ent...

CVSS 7.1 2026-08-05
CVE-2026-71243
HIGH

The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = "mkdir -p " + path.join(info.d...

CVSS 8.8 2026-08-05
CVE-2026-71242
HIGH

Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies ...

CVSS 8.3 2026-08-05
CVE-2026-71241
HIGH

Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling ro...

CVSS 7.5 2026-08-05
CVE-2026-71239
HIGH

DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: me...

CVSS 8.1 2026-08-05
CVE-2026-71236
HIGH

Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HT...

CVSS 8.7 2026-08-05
CVE-2026-71235
HIGH

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go...

CVSS 8.8 2026-08-05
CVE-2026-71234
HIGH

Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and gr...

CVSS 7.5 2026-08-05
CVE-2026-71233
HIGH

InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020...

CVSS 8.7 2026-08-05
CVE-2026-71232
HIGH

MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exe...

CVSS 7.2 2026-08-05
CVE-2026-60009
HIGH

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacke...

CVSS 8.8 Eclipse theia 2026-08-05
CVE-2026-12609
HIGH

In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the req...

CVSS 7.5 Eclipse theia 2026-08-05
CVE-2026-25703
HIGH

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

CVSS 7.3 2026-08-05
CVE-2026-7693
HIGH

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST pa...

CVSS 7.2 2026-08-05
CVE-2026-7520
HIGH

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX h...

CVSS 8.1 2026-08-05
CVE-2026-7444
HIGH

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce...

CVSS 8.1 2026-08-05
CVE-2026-71215
HIGH

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via p...

CVSS 7.5 2026-08-05
1 472 473 474 475 476 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.