CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 478 of 500
CVE-2026-10824
MEDIUM

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanen...

CVSS 6.5 2026-06-25
CVE-2026-5309
MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have all...

CVSS 5.4 Gitlab gitlab 2026-06-25
CVE-2026-2238
MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have ...

CVSS 5.3 Gitlab gitlab 2026-06-25
CVE-2026-11379
MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in D...

CVSS 5.3 Gitlab gitlab 2026-06-25
CVE-2026-10712
MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have...

CVSS 6.1 Gitlab gitlab 2026-06-25
CVE-2026-10086
MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have all...

CVSS 5.4 Gitlab gitlab 2026-06-25
CVE-2026-2508
MEDIUM

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficien...

CVSS 6.5 2026-06-25
CVE-2026-12079
MEDIUM

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on...

CVSS 6.5 2026-06-25
CVE-2026-10833
MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block A...

CVSS 6.4 2026-06-25
CVE-2026-9154
MEDIUM

Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the ...

CVSS 6.5 Gnu sed 2026-06-25
CVE-2026-9153
MEDIUM

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficie...

CVSS 6.5 Gnu sed 2026-06-25
CVE-2025-60473
MEDIUM

A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service...

CVSS 5.5 Gpac gpac 2026-06-25
CVE-2025-60466
MEDIUM

A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via ...

CVSS 5 Gpac gpac 2026-06-25
CVE-2026-39900
MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php JavaScript c...

CVSS 6.1 Cacti cacti 2026-06-24
CVE-2026-39899
MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This is...

CVSS 5.3 Cacti cacti 2026-06-24
CVE-2026-9775
MEDIUM

ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of A...

CVSS 6.5 Aten unizon 2026-06-24
CVE-2026-9774
MEDIUM

ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations ...

CVSS 6.5 Aten unizon 2026-06-24
CVE-2026-54068
MEDIUM

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's kernel r...

CVSS 5.9 2026-06-24
CVE-2026-53766
MEDIUM

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces works...

CVSS 6.1 Google chrome-devtools-mcp 2026-06-24
CVE-2026-53765
MEDIUM

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon writes it...

CVSS 6.1 Google chrome-devtools-mcp 2026-06-24
1 476 477 478 479 480 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.