CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 5 of 500
CVE-2026-89036
HIGH

Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by ...

CVSS 8.8 2026-09-17
CVE-2026-86864
HIGH

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argumen...

CVSS 8.8 2026-09-17
CVE-2026-86040
HIGH

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.a...

CVSS 7.5 2026-09-17
CVE-2026-86039
HIGH

libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to ver...

CVSS 8.2 2026-09-17
CVE-2026-86038
HIGH

libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils...

CVSS 7.5 2026-09-17
CVE-2026-85721
HIGH

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic ...

CVSS 7.5 2026-09-17
CVE-2026-85719
HIGH

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests u...

CVSS 7.5 2026-09-17
CVE-2026-85715
HIGH

ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmf...

CVSS 7.5 2026-09-17
CVE-2026-81516
HIGH

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, ConsulDiscoveryClient construct...

CVSS 7.5 2026-09-17
CVE-2026-81515
HIGH

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deseriali...

CVSS 7.5 2026-09-17
CVE-2026-76834
HIGH

b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject p...

CVSS 8.1 2026-09-17
CVE-2026-69197
HIGH

Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenc...

CVSS 8.7 2026-09-17
CVE-2026-56795
HIGH

Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially ex...

CVSS 8.2 2026-09-17
CVE-2026-92987
HIGH

roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with ten...

CVSS 7.5 2026-09-17
CVE-2026-92986
HIGH

SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or craft...

CVSS 8.8 2026-09-17
CVE-2026-92985
HIGH

SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with...

CVSS 8.8 2026-09-17
CVE-2026-92984
HIGH

HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessio...

CVSS 8.1 2026-09-17
CVE-2026-92983
HIGH

InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of inter...

CVSS 7.5 2026-09-17
CVE-2026-87742
HIGH

A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster th...

CVSS 7.5 2026-09-17
CVE-2026-85077
HIGH

Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response ...

CVSS 8.2 2026-09-17
1 3 4 5 6 7 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.