CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 498 of 500
CVE-2026-62426
HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operatio...

CVSS 8.8 2026-07-28
CVE-2026-49332
HIGH

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys ...

CVSS 8.5 2026-07-28
CVE-2026-42493
HIGH

Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternative...

CVSS 7.5 2026-07-28
CVE-2026-42492
HIGH

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was ...

CVSS 7.5 2026-07-28
CVE-2026-21047
HIGH

Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.

CVSS 8.3 2026-07-28
CVE-2026-15025
HIGH

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3....

CVSS 7.5 2026-07-28
CVE-2026-13440
HIGH

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...

CVSS 7.2 2026-07-28
CVE-2026-63301
HIGH

In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language...

CVSS 7 2026-07-28
CVE-2026-59248
HIGH

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or clien...

CVSS 8.7 2026-07-28
CVE-2026-14785
HIGH

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escap...

CVSS 7.5 2026-07-28
CVE-2026-14328
HIGH

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. ...

CVSS 8.8 2026-07-28
CVE-2026-10207
HIGH

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplie...

CVSS 7.5 2026-07-28
CVE-2026-61376
HIGH

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command...

CVSS 7.2 2026-07-28
CVE-2026-59764
HIGH

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be exe...

CVSS 7.2 2026-07-28
CVE-2026-14516
HIGH

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, an...

CVSS 7.5 2026-07-28
CVE-2026-14169
HIGH

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could resul...

CVSS 8.1 2026-07-28
CVE-2026-14168
HIGH

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system acces...

CVSS 8.8 2026-07-28
CVE-2026-14167
HIGH

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

CVSS 8.8 2026-07-28
CVE-2026-13161
HIGH

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions u...

CVSS 7.5 2026-07-28
CVE-2026-12800
HIGH

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST A...

CVSS 7.5 2026-07-28
1 496 497 498 499 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.