CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 500 of 500
CVE-2026-40809
MEDIUM

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from ...

CVSS 6.5 2026-06-16
CVE-2026-2381
MEDIUM

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` funct...

CVSS 6.5 2026-06-16
CVE-2026-10093
MEDIUM

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and i...

CVSS 6.4 2026-06-16
CVE-2025-9912
MEDIUM

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary comma...

CVSS 6.3 2026-06-16
CVE-2026-9187
MEDIUM

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability c...

CVSS 5.3 2026-06-16
CVE-2026-5149
MEDIUM

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking...

CVSS 6.5 2026-06-16
CVE-2026-50255
MEDIUM

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with S...

CVSS 6.7 2026-06-16
CVE-2026-10635
MEDIUM

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domain...

CVSS 6.3 Zephyrproject zephyr 2026-06-16
CVE-2025-10262
MEDIUM

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authentica...

CVSS 6.3 2026-06-16
CVE-2026-6964
MEDIUM

The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly veri...

CVSS 5.3 2026-06-16
CVE-2026-42014
MEDIUM

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an ...

CVSS 6.6 2026-06-16
CVE-2026-1766
MEDIUM

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerabi...

CVSS 6.1 Redhat enterprise_linux 2026-06-16
CVE-2026-1765
MEDIUM

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processin...

CVSS 5.6 2026-06-16
CVE-2026-1764
MEDIUM

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds chec...

CVSS 5.6 Redhat enterprise_linux 2026-06-16
CVE-2026-12162
MEDIUM

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a ...

CVSS 5.5 Devolutions remote_desktop_manager 2026-06-16
CVE-2026-48157
MEDIUM

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses HttpException::setTitle() and/or ...

CVSS 6.1 2026-06-15
CVE-2026-49775
MEDIUM

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

CVSS 6.5 2026-06-15
CVE-2026-49773
MEDIUM

Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

CVSS 6.5 2026-06-15
CVE-2026-48965
MEDIUM

Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.

CVSS 6.5 2026-06-15
CVE-2026-48887
MEDIUM

Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.

CVSS 6.5 2026-06-15
1 498 499 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.