CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 475 of 500
CVE-2026-71211
HIGH

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or ...

CVSS 7.1 2026-08-05
CVE-2026-71209
HIGH

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cove...

CVSS 7.5 2026-08-05
CVE-2026-71206
HIGH

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the acc...

CVSS 8.3 2026-08-05
CVE-2026-71202
HIGH

The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never again...

CVSS 7.5 2026-08-05
CVE-2026-70378
HIGH

imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target w...

CVSS 7.5 2026-08-05
CVE-2026-70377
HIGH

imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplie...

CVSS 7.5 2026-08-05
CVE-2026-6639
HIGH

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `g...

CVSS 7.5 2026-08-05
CVE-2026-6627
HIGH

The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up...

CVSS 8.2 2026-08-05
CVE-2026-6147
HIGH

The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and i...

CVSS 8.8 2026-08-05
CVE-2026-6079
HIGH

The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() fun...

CVSS 7.3 2026-08-05
CVE-2026-6020
HIGH

The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3....

CVSS 7.2 2026-08-05
CVE-2026-64581
HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with _...

CVSS 7.8 2026-08-05
CVE-2026-64580
HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() On the error path where in6_dev_g...

CVSS 7.8 2026-08-05
CVE-2026-64578
HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd validates a compound (chained) ...

CVSS 8.2 2026-08-05
CVE-2026-64577
HIGH

In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_resp() ignores skb_pull_data()'s r...

CVSS 7.5 2026-08-05
CVE-2026-64576
HIGH

In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() nh_res_bucket_migrate() passes an uninitialized netlink_...

CVSS 7.1 2026-08-05
CVE-2026-64575
HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() releases the current batch via bpf_ite...

CVSS 7.8 2026-08-05
CVE-2026-64574
HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update error path When ieee80211_vif_update_links() adds new links ...

CVSS 7.8 2026-08-05
CVE-2026-64570
HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on alloc failure ieee80211_set_fils_discovery() calls kfree_rcu...

CVSS 7.8 2026-08-05
CVE-2026-64568
HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure ieee80211_set_unsol_bcast_probe_resp()...

CVSS 7.8 2026-08-05
1 473 474 475 476 477 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.