CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 477 of 500
CVE-2026-16603
HIGH

The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full conten...

CVSS 7.5 2026-08-05
CVE-2026-16602
HIGH

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users...

CVSS 7.5 2026-08-05
CVE-2026-16573
HIGH

The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file contain...

CVSS 7.5 2026-08-05
CVE-2026-16561
HIGH

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments o...

CVSS 7.5 2026-08-05
CVE-2026-16055
HIGH

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly...

CVSS 7.5 2026-08-05
CVE-2026-16036
HIGH

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor...

CVSS 7.5 2026-08-05
CVE-2026-15372
HIGH

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who alread...

CVSS 7.5 2026-08-05
CVE-2026-15230
HIGH

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user ...

CVSS 8.1 2026-08-05
CVE-2026-14553
HIGH

The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing...

CVSS 8.1 2026-08-05
CVE-2026-8761
HIGH

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersCont...

CVSS 8.8 2026-08-05
CVE-2026-71190
HIGH

In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]...

CVSS 8.7 2026-08-05
CVE-2026-68074
HIGH

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: thr...

CVSS 7.5 Apache qpid_broker-j 2026-08-05
CVE-2026-68060
HIGH

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J...

CVSS 7.5 Apache qpid_broker-j 2026-08-05
CVE-2026-67589
HIGH

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2...

CVSS 7.5 Apache qpid_protonj2 2026-08-05
CVE-2026-67588
HIGH

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: thr...

CVSS 7.5 Apache qpid_protonj2 2026-08-05
CVE-2026-67551
HIGH

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dot...

CVSS 7.5 Apache qpid_proton-dotnet 2026-08-05
CVE-2026-67465
HIGH

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet...

CVSS 7.5 Apache qpid_proton-dotnet 2026-08-05
CVE-2026-66273
HIGH

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J...

CVSS 7.5 Apache qpid_proton-j 2026-08-05
CVE-2026-66257
HIGH

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: thr...

CVSS 7.5 Apache qpid_proton-j 2026-08-05
CVE-2026-55707
HIGH

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's ...

CVSS 7.1 2026-08-05
1 475 476 477 478 479 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.