CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 488 of 500
CVE-2026-13586
HIGH

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-13506
HIGH

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle ...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-12852
HIGH

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-12817
HIGH

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy ...

CVSS 8.6 Bouncycastle bc-java 2026-08-03
CVE-2026-12816
HIGH

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-12803
HIGH

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS bef...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-12802
HIGH

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bounc...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-58061
HIGH

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bo...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-58060
HIGH

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, ...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-58059
HIGH

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and B...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-20495
HIGH

In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed...

CVSS 7.8 Mediatek mt7925_firmware 2026-08-03
CVE-2026-20483
HIGH

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privilege...

CVSS 7.7 Mediatek mt8893_firmware 2026-08-03
CVE-2026-20479
HIGH

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlle...

CVSS 7.5 Mediatek mt2735_firmware 2026-08-03
CVE-2026-20465
HIGH

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional e...

CVSS 8.1 2026-08-03
CVE-2026-65875
HIGH

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacke...

CVSS 7.1 2026-08-03
CVE-2026-59651
HIGH

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-59649
HIGH

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, an...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-59646
HIGH

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, ...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-59645
HIGH

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.7...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-59644
HIGH

In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.

CVSS 7.5 Bouncycastle bc-java 2026-08-03
1 486 487 488 489 490 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.