CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 488 of 500
CVE-2026-47377
MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() on a path extracted from the URL...

CVSS 5.1 2026-06-23
CVE-2026-47376
MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL token directly into a JavaScript string literal in a server-...

CVSS 5.1 2026-06-23
CVE-2026-47375
MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed base can inject arbitrary SQL in...

CVSS 6 2026-06-23
CVE-2026-47279
MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that...

CVSS 6.9 2026-06-23
CVE-2026-46552
MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using o...

CVSS 5.8 2026-06-23
CVE-2026-46551
MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, the uploadViaURL path in the v1/v2 attachment API did not enforce NC_ATTACHMENT_FIELD_SIZE against th...

CVSS 6.5 2026-06-23
CVE-2026-46550
MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with httpOnly: true but missing both the secure flag and the sameSit...

CVSS 5.4 2026-06-23
CVE-2026-46547
MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in the Page Leaving Warning page. The ncRedirectUrl and ncBackUr...

CVSS 6.1 2026-06-23
CVE-2026-11820
MEDIUM

A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key an...

CVSS 6.5 Redhat enterprise_linux 2026-06-23
CVE-2026-11819
MEDIUM

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Ke...

CVSS 5.5 Redhat enterprise_linux 2026-06-23
CVE-2025-64105
MEDIUM

FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions 0.6.21 through 0.7.2 are vulnera...

CVSS 5.1 2026-06-23
CVE-2026-45792
MEDIUM

rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration files. RTK aut...

CVSS 5.5 Rtk-ai rtk 2026-06-23
CVE-2026-55736
MEDIUM

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is ...

CVSS 5.9 2026-06-23
CVE-2026-54324
MEDIUM

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authorization flaw in Daytona's notific...

CVSS 6.5 2026-06-23
CVE-2026-54323
MEDIUM

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS cer...

CVSS 5.9 2026-06-23
CVE-2026-54022
MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership o...

CVSS 5.3 Openwebui open_webui 2026-06-23
CVE-2026-54021
MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ollama proxy routes accept a call...

CVSS 6.3 Openwebui open_webui 2026-06-23
CVE-2026-54019
MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level ACL checks, but the patch can s...

CVSS 6.5 Openwebui open_webui 2026-06-23
CVE-2026-54015
MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI's prompt version-history endpoints authorize the promp...

CVSS 6.4 Openwebui open_webui 2026-06-23
CVE-2026-54011
MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open WebUI renders Mermaid blocks from Markdown files in the file ...

CVSS 5.4 Openwebui open_webui 2026-06-23
1 486 487 488 489 490 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.