CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 58 of 500
CVE-2026-90940
MEDIUM

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal ca...

CVSS 5.3 2026-09-14
CVE-2026-90939
MEDIUM

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retri...

CVSS 6.5 2026-09-14
CVE-2026-90786
MEDIUM

A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the file src/compiler/semantics.c of the component Duplicate Symbol...

CVSS 5.3 2026-09-14
CVE-2026-90785
MEDIUM

A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/compiler/semantics.c of the component Struct Analysis. The manip...

CVSS 5.3 2026-09-14
CVE-2026-84179
MEDIUM

Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field...

CVSS 6.5 2026-09-14
CVE-2026-82920
MEDIUM

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channe...

CVSS 5.5 2026-09-14
CVE-2026-7208
MEDIUM

Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processe...

CVSS 5.3 2026-09-14
CVE-2026-73191
MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance'...

CVSS 6.1 2026-09-14
CVE-2026-90957
MEDIUM

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap ...

CVSS 5.1 2026-09-14
CVE-2026-90931
MEDIUM

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malic...

CVSS 5.4 2026-09-14
CVE-2026-90930
MEDIUM

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to by...

CVSS 6.8 2026-09-14
CVE-2026-90928
MEDIUM

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authen...

CVSS 6.5 2026-09-14
CVE-2026-90927
MEDIUM

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large ...

CVSS 6.5 2026-09-14
CVE-2026-90784
MEDIUM

A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to...

CVSS 5.3 2026-09-14
CVE-2026-90716
MEDIUM

A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Numbe...

CVSS 5.5 2026-09-14
CVE-2026-90714
MEDIUM

A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. T...

CVSS 6.3 2026-09-14
CVE-2026-78318
MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's ...

CVSS 6.1 2026-09-14
CVE-2026-77147
MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious G...

CVSS 6.5 2026-09-14
CVE-2026-79701
MEDIUM

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the aj...

CVSS 6.9 2026-09-14
CVE-2026-9812
MEDIUM

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating it...

CVSS 6.5 2026-09-14
1 56 57 58 59 60 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.