CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 484 of 500
CVE-2026-67974
HIGH

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via...

CVSS 7.5 2026-08-03
CVE-2026-67970
HIGH

Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.

CVSS 7.5 2026-08-03
CVE-2026-67969
HIGH

An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.

CVSS 7.5 2026-08-03
CVE-2026-67977
HIGH

An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS 7.5 2026-08-03
CVE-2026-67973
HIGH

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

CVSS 7.5 2026-08-03
CVE-2026-47746
HIGH

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation ...

CVSS 8.9 2026-08-03
CVE-2026-10849
HIGH

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/ha...

CVSS 7.5 Zephyrproject zephyr 2026-08-03
CVE-2026-69246
HIGH

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set ...

CVSS 7.2 2026-08-03
CVE-2026-69244
HIGH

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an e...

CVSS 7.1 2026-08-03
CVE-2026-67972
HIGH

An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.

CVSS 7.5 2026-08-03
CVE-2026-67976
HIGH

The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputt...

CVSS 7.5 2026-08-03
CVE-2026-66065
HIGH

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incompl...

CVSS 8.4 2026-08-03
CVE-2026-52521
HIGH

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.

CVSS 8.1 2026-08-03
CVE-2026-48113
HIGH

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic ...

CVSS 8.5 2026-08-03
CVE-2026-41447
HIGH

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unval...

CVSS 7.8 2026-08-03
CVE-2026-18733
HIGH

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent...

CVSS 8.8 2026-08-03
CVE-2026-18647
HIGH

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functio...

CVSS 7.3 2026-08-03
CVE-2026-69192
HIGH

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as...

CVSS 7.7 2026-08-03
CVE-2026-69185
HIGH

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait fo...

CVSS 7.5 2026-08-03
CVE-2026-68981
HIGH

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum reque...

CVSS 7.5 Apache nifi 2026-08-03
1 482 483 484 485 486 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.