CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 496 of 500
CVE-2026-67185
HIGH

TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are c...

CVSS 7.5 2026-07-28
CVE-2026-67184
HIGH

TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request l...

CVSS 7.5 2026-07-28
CVE-2026-67183
HIGH

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each req...

CVSS 7.5 2026-07-28
CVE-2026-67182
HIGH

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) in...

CVSS 7.5 2026-07-28
CVE-2026-54609
HIGH

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the h...

CVSS 8.6 2026-07-28
CVE-2026-54605
HIGH

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a ...

CVSS 7.2 2026-07-28
CVE-2026-54603
HIGH

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned t...

CVSS 8.6 2026-07-28
CVE-2026-54345
HIGH

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from ...

CVSS 7.5 Gopacket gopacket 2026-07-28
CVE-2026-54332
HIGH

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit ...

CVSS 7.5 Gopacket gopacket 2026-07-28
CVE-2026-51275
HIGH

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to execute arbitrary code or cause a...

CVSS 8.8 2026-07-28
CVE-2026-51274
HIGH

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of service (ap...

CVSS 8.8 2026-07-28
CVE-2026-51273
HIGH

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded audio streaming library. The pr...

CVSS 7.8 2026-07-28
CVE-2026-16313
HIGH

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name stri...

CVSS 7.6 2026-07-28
CVE-2026-7868
HIGH

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.

CVSS 8.8 Ibm power_system_s1122_\(9824-22a\)_firmware 2026-07-28
CVE-2026-66748
HIGH

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary ...

CVSS 8.8 2026-07-28
CVE-2026-61609
HIGH

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() a...

CVSS 7.5 2026-07-28
CVE-2026-54593
HIGH

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-si...

CVSS 8.1 2026-07-28
CVE-2026-54545
HIGH

wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once before writing extracted module...

CVSS 7.1 2026-07-28
CVE-2026-51270
HIGH

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the htmlToUTF8() HTML entity decoding function. The function parses attacker-controlled maliciou...

CVSS 8.8 2026-07-28
CVE-2026-51269
HIGH

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-controlled long speech text inp...

CVSS 8.8 2026-07-28
1 494 495 496 497 498 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.