CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 495 of 500
CVE-2026-49071
MEDIUM

Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.

CVSS 6.5 2026-06-17
CVE-2026-48782
MEDIUM

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blo...

CVSS 6.8 Pydantic pydantic_ai 2026-06-17
CVE-2026-47340
MEDIUM

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache Dolph...

CVSS 6.5 Apache dolphinscheduler 2026-06-17
CVE-2026-47277
MEDIUM

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unau...

CVSS 6.5 2026-06-17
CVE-2026-45436
MEDIUM

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

CVSS 6.5 2026-06-17
CVE-2026-44587
MEDIUM

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in str...

CVSS 6.1 Carrierwave_project carrierwave 2026-06-17
CVE-2026-42357
MEDIUM

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache D...

CVSS 6.5 Apache dolphinscheduler 2026-06-17
CVE-2026-40724
MEDIUM

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

CVSS 6.5 2026-06-17
CVE-2026-40722
MEDIUM

Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: fr...

CVSS 5.5 2026-06-17
CVE-2026-39578
MEDIUM

Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.

CVSS 5.5 2026-06-17
CVE-2026-39577
MEDIUM

Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.

CVSS 5.5 2026-06-17
CVE-2026-39433
MEDIUM

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

CVSS 6.5 2026-06-17
CVE-2026-2604
MEDIUM

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI con...

CVSS 5.6 2026-06-17
CVE-2026-28587
MEDIUM

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosu...

CVSS 5.5 Google android 2026-06-17
CVE-2026-28576
MEDIUM

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution pri...

CVSS 5.5 Google android 2026-06-17
CVE-2026-28575
MEDIUM

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a...

CVSS 5.5 Google android 2026-06-17
CVE-2026-27869
MEDIUM

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could, wit...

CVSS 6.9 2026-06-17
CVE-2026-27868
MEDIUM

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obta...

CVSS 6.9 2026-06-17
CVE-2026-27410
MEDIUM

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

CVSS 6.5 2026-06-17
CVE-2026-12461
MEDIUM

Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a cra...

CVSS 6.5 Google chrome 2026-06-17
1 493 494 495 496 497 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.