CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 498 of 500
CVE-2026-53854
MEDIUM

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state ...

CVSS 6.5 Openclaw openclaw 2026-06-16
CVE-2026-53852
MEDIUM

OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by subm...

CVSS 5.4 Openclaw openclaw 2026-06-16
CVE-2026-53851
MEDIUM

OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers...

CVSS 5.3 Openclaw openclaw 2026-06-16
CVE-2026-53850
MEDIUM

OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper aut...

CVSS 5.5 Openclaw openclaw 2026-06-16
CVE-2026-53847
MEDIUM

OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator.write access to modify global co...

CVSS 5.4 Openclaw openclaw 2026-06-16
CVE-2026-53844
MEDIUM

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper...

CVSS 6.5 Openclaw openclaw 2026-06-16
CVE-2026-53841
MEDIUM

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers c...

CVSS 6.1 Openclaw openclaw 2026-06-16
CVE-2026-4367
MEDIUM

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or ...

CVSS 5.5 2026-06-16
CVE-2026-48775
MEDIUM

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSer...

CVSS 6.8 Langchain langgraph-checkpoint 2026-06-16
CVE-2026-47963
MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulne...

CVSS 5.5 Adobe dng_software_development_kit 2026-06-16
CVE-2026-47934
MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulne...

CVSS 5.5 Adobe dng_software_development_kit 2026-06-16
CVE-2026-47927
MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulne...

CVSS 5.5 Adobe dng_software_development_kit 2026-06-16
CVE-2026-47748
MEDIUM

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae0...

CVSS 5.5 Leejet stable-diffusion.cpp 2026-06-16
CVE-2026-12003
MEDIUM

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks ...

CVSS 5.3 2026-06-16
CVE-2024-30476
MEDIUM

PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vuln...

CVSS 5.4 2026-06-16
CVE-2024-22451
MEDIUM

Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through p...

CVSS 6.7 Dell peripheral_manager 2026-06-16
CVE-2026-9307
MEDIUM

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics web...

CVSS 6.3 2026-06-16
CVE-2026-10831
MEDIUM

A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not properly validate whether a sender ...

CVSS 6.9 2026-06-16
CVE-2026-9507
MEDIUM

A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijack a victim’s account by keeping the initial session identifi...

CVSS 5.1 2026-06-16
CVE-2026-53899
MEDIUM

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. T...

CVSS 6.5 Mozilla firefox_mobile 2026-06-16
1 496 497 498 499 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.