CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 497 of 500
CVE-2026-46825
MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnera...

CVSS 6 Oracle vm_virtualbox 2026-06-17
CVE-2026-46812
MEDIUM

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2....

CVSS 6.1 Oracle access_manager 2026-06-17
CVE-2026-46810
MEDIUM

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. ...

CVSS 6.5 Oracle identity_manager 2026-06-17
CVE-2026-46790
MEDIUM

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploi...

CVSS 5.3 Oracle webcenter_content 2026-06-17
CVE-2026-46770
MEDIUM

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 1...

CVSS 6.1 Oracle application_development_framework 2026-06-17
CVE-2026-46768
MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnera...

CVSS 6 Oracle vm_virtualbox 2026-06-17
CVE-2026-35291
MEDIUM

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Difficult to ex...

CVSS 6.6 Oracle weblogic_server 2026-06-17
CVE-2026-35261
MEDIUM

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2....

CVSS 6.5 Oracle access_manager 2026-06-17
CVE-2026-12425
MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). T...

CVSS 6.1 Powerschool employee_access_center 2026-06-16
CVE-2026-12105
MEDIUM

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.

CVSS 6.5 Devolutions devolutions_server 2026-06-16
CVE-2026-0155
MEDIUM

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution priv...

CVSS 5.3 Google android 2026-06-16
CVE-2026-0165
MEDIUM

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no addi...

CVSS 6.5 Google android 2026-06-16
CVE-2026-0141
MEDIUM

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution p...

CVSS 5.3 Google android 2026-06-16
CVE-2026-0128
MEDIUM

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional executio...

CVSS 6.5 Google android 2026-06-16
CVE-2026-0127
MEDIUM

In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service cau...

CVSS 6.5 Google android 2026-06-16
CVE-2026-53863
MEDIUM

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID to the poli...

CVSS 6.5 Openclaw openclaw 2026-06-16
CVE-2026-53862
MEDIUM

OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can re...

CVSS 5.4 Openclaw openclaw 2026-06-16
CVE-2026-53860
MEDIUM

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than ...

CVSS 5.4 Openclaw openclaw 2026-06-16
CVE-2026-53859
MEDIUM

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived ...

CVSS 6.5 Openclaw openclaw 2026-06-16
CVE-2026-53856
MEDIUM

OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attacker...

CVSS 5.5 Openclaw openclaw 2026-06-16
1 495 496 497 498 499 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.