CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 474 of 500
CVE-2026-13223
MEDIUM

Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from on...

CVSS 6.3 2026-06-25
CVE-2026-13222
MEDIUM

Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one p...

CVSS 6.3 2026-06-25
CVE-2026-57619
MEDIUM

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

CVSS 6.5 2026-06-25
CVE-2026-57429
MEDIUM

Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

CVSS 6.5 2026-06-25
CVE-2026-56050
MEDIUM

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCom...

CVSS 6.5 2026-06-25
CVE-2026-56023
MEDIUM

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

CVSS 5.4 2026-06-25
CVE-2026-56013
MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

CVSS 6.5 2026-06-25
CVE-2026-52690
MEDIUM

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

CVSS 5.9 2026-06-25
CVE-2026-4526
MEDIUM

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a...

CVSS 6.5 Silabs emberznet 2026-06-25
CVE-2026-47154
MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages m...

CVSS 6.5 Silabs emberznet 2026-06-25
CVE-2026-47153
MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has alre...

CVSS 6.5 Silabs emberznet 2026-06-25
CVE-2026-47152
MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has alre...

CVSS 6.5 Silabs emberznet 2026-06-25
CVE-2026-47149
MEDIUM

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from...

CVSS 6.5 Silabs emberznet 2026-06-25
CVE-2026-47148
MEDIUM

In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must...

CVSS 6.5 Silabs emberznet 2026-06-25
CVE-2026-47146
MEDIUM

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the...

CVSS 6.5 Silabs emberznet 2026-06-25
CVE-2026-47145
MEDIUM

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the...

CVSS 6.5 Silabs emberznet 2026-06-25
CVE-2026-42390
MEDIUM

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

CVSS 5.3 2026-06-25
CVE-2026-42389
MEDIUM

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

CVSS 5.3 2026-06-25
CVE-2026-42388
MEDIUM

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

CVSS 5.9 2026-06-25
CVE-2026-42387
MEDIUM

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.

CVSS 5.9 2026-06-25
1 472 473 474 475 476 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.