CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 484 of 500
CVE-2026-52972
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Cap AEAD AD length to 0x80000000 In order to prevent arithmetic overflows when checking the T...

CVSS 5.5 Linux linux_kernel 2026-06-24
CVE-2026-52965
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure When ttm_tt_swapout() fails, the current co...

CVSS 5.5 Linux linux_kernel 2026-06-24
CVE-2026-52964
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans The USB MIDI 2.0 endpoint parser has the same descri...

CVSS 5.5 Linux linux_kernel 2026-06-24
CVE-2026-52963
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI endpoint descriptor scans snd_usbmidi_get_ms_info() validates the internal MIDIStr...

CVSS 5.5 Linux linux_kernel 2026-06-24
CVE-2026-52961
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size The generic/642 test-case can reproduce ...

CVSS 5.5 Linux linux_kernel 2026-06-24
CVE-2026-52949
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure Apply the same fix as b2ed01e7ad ("drm/ttm: F...

CVSS 5.5 Linux linux_kernel 2026-06-24
CVE-2026-52948
MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzkaller, a persistent `schedule_t...

CVSS 5.5 Linux linux_kernel 2026-06-24
CVE-2026-50701
MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view com...

CVSS 5.1 2026-06-24
CVE-2026-11878
MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects...

CVSS 6.1 Microfocus access_manager 2026-06-24
CVE-2026-57305
MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified us...

CVSS 5.4 Jenkins assembla 2026-06-24
CVE-2026-57304
MEDIUM

A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specif...

CVSS 5.4 Jenkins assembla 2026-06-24
CVE-2026-57298
MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to have Jenkins connect to an attacke...

CVSS 5.4 2026-06-24
CVE-2026-57295
MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using at...

CVSS 5.4 Jenkins ec2_fleet 2026-06-24
CVE-2026-57294
MEDIUM

A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL us...

CVSS 5.4 Jenkins ec2_fleet 2026-06-24
CVE-2026-57292
MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-...

CVSS 5.4 2026-06-24
CVE-2026-57291
MEDIUM

Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attac...

CVSS 5.4 2026-06-24
CVE-2026-57282
MEDIUM

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able ...

CVSS 5 Jenkins git_client 2026-06-24
CVE-2026-56358
MEDIUM

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitiz...

CVSS 5.4 N8n n8n 2026-06-24
CVE-2026-56338
MEDIUM

Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validati...

CVSS 5.3 2026-06-24
CVE-2026-56337
MEDIUM

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers to enumerate app_ids by calling...

CVSS 5.3 2026-06-24
1 482 483 484 485 486 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.