CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 493 of 500
CVE-2026-54719
HIGH

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did no...

CVSS 7.5 2026-07-28
CVE-2026-54650
HIGH

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the o...

CVSS 8.6 2026-07-28
CVE-2026-54638
HIGH

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthe...

CVSS 7.5 2026-07-28
CVE-2026-47219
HIGH

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely...

CVSS 7.5 2026-07-28
CVE-2026-55415
HIGH

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Fr...

CVSS 7.5 Koxudaxi datamodel-code-generator 2026-07-28
CVE-2026-55391
HIGH

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Pr...

CVSS 7.5 Koxudaxi datamodel-code-generator 2026-07-28
CVE-2026-55390
HIGH

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for ...

CVSS 7.5 2026-07-28
CVE-2026-55389
HIGH

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Pr...

CVSS 7.5 Koxudaxi datamodel-code-generator 2026-07-28
CVE-2026-54691
HIGH

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --url targets and...

CVSS 8.2 2026-07-28
CVE-2026-54690
HIGH

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Fr...

CVSS 8.2 Koxudaxi datamodel-code-generator 2026-07-28
CVE-2026-54656
HIGH

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Fr...

CVSS 7.8 Koxudaxi datamodel-code-generator 2026-07-28
CVE-2026-54655
HIGH

datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel_code_generator/parser/jsonsche...

CVSS 7.8 2026-07-28
CVE-2026-54654
HIGH

datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is rendered into Python comments in...

CVSS 7.8 2026-07-28
CVE-2026-54653
HIGH

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Fr...

CVSS 8.8 Koxudaxi datamodel-code-generator 2026-07-28
CVE-2026-54621
HIGH

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/Unio...

CVSS 7.8 2026-07-28
CVE-2026-59942
HIGH

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP proces...

CVSS 7.5 Dompdf_project dompdf 2026-07-28
CVE-2026-59941
HIGH

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bou...

CVSS 7.5 Dompdf_project dompdf 2026-07-28
CVE-2026-15328
HIGH

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.

CVSS 8.1 Ibm websphere_application_server 2026-07-28
CVE-2026-15325
HIGH

IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.

CVSS 8.7 Ibm websphere_application_server 2026-07-28
CVE-2026-15280
HIGH

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechan...

CVSS 7.5 Ibm websphere_application_server 2026-07-28
1 491 492 493 494 495 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.