CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 494 of 500
CVE-2026-15064
HIGH

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper hand...

CVSS 8.7 Ibm websphere_application_server 2026-07-28
CVE-2026-15057
HIGH

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

CVSS 7.5 Ibm websphere_application_server 2026-07-28
CVE-2026-14996
HIGH

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

CVSS 8.2 Ibm aspera_faspex 2026-07-28
CVE-2026-14981
HIGH

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP...

CVSS 7.5 Ibm websphere_application_server 2026-07-28
CVE-2026-14959
HIGH

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

CVSS 7.2 Ibm aspera_faspex 2026-07-28
CVE-2026-14958
HIGH

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

CVSS 7.2 Ibm aspera_faspex 2026-07-28
CVE-2026-14893
HIGH

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through i...

CVSS 7.3 2026-07-28
CVE-2026-14528
HIGH

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

CVSS 7.5 Ibm websphere_application_server 2026-07-28
CVE-2026-13463
HIGH

IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

CVSS 7.5 Ibm cloud_pak_system 2026-07-28
CVE-2026-13442
HIGH

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This caus...

CVSS 7.1 Langflow langflow 2026-07-28
CVE-2026-57510
HIGH

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to o...

CVSS 8.8 2026-07-28
CVE-2026-55555
HIGH

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By pr...

CVSS 7.5 Dompdf_project dompdf 2026-07-28
CVE-2026-55554
HIGH

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing path...

CVSS 7.5 Dompdf_project dompdf 2026-07-28
CVE-2026-48060
HIGH

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection a...

CVSS 8.1 2026-07-28
CVE-2026-16347
HIGH

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful ra...

CVSS 8.8 2026-07-28
CVE-2026-7769
HIGH

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 thr...

CVSS 8.1 Ibm sterling_b2b_integrator 2026-07-28
CVE-2026-66745
HIGH

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrativ...

CVSS 7.5 2026-07-28
CVE-2026-59932
HIGH

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, an...

CVSS 7.5 2026-07-28
CVE-2026-50737
HIGH

When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply wo...

CVSS 7.5 Enterprisedb pglogical 2026-07-28
CVE-2026-50736
HIGH

The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privi...

CVSS 7.5 Enterprisedb pglogical 2026-07-28
1 492 493 494 495 496 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.