CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 490 of 500
CVE-2026-54301
MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node...

CVSS 5.4 N8n n8n 2026-06-23
CVE-2026-48520
MEDIUM

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrar...

CVSS 6.1 Langflow langflow 2026-06-23
CVE-2026-44958
MEDIUM

An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The b...

CVSS 5.4 2026-06-23
CVE-2026-42867
MEDIUM

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/kno...

CVSS 6.5 Langflow langflow 2026-06-23
CVE-2026-34915
MEDIUM

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perf...

CVSS 6.1 2026-06-23
CVE-2026-56696
MEDIUM

OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project contex...

CVSS 5.4 2026-06-23
CVE-2026-56695
MEDIUM

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by...

CVSS 6.5 2026-06-23
CVE-2026-56694
MEDIUM

NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges...

CVSS 5.4 2026-06-23
CVE-2026-56693
MEDIUM

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side ...

CVSS 5.5 2026-06-23
CVE-2026-56692
MEDIUM

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host valida...

CVSS 5.5 2026-06-23
CVE-2026-56402
MEDIUM

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a val...

CVSS 6.5 2026-06-23
CVE-2026-55767
MEDIUM

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesD...

CVSS 5.8 Guzzlephp guzzle 2026-06-23
CVE-2026-55568
MEDIUM

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Pr...

CVSS 5.9 Guzzlephp guzzle 2026-06-23
CVE-2026-54303
MEDIUM

n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response wit...

CVSS 5.4 N8n n8n 2026-06-23
CVE-2026-52673
MEDIUM

SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component

CVSS 6.5 2026-06-23
CVE-2025-55639
MEDIUM

GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to caus...

CVSS 6.5 Gpac gpac 2026-06-23
CVE-2026-11772
MEDIUM

DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arbitrary JavaScript execution in ...

CVSS 5.1 2026-06-23
CVE-2026-12969
MEDIUM

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing t...

CVSS 5.3 Redhat enterprise_linux 2026-06-23
CVE-2026-10609
MEDIUM

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying t...

CVSS 6.8 Redhat cluster_logging_operator 2026-06-23
CVE-2026-56762
MEDIUM

Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing invalid characters such as control c...

CVSS 5.3 2026-06-23
1 488 489 490 491 492 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.