CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 479 of 500
CVE-2026-47110
MEDIUM

Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON with the a...

CVSS 6.5 2026-06-24
CVE-2026-39897
MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_footer. This issue has been fix...

CVSS 6.1 Cacti cacti 2026-06-24
CVE-2026-10642
MEDIUM

The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the interrupt-driven application cal...

CVSS 6.5 Zephyrproject zephyr 2026-06-24
CVE-2025-60468
MEDIUM

GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The com...

CVSS 5.5 Gpac gpac 2026-06-24
CVE-2026-52816
MEDIUM

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST /-/api/sanitize_ipynb allows arbitrary data: URIs without p...

CVSS 5.4 2026-06-24
CVE-2026-52815
MEDIUM

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at i...

CVSS 5.5 2026-06-24
CVE-2026-52814
MEDIUM

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an unauthenticated, asymmetric Denial of Service (DoS) attack. The...

CVSS 5.5 2026-06-24
CVE-2026-52809
MEDIUM

Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.A...

CVSS 6.8 2026-06-24
CVE-2026-52804
MEDIUM

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by-one err...

CVSS 5.5 2026-06-24
CVE-2026-52802
MEDIUM

Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to parameters can bypass validatio...

CVSS 5.4 2026-06-24
CVE-2026-50128
MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit authors of their artic...

CVSS 5.3 2026-06-24
CVE-2026-49278
MEDIUM

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endp...

CVSS 6.7 2026-06-24
CVE-2026-32315
MEDIUM

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motione...

CVSS 5.5 2026-06-24
CVE-2026-31978
MEDIUM

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal ...

CVSS 6.5 2026-06-24
CVE-2026-13208
MEDIUM

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from th...

CVSS 6.5 Kubevirt kubevirt 2026-06-24
CVE-2026-48028
MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-...

CVSS 6.5 2026-06-24
CVE-2026-46349
MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-...

CVSS 5.3 2026-06-24
CVE-2026-53949
MEDIUM

Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possibl...

CVSS 5.3 2026-06-24
CVE-2026-53948
MEDIUM

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowe...

CVSS 5.4 2026-06-24
CVE-2026-53947
MEDIUM

Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacke...

CVSS 5.3 2026-06-24
1 477 478 479 480 481 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.