CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 497 of 500
CVE-2026-47483
HIGH

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurr...

CVSS 8.2 2026-07-28
CVE-2026-47427
HIGH

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is ...

CVSS 7.5 Github mcp_server 2026-07-28
CVE-2026-45293
HIGH

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameter...

CVSS 8.6 2026-07-28
CVE-2026-43910
HIGH

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, A...

CVSS 8.2 Appium java-client 2026-07-28
CVE-2026-8164
HIGH

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affect...

CVSS 7.3 2026-07-28
CVE-2026-67178
HIGH

MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example...

CVSS 7.8 2026-07-28
CVE-2026-63727
HIGH

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able...

CVSS 8.8 2026-07-28
CVE-2026-51254
HIGH

schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerability in the MP3Decoder::GetBits() function of the MP3 decoder due to unchecked bit reading operations. The lack...

CVSS 7.8 2026-07-28
CVE-2026-51251
HIGH

Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::decode() function of the MP3 decoder due to missing size validation on untrusted mainDataBe...

CVSS 7.5 2026-07-28
CVE-2026-59878
HIGH

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector c...

CVSS 7.5 Apache activemq 2026-07-28
CVE-2026-7187
HIGH

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS...

CVSS 8.8 2026-07-28
CVE-2026-66920
HIGH

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursively traversed graph edges, whil...

CVSS 8.2 2026-07-28
CVE-2026-66918
HIGH

Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document. When rendering a graph node, ...

CVSS 8.2 2026-07-28
CVE-2026-65881
HIGH

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read a...

CVSS 7.5 2026-07-28
CVE-2026-62433
HIGH

Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation without any checking being done. As a result, certain opera...

CVSS 7.3 2026-07-28
CVE-2026-62432
HIGH

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in derefer...

CVSS 7.3 2026-07-28
CVE-2026-62431
HIGH

The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault.

CVSS 7.5 2026-07-28
CVE-2026-62430
HIGH

Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest chosen index, and one of the usages of the index didn't take t...

CVSS 7.5 2026-07-28
CVE-2026-62428
HIGH

When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a mapping or another copy). For all copy operations the refere...

CVSS 7.8 2026-07-28
CVE-2026-62427
HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operatio...

CVSS 8.8 2026-07-28
1 495 496 497 498 499 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.