CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 492 of 500
CVE-2026-58159
HIGH

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0....

CVSS 8.2 Apache traffic_server 2026-07-29
CVE-2026-58157
HIGH

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9...

CVSS 8.7 Apache traffic_server 2026-07-29
CVE-2026-50622
HIGH

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assig...

CVSS 8.8 Apache atlas 2026-07-29
CVE-2026-23904
HIGH

Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause th...

CVSS 7.3 Apache kyuubi 2026-07-29
CVE-2026-64557
HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() l2cap_sock_new_connection_cb() returned...

CVSS 8.8 2026-07-29
CVE-2026-64556
HIGH

In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exec perf_event_remove_on_exec() removes events by calling per...

CVSS 7.8 2026-07-29
CVE-2026-65324
HIGH

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Se...

CVSS 7.5 Apache traffic_server 2026-07-29
CVE-2026-58154
HIGH

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9....

CVSS 8.9 Apache traffic_server 2026-07-29
CVE-2026-58153
HIGH

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: ...

CVSS 8.3 Apache traffic_server 2026-07-29
CVE-2026-58151
HIGH

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1....

CVSS 7.5 Apache traffic_server 2026-07-29
CVE-2026-13425
HIGH

The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient i...

CVSS 7.2 2026-07-29
CVE-2026-63231
HIGH

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to rea...

CVSS 8.1 2026-07-29
CVE-2026-14300
HIGH

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification ...

CVSS 8.1 2026-07-29
CVE-2026-14234
HIGH

The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administr...

CVSS 7.1 2026-07-29
CVE-2026-13690
HIGH

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's ...

CVSS 7.4 2026-07-29
CVE-2026-11974
HIGH

The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauth...

CVSS 8.6 2026-07-29
CVE-2026-12476
HIGH

The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in th...

CVSS 7.2 2026-07-29
CVE-2026-12144
HIGH

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` func...

CVSS 8.8 2026-07-29
CVE-2026-56822
HIGH

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshake...

CVSS 7.4 Netty netty 2026-07-29
CVE-2026-56821
HIGH

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP...

CVSS 7.4 Netty netty 2026-07-29
1 490 491 492 493 494 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.