CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 491 of 500
CVE-2026-67328
HIGH

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attacker...

CVSS 8.1 2026-08-01
CVE-2026-67327
HIGH

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link...

CVSS 8.3 2026-08-01
CVE-2026-67326
HIGH

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. A...

CVSS 7.8 Gitpython_project gitpython 2026-08-01
CVE-2026-67325
HIGH

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe ...

CVSS 8.8 Gitpython_project gitpython 2026-08-01
CVE-2026-67323
HIGH

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such ...

CVSS 8.4 Gitpython_project gitpython 2026-08-01
CVE-2026-67322
HIGH

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cyg...

CVSS 7.5 Gitpython_project gitpython 2026-08-01
CVE-2026-67321
HIGH

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. ...

CVSS 7.5 Axios axios 2026-08-01
CVE-2026-67320
HIGH

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototyp...

CVSS 7.5 Axios axios 2026-08-01
CVE-2026-67317
HIGH

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers c...

CVSS 7.5 Axios axios 2026-08-01
CVE-2026-67316
HIGH

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or depe...

CVSS 7.4 Axios axios 2026-08-01
CVE-2026-67315
HIGH

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROX...

CVSS 7.5 Axios axios 2026-08-01
CVE-2026-67313
HIGH

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply Form...

CVSS 7.5 Axios axios 2026-08-01
CVE-2026-67312
HIGH

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when seria...

CVSS 7.5 Axios axios 2026-08-01
CVE-2026-67309
HIGH

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingres...

CVSS 7.5 Traefik traefik 2026-08-01
CVE-2026-67307
HIGH

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only t...

CVSS 7.7 Wazuh wazuh 2026-08-01
CVE-2026-67305
HIGH

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without vali...

CVSS 8.8 Freerdp freerdp 2026-08-01
CVE-2026-67304
HIGH

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed s...

CVSS 7.5 Freerdp freerdp 2026-08-01
CVE-2026-67301
HIGH

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enab...

CVSS 7.5 Freerdp freerdp 2026-08-01
CVE-2026-67300
HIGH

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncU...

CVSS 7.5 2026-08-01
CVE-2026-67299
HIGH

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). ...

CVSS 7.5 Freerdp freerdp 2026-08-01
1 489 490 491 492 493 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.