CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 485 of 500
CVE-2026-67599
HIGH

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized i...

CVSS 7.2 2026-08-03
CVE-2026-67598
HIGH

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS r...

CVSS 7.4 2026-08-03
CVE-2026-62354
HIGH

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The propo...

CVSS 7.7 2026-08-03
CVE-2026-47211
HIGH

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user c...

CVSS 8.4 2026-08-03
CVE-2026-18641
HIGH

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.D...

CVSS 7.3 2026-08-03
CVE-2026-59913
HIGH

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with l...

CVSS 7.8 Dell display_and_peripheral_manager 2026-08-03
CVE-2026-59912
HIGH

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could po...

CVSS 7.8 Dell display_and_peripheral_manager 2026-08-03
CVE-2025-15629
HIGH

A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictab...

CVSS 7.5 Tp-link omada_oc200_v3_firmware 2026-08-03
CVE-2025-15628
HIGH

Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains...

CVSS 7.5 Tp-link omada_oc200_v3_firmware 2026-08-03
CVE-2025-15627
HIGH

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges betwee...

CVSS 7.5 Tp-link omada_oc200_v3_firmware 2026-08-03
CVE-2026-61524
HIGH

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote cod...

CVSS 7.2 2026-08-03
CVE-2026-61523
HIGH

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting m...

CVSS 7.2 2026-08-03
CVE-2026-40717
HIGH

Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could po...

CVSS 7.8 Dell monitor_driver 2026-08-03
CVE-2026-69152
HIGH

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while con...

CVSS 7.5 Juliangruber brace-expansion 2026-08-03
CVE-2026-67611
HIGH

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the expos...

CVSS 8.1 Open-emr openemr 2026-08-03
CVE-2026-67610
HIGH

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malic...

CVSS 8.1 2026-08-03
CVE-2026-61372
HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users ar...

CVSS 7.5 Apache jena_fuseki 2026-08-03
CVE-2026-41453
HIGH

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING c...

CVSS 8.8 2026-08-03
CVE-2026-39931
HIGH

OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges...

CVSS 7.2 Open-emr openemr 2026-08-03
CVE-2026-18718
HIGH

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra proj...

CVSS 7 2026-08-03
1 483 484 485 486 487 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.