CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 495 of 500
CVE-2026-49258
HIGH

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the...

CVSS 8.8 2026-07-28
CVE-2026-48396
HIGH

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vuln...

CVSS 8.6 Adobe bridge 2026-07-28
CVE-2026-48395
HIGH

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulner...

CVSS 8.6 Adobe bridge 2026-07-28
CVE-2026-48394
HIGH

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use...

CVSS 7.8 Adobe bridge 2026-07-28
CVE-2026-48393
HIGH

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use...

CVSS 7.8 Adobe bridge 2026-07-28
CVE-2026-48392
HIGH

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use...

CVSS 7.8 Adobe bridge 2026-07-28
CVE-2026-48391
HIGH

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could explo...

CVSS 8.2 Adobe bridge 2026-07-28
CVE-2026-48390
HIGH

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read an...

CVSS 8.2 Adobe bridge 2026-07-28
CVE-2026-48374
HIGH

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker cou...

CVSS 7.8 Adobe bridge 2026-07-28
CVE-2026-47726
HIGH

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check. ...

CVSS 7.1 2026-07-28
CVE-2026-18107
HIGH

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hij...

CVSS 7.8 2026-07-28
CVE-2026-16771
HIGH

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on cl...

CVSS 8.8 2026-07-28
CVE-2026-16496
HIGH

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user...

CVSS 8.9 2026-07-28
CVE-2026-15992
HIGH

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce v...

CVSS 8.8 2026-07-28
CVE-2026-14869
HIGH

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client ...

CVSS 8.6 2026-07-28
CVE-2026-59933
HIGH

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, an...

CVSS 7.5 2026-07-28
CVE-2026-59931
HIGH

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, an...

CVSS 7.7 2026-07-28
CVE-2026-54635
HIGH

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the ...

CVSS 7.5 2026-07-28
CVE-2026-48388
HIGH

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user....

CVSS 8.6 Adobe photoshop_installer 2026-07-28
CVE-2026-48372
HIGH

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu...

CVSS 7.8 Adobe format_plugins 2026-07-28
1 493 494 495 496 497 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.