CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 479 of 500
CVE-2026-67856
HIGH

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubs...

CVSS 7.5 2026-08-04
CVE-2026-67855
HIGH

open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause ...

CVSS 7.5 2026-08-04
CVE-2026-67857
HIGH

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

CVSS 7.5 2026-08-04
CVE-2026-45103
HIGH

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header usin...

CVSS 7.5 2026-08-04
CVE-2026-45084
HIGH

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the prese...

CVSS 8.7 2026-08-04
CVE-2026-18814
HIGH

A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can ...

CVSS 7.2 2026-08-04
CVE-2026-70494
HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/router...

CVSS 8.1 Openwebui open_webui 2026-08-04
CVE-2026-66901
HIGH

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library...

CVSS 7.5 2026-08-04
CVE-2026-51401
HIGH

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

CVSS 7.7 Vim vim 2026-08-04
CVE-2026-51400
HIGH

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

CVSS 8.4 Vim vim 2026-08-04
CVE-2026-65986
HIGH

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annot...

CVSS 8.5 2026-08-04
CVE-2026-18813
HIGH

A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command inj...

CVSS 7.2 2026-08-04
CVE-2026-18812
HIGH

A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to ...

CVSS 7.2 2026-08-04
CVE-2026-18811
HIGH

A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url results...

CVSS 7.2 2026-08-04
CVE-2026-13227
HIGH

An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.pros...

CVSS 7.1 2026-08-04
CVE-2026-70485
HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was global...

CVSS 7.1 Openwebui open_webui 2026-08-04
CVE-2026-70482
HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchan...

CVSS 8.8 Openwebui open_webui 2026-08-04
CVE-2026-70479
HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validate...

CVSS 7.7 Openwebui open_webui 2026-08-04
CVE-2026-70476
HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/ro...

CVSS 8.2 Flowiseai flowise 2026-08-04
CVE-2026-47682
HIGH

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's be...

CVSS 7.1 2026-08-04
1 477 478 479 480 481 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.