CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 492 of 500
CVE-2026-28573
MEDIUM

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution ...

CVSS 5.5 Google android 2026-06-18
CVE-2026-12137
MEDIUM

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' ...

CVSS 6.1 2026-06-18
CVE-2026-12136
MEDIUM

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and includin...

CVSS 6.4 2026-06-18
CVE-2026-12098
MEDIUM

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 1...

CVSS 6.4 2026-06-18
CVE-2026-12120
MEDIUM

The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.7 via th...

CVSS 5.3 2026-06-18
CVE-2026-12093
MEDIUM

The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that ...

CVSS 5.3 2026-06-18
CVE-2026-11402
MEDIUM

The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all version...

CVSS 6.4 2026-06-18
CVE-2026-10029
MEDIUM

The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...

CVSS 5.3 2026-06-18
CVE-2026-54533
MEDIUM

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output fil...

CVSS 6.9 2026-06-17
CVE-2026-54445
MEDIUM

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ide...

CVSS 6.9 2026-06-17
CVE-2026-50202
MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase pr...

CVSS 5.9 2026-06-17
CVE-2026-50201
MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 ...

CVSS 6.5 2026-06-17
CVE-2026-44646
MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, Context.spawn() creates a child Context for the {% render %...

CVSS 5.3 2026-06-17
CVE-2026-44645
MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the renderLimit option can be fully bypassed by a {% for %}...

CVSS 6.5 2026-06-17
CVE-2026-44644
MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through a flaw in the strip_html filter l...

CVSS 6.1 2026-06-17
CVE-2026-12568
MEDIUM

The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name conta...

CVSS 6.5 2026-06-17
CVE-2026-12565
MEDIUM

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU t...

CVSS 5.3 2026-06-17
CVE-2024-27928
MEDIUM

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks into a vantage6 user's email account, they can 1) reset the ...

CVSS 5.9 2026-06-17
CVE-2026-8049
MEDIUM

In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in ...

CVSS 5.3 2026-06-17
CVE-2026-54386
MEDIUM

marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting...

CVSS 6.1 2026-06-17
1 490 491 492 493 494 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.