CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 481 of 500
CVE-2026-47612
HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successfu...

CVSS 7.5 Nvidia dynamo 2026-08-04
CVE-2026-24255
HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixe...

CVSS 7.5 Nvidia dynamo 2026-08-04
CVE-2026-24253
HIGH

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service an...

CVSS 8.2 Nvidia dynamo 2026-08-04
CVE-2026-18830
HIGH

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security contr...

CVSS 8.1 2026-08-04
CVE-2026-18788
HIGH

A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation r...

CVSS 7.3 2026-08-04
CVE-2026-69262
HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission(...

CVSS 8.1 Flowiseai flowise 2026-08-04
CVE-2026-69259
HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/S...

CVSS 8.8 Flowiseai flowise 2026-08-04
CVE-2026-69257
HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mappe...

CVSS 8.6 Flowiseai flowise 2026-08-04
CVE-2026-69256
HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed thr...

CVSS 8.8 Flowiseai flowise 2026-08-04
CVE-2026-69255
HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extra...

CVSS 8.8 Flowiseai flowise 2026-08-04
CVE-2026-64634
HIGH

A vulnerability allowing local privilege escalation to the Reporter service context.

CVSS 8.4 2026-08-04
CVE-2026-64631
HIGH

A vulnerability allowing a low-privileged user to inject SQL and extract database contents.

CVSS 8.6 2026-08-04
CVE-2026-58075
HIGH

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.

CVSS 8.7 2026-08-04
CVE-2026-58074
HIGH

A vulnerability allowing a high-privileged user to execute arbitrary code on the server.

CVSS 8.6 2026-08-04
CVE-2026-58071
HIGH

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an adm...

CVSS 8.2 2026-08-04
CVE-2026-58067
HIGH

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.

CVSS 8.7 2026-08-04
CVE-2026-56848
HIGH

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free....

CVSS 7.5 2026-08-04
CVE-2026-18787
HIGH

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoi...

CVSS 8.8 2026-08-04
CVE-2026-15307
HIGH

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the ...

CVSS 8.8 Djangoproject django 2026-08-04
CVE-2026-15314
HIGH

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation befor...

CVSS 7.5 Tp-link tapo_p110_firmware 2026-08-04
1 479 480 481 482 483 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.