CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 54 of 500
CVE-2026-12766
MEDIUM

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, p...

CVSS 5.4 2026-09-14
CVE-2026-12765
MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system,...

CVSS 6.5 2026-09-14
CVE-2026-90815
MEDIUM

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the compo...

CVSS 6.3 2026-09-14
CVE-2026-90814
MEDIUM

A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the component ...

CVSS 6.3 2026-09-14
CVE-2026-73497
MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlle...

CVSS 6.5 2026-09-14
CVE-2026-55244
MEDIUM

ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit...

CVSS 5 2026-09-14
CVE-2026-55093
MEDIUM

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src...

CVSS 6.1 2026-09-14
CVE-2026-54559
MEDIUM

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP,...

CVSS 6.9 2026-09-14
CVE-2026-54246
MEDIUM

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authe...

CVSS 5.7 2026-09-14
CVE-2026-53717
MEDIUM

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go fo...

CVSS 6.5 2026-09-14
CVE-2026-18065
MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.

CVSS 5.3 2026-09-14
CVE-2026-17628
MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.

CVSS 5.4 2026-09-14
CVE-2026-17463
MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of ...

CVSS 6.5 2026-09-14
CVE-2026-17047
MEDIUM

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

CVSS 5.4 2026-09-14
CVE-2026-16702
MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of ...

CVSS 6.5 2026-09-14
CVE-2026-16435
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.

CVSS 5.9 2026-09-14
CVE-2026-16188
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

CVSS 5.3 2026-09-14
CVE-2026-16187
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

CVSS 6.5 2026-09-14
CVE-2026-16186
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

CVSS 5.4 2026-09-14
CVE-2026-16185
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

CVSS 6.4 2026-09-14
1 52 53 54 55 56 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.