CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 57 of 500
CVE-2026-53496
MEDIUM

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the...

CVSS 5.3 2026-09-14
CVE-2026-90995
MEDIUM

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a sp...

CVSS 5.5 2026-09-14
CVE-2026-90794
MEDIUM

A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing a m...

CVSS 6.3 2026-09-14
CVE-2026-90793
MEDIUM

A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation...

CVSS 5.4 2026-09-14
CVE-2026-88819
MEDIUM

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

CVSS 6.3 2026-09-14
CVE-2026-55795
MEDIUM

Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when t...

CVSS 6.9 2026-09-14
CVE-2026-55236
MEDIUM

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation path authorizes the assistant attached to a run by dis...

CVSS 5.9 2026-09-14
CVE-2026-55235
MEDIUM

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is deli...

CVSS 5.9 2026-09-14
CVE-2026-54529
MEDIUM

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query par...

CVSS 5.3 2026-09-14
CVE-2026-53708
MEDIUM

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/g...

CVSS 6.6 2026-09-14
CVE-2026-4103
MEDIUM

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the i...

CVSS 6.4 2026-09-14
CVE-2025-24890
MEDIUM

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an ad...

CVSS 6.8 2026-09-14
CVE-2026-90791
MEDIUM

A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Th...

CVSS 6.3 2026-09-14
CVE-2026-90790
MEDIUM

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notific...

CVSS 6.3 2026-09-14
CVE-2026-82434
MEDIUM

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it....

CVSS 6.5 2026-09-14
CVE-2026-82433
MEDIUM

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, th...

CVSS 6.5 2026-09-14
CVE-2026-82426
MEDIUM

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that i...

CVSS 6.5 2026-09-14
CVE-2026-57120
MEDIUM

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or st...

CVSS 6.5 2026-09-14
CVE-2026-57115
MEDIUM

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects auto...

CVSS 6.5 2026-09-14
CVE-2026-12985
MEDIUM

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob pat...

CVSS 6.8 2026-09-14
1 55 56 57 58 59 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.