CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 490 of 500
CVE-2026-15241
HIGH

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse ...

CVSS 7.5 2026-08-02
CVE-2026-15236
HIGH

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the pe...

CVSS 7.5 2026-08-02
CVE-2026-15206
HIGH

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent...

CVSS 7.5 2026-08-02
CVE-2026-15151
HIGH

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-managem...

CVSS 7.5 2026-08-02
CVE-2026-14920
HIGH

## Summary

CVSS 8.2 2026-08-02
CVE-2026-12586
HIGH

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthentica...

CVSS 8.1 2026-08-02
CVE-2026-18352
HIGH

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes ...

CVSS 7.5 2026-08-02
CVE-2026-13339
HIGH

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it...

CVSS 7.5 2026-08-02
CVE-2026-18556
KEV HIGH

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CVSS 7.4 N-able n-central 2026-08-01
CVE-2026-55735
HIGH

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in li...

CVSS 7.5 Ueberauth guardian 2026-08-01
CVE-2026-55734
HIGH

Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. T...

CVSS 7.5 Ueberauth guardian 2026-08-01
CVE-2026-55733
HIGH

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Per...

CVSS 7.5 Ueberauth guardian 2026-08-01
CVE-2026-54894
HIGH

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plu...

CVSS 7.5 Ueberauth guardian 2026-08-01
CVE-2026-67352
HIGH

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administr...

CVSS 7.6 2026-08-01
CVE-2026-67343
HIGH

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken ...

CVSS 8.8 2026-08-01
CVE-2026-67340
HIGH

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed...

CVSS 7.2 2026-08-01
CVE-2026-67336
HIGH

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. A...

CVSS 8.7 2026-08-01
CVE-2026-67333
HIGH

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin...

CVSS 7.2 2026-08-01
CVE-2026-67331
HIGH

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other user...

CVSS 8.3 2026-08-01
CVE-2026-67329
HIGH

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware v...

CVSS 7.1 2026-08-01
1 488 489 490 491 492 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.