CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 476 of 500
CVE-2026-64567
HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 free space cache, __load_free_sp...

CVSS 7.8 2026-08-05
CVE-2026-61483
HIGH

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan ...

CVSS 7.5 Apache lucy 2026-08-05
CVE-2026-61485
HIGH

** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired...

CVSS 7.5 Apache lucy 2026-08-05
CVE-2026-59675
HIGH

When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is ...

CVSS 7.5 2026-08-05
CVE-2026-55997
HIGH

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, s...

CVSS 8.8 2026-08-05
CVE-2026-55739
HIGH

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/up...

CVSS 8.3 2026-08-05
CVE-2026-54418
HIGH

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parame...

CVSS 8.1 2026-08-05
CVE-2026-54416
HIGH

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','ph...

CVSS 7.2 2026-08-05
CVE-2026-18881
HIGH

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_t...

CVSS 7.5 2026-08-05
CVE-2026-12000
HIGH

The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-j...

CVSS 7.5 2026-08-05
CVE-2026-70375
HIGH

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js...

CVSS 8.8 2026-08-05
CVE-2026-70374
HIGH

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail in src/Server/Entity/R...

CVSS 8.8 2026-08-05
CVE-2026-68073
HIGH

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through ...

CVSS 7.5 Apache qpid_broker-j 2026-08-05
CVE-2026-67590
HIGH

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through ...

CVSS 7.5 Apache qpid_protonj2 2026-08-05
CVE-2026-67552
HIGH

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet thro...

CVSS 7.5 Apache qpid_proton-dotnet 2026-08-05
CVE-2026-67592
HIGH

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial...

CVSS 7.5 Apache qpid_protonj2 2026-08-05
CVE-2026-66274
HIGH

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through ...

CVSS 7.5 Apache qpid_proton-j 2026-08-05
CVE-2026-16736
HIGH

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing ...

CVSS 7.5 2026-08-05
CVE-2026-16605
HIGH

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (St...

CVSS 7.2 2026-08-05
CVE-2026-16604
HIGH

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to re...

CVSS 7.5 2026-08-05
1 474 475 476 477 478 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.