CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 494 of 500
CVE-2026-20220
MEDIUM

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an a...

CVSS 6.3 Cisco crosswork_network_controller 2026-06-17
CVE-2026-1288
MEDIUM

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation ...

CVSS 5.5 Autodesk revit 2026-06-17
CVE-2025-32748
MEDIUM

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this...

CVSS 6.1 Dell powerflex_rack_release_certification_matrix 2026-06-17
CVE-2026-55748
MEDIUM

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this ...

CVSS 6 2026-06-17
CVE-2026-48117
MEDIUM

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack in which an attacker could regis...

CVSS 6.8 2026-06-17
CVE-2026-35162
MEDIUM

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit thi...

CVSS 6.5 Dell powerflex_manager 2026-06-17
CVE-2026-12528
MEDIUM

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overf...

CVSS 5.4 Redhat directory_server 2026-06-17
CVE-2026-11311
MEDIUM

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. ...

CVSS 6.5 F5 nginx_gateway_fabric 2026-06-17
CVE-2026-10850
MEDIUM

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint...

CVSS 5.4 Plane plane 2026-06-17
CVE-2024-47477
MEDIUM

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulner...

CVSS 6.5 Dell powerflex_manager 2026-06-17
CVE-2026-9591
MEDIUM

Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an ...

CVSS 6.9 2026-06-17
CVE-2026-54817
MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a thr...

CVSS 6.5 2026-06-17
CVE-2026-52716
MEDIUM

Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

CVSS 6.5 2026-06-17
CVE-2025-15657
MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.

CVSS 5.3 2026-06-17
CVE-2026-8607
MEDIUM

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shor...

CVSS 6.4 2026-06-17
CVE-2026-8494
MEDIUM

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including,...

CVSS 6.4 2026-06-17
CVE-2026-8383
MEDIUM

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to ...

CVSS 5.3 2026-06-17
CVE-2026-7850
MEDIUM

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, ...

CVSS 5.9 2026-06-17
CVE-2026-54196
MEDIUM

Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1.

CVSS 6.8 2026-06-17
CVE-2026-49072
MEDIUM

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

CVSS 6.5 2026-06-17
1 492 493 494 495 496 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.