CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 496 of 500
CVE-2026-12459
MEDIUM

Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chrom...

CVSS 6.1 Google chrome 2026-06-17
CVE-2026-12450
MEDIUM

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a craft...

CVSS 6.5 Google chrome 2026-06-17
CVE-2026-12444
MEDIUM

Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain potentially sensitive information from process memory via a ...

CVSS 5.5 Google chrome 2026-06-17
CVE-2026-12115
MEDIUM

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via...

CVSS 6.6 2026-06-17
CVE-2026-11975
MEDIUM

Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execute arbitrary JavaScript via the S...

CVSS 6.2 2026-06-17
CVE-2026-10839
MEDIUM

Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the applicati...

CVSS 5.1 2026-06-17
CVE-2026-10837
MEDIUM

Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that, when opened by a victim, cause t...

CVSS 5.1 2026-06-17
CVE-2026-10836
MEDIUM

Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A successful exploit could result in th...

CVSS 5.1 2026-06-17
CVE-2026-0064
MEDIUM

In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges ...

CVSS 5.5 Google android 2026-06-17
CVE-2025-69137
MEDIUM

Subscriber Broken Access Control in Genemy <= 1.6.6 versions.

CVSS 6.5 2026-06-17
CVE-2025-62340
MEDIUM

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sess...

CVSS 5.3 Hcltech icontrol 2026-06-17
CVE-2025-15642
MEDIUM

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Pro...

CVSS 6.8 2026-06-17
CVE-2025-15641
MEDIUM

Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the cust...

CVSS 6.8 2026-06-17
CVE-2024-37210
MEDIUM

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.

CVSS 6.5 2026-06-17
CVE-2024-35690
MEDIUM

Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/...

CVSS 6.5 2026-06-17
CVE-2024-33909
MEDIUM

Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/...

CVSS 5.3 2026-06-17
CVE-2026-46979
MEDIUM

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2...

CVSS 6.5 Oracle peoplesoft_enterprise_campus_software_campus_community 2026-06-17
CVE-2026-46877
MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnera...

CVSS 6 Oracle vm_virtualbox 2026-06-17
CVE-2026-46871
MEDIUM

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerabilit...

CVSS 6.5 Oracle mysql_shell 2026-06-17
CVE-2026-46869
MEDIUM

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitab...

CVSS 6.5 Oracle mysql_shell 2026-06-17
1 494 495 496 497 498 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.