CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 493 of 500
CVE-2026-48991
MEDIUM

XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain loc...

CVSS 5.5 2026-06-17
CVE-2026-48990
MEDIUM

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts oversiz...

CVSS 5.3 2026-06-17
CVE-2026-48820
MEDIUM

CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_ge...

CVSS 6.3 2026-06-17
CVE-2026-49133
MEDIUM

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content director...

CVSS 6.5 2026-06-17
CVE-2026-48988
MEDIUM

markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the...

CVSS 5.3 Markdown-it_project markdown-it 2026-06-17
CVE-2026-48821
MEDIUM

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an adm...

CVSS 5.8 2026-06-17
CVE-2026-55201
MEDIUM

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compromised remote Windows server to ...

CVSS 6.8 2026-06-17
CVE-2026-48822
MEDIUM

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion process used in th...

CVSS 5.8 2026-06-17
CVE-2026-48817
MEDIUM

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and look...

CVSS 5.3 Encode starlette 2026-06-17
CVE-2026-32682
MEDIUM

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabr...

CVSS 6.5 F5 nginx_gateway_fabric 2026-06-17
CVE-2026-10741
MEDIUM

Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to di...

CVSS 5.9 2026-06-17
CVE-2026-55198
MEDIUM

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. T...

CVSS 6.5 2026-06-17
CVE-2026-55197
MEDIUM

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcrip...

CVSS 6.5 2026-06-17
CVE-2026-53870
MEDIUM

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to ...

CVSS 5.5 2026-06-17
CVE-2026-9679
MEDIUM

Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equi...

CVSS 5.9 Nodejs undici 2026-06-17
CVE-2026-9678
MEDIUM

Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache fi...

CVSS 5.9 Nodejs undici 2026-06-17
CVE-2026-7300
MEDIUM

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Over...

CVSS 6.5 Rti connext_professional 2026-06-17
CVE-2026-2675
MEDIUM

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.This issue affects Connext Professional: fr...

CVSS 6.5 Rti connext_professional 2026-06-17
CVE-2026-35068
MEDIUM

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privile...

CVSS 5.7 Dell powerflex_manager 2026-06-17
CVE-2026-20246
MEDIUM

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerabili...

CVSS 6 Cisco umbrella_virtual_appliance 2026-06-17
1 491 492 493 494 495 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.