CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 55 of 500
CVE-2026-16147
MEDIUM

The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transf...

CVSS 6.8 2026-09-14
CVE-2026-15924
MEDIUM

Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket co...

CVSS 5.9 2026-09-14
CVE-2026-15887
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

CVSS 5.4 2026-09-14
CVE-2026-15634
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transf...

CVSS 6.5 2026-09-14
CVE-2026-15412
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attac...

CVSS 6.5 2026-09-14
CVE-2026-15396
MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transf...

CVSS 6.5 2026-09-14
CVE-2026-90810
MEDIUM

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-age...

CVSS 6.3 2026-09-14
CVE-2026-90808
MEDIUM

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the compon...

CVSS 6.3 2026-09-14
CVE-2026-89021
MEDIUM

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container...

CVSS 6.9 2026-09-14
CVE-2026-19543
MEDIUM

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce th...

CVSS 6.2 2026-09-14
CVE-2026-15893
MEDIUM

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachab...

CVSS 6.5 2026-09-14
CVE-2026-91081
MEDIUM

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public d...

CVSS 5.8 2026-09-14
CVE-2026-91021
MEDIUM

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of use...

CVSS 5.4 2026-09-14
CVE-2026-90807
MEDIUM

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the compo...

CVSS 6.3 2026-09-14
CVE-2026-90806
MEDIUM

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the compone...

CVSS 6.3 2026-09-14
CVE-2026-57581
MEDIUM

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthentic...

CVSS 5.3 2026-09-14
CVE-2026-57570
MEDIUM

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 ...

CVSS 6.5 2026-09-14
CVE-2026-55847
MEDIUM

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi....

CVSS 6.1 2026-09-14
CVE-2026-55846
MEDIUM

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath...

CVSS 6.2 2026-09-14
CVE-2026-55832
MEDIUM

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled extern...

CVSS 6.1 2026-09-14
1 53 54 55 56 57 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.