CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 489 of 500
CVE-2026-59643
HIGH

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0....

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-59642
HIGH

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-59639
HIGH

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bo...

CVSS 7.5 Bouncycastle bc-java 2026-08-03
CVE-2026-15055
HIGH

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy...

CVSS 8.2 Bouncycastle bc-java 2026-08-03
CVE-2026-12185
HIGH

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

CVSS 8.6 Bouncycastle bc-java 2026-08-03
CVE-2026-3245
HIGH

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

CVSS 7.5 2026-08-03
CVE-2026-18577
KEV HIGH

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVSS 8.1 N-able n-central 2026-08-02
CVE-2026-10848
HIGH

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that...

CVSS 8.6 Zephyrproject zephyr 2026-08-02
CVE-2026-9856
HIGH

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained(...

CVSS 7.1 2026-08-02
CVE-2026-68581
HIGH

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both re...

CVSS 8.1 2026-08-02
CVE-2026-68580
HIGH

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to valida...

CVSS 7.5 2026-08-02
CVE-2026-68578
HIGH

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-al...

CVSS 7.5 2026-08-02
CVE-2026-67357
HIGH

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers ...

CVSS 7.5 2026-08-02
CVE-2026-67356
HIGH

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without p...

CVSS 8.8 2026-08-02
CVE-2025-71400
HIGH

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbit...

CVSS 7.1 2026-08-02
CVE-2025-71399
HIGH

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path ...

CVSS 8.6 2026-08-02
CVE-2026-18571
HIGH

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to cr...

CVSS 7.2 Redhat build_of_keycloak 2026-08-02
CVE-2026-16540
HIGH

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated ...

CVSS 7.5 2026-08-02
CVE-2026-16285
HIGH

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users t...

CVSS 7.5 2026-08-02
CVE-2026-16261
HIGH

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions fro...

CVSS 7.5 2026-08-02
1 487 488 489 490 491 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.