CVE Search
Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.
A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provide...
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low pr...
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could po...
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could p...
Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write ...
Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the a...
Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.