CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 483 of 500
CVE-2026-70373
HIGH

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directl...

CVSS 8.8 2026-08-04
CVE-2026-70372
HIGH

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated st...

CVSS 8.8 2026-08-04
CVE-2026-70371
HIGH

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Colu...

CVSS 8.8 2026-08-04
CVE-2026-70370
HIGH

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of ...

CVSS 8.8 2026-08-04
CVE-2026-70369
HIGH

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragme...

CVSS 8.8 2026-08-04
CVE-2026-63252
HIGH

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthent...

CVSS 7.5 Eclipse milo 2026-08-04
CVE-2026-62927
HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous ...

CVSS 7.5 Eclipse milo 2026-08-04
CVE-2026-61387
HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation i...

CVSS 7.5 Eclipse milo 2026-08-04
CVE-2026-60007
HIGH

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowi...

CVSS 7.4 Eclipse milo 2026-08-04
CVE-2026-58080
HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the run...

CVSS 8.2 Eclipse milo 2026-08-04
CVE-2026-18806
HIGH

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. ...

CVSS 7.1 2026-08-04
CVE-2026-10710
HIGH

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverag...

CVSS 7.8 Autodesk fbx_software_development_kit 2026-08-04
CVE-2026-10709
HIGH

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious...

CVSS 7.8 Autodesk fbx_software_development_kit 2026-08-04
CVE-2026-14838
HIGH

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. ...

CVSS 7.4 2026-08-04
CVE-2026-67243
HIGH

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upl...

CVSS 7.2 2026-08-04
CVE-2026-18759
HIGH

The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the en...

CVSS 8.5 2026-08-04
CVE-2026-18755
HIGH

A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dyna...

CVSS 7.3 2026-08-04
CVE-2026-64563
HIGH

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resu...

CVSS 7.8 2026-08-04
CVE-2026-64562
HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 still points ...

CVSS 8.8 2026-08-04
CVE-2026-64561
HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i...

CVSS 8.8 2026-08-04
1 481 482 483 484 485 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.