CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
10,000 result(s) · page 59 of 500
CVE-2026-94493
CRITICAL

A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The ma...

CVSS 10 2026-09-22
CVE-2026-94492
MEDIUM

A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenA...

CVSS 6.3 2026-09-22
CVE-2026-94491
HIGH

A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to ...

CVSS 7.3 2026-09-22
CVE-2026-76974
MEDIUM

SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated us...

CVSS 5.3 2026-09-22
CVE-2026-94425
HIGH

A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL H...

CVSS 8.8 2026-09-21
CVE-2026-94627
HIGH

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregat...

CVSS 7.5 2026-09-21
CVE-2026-94626
HIGH

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attack...

CVSS 7.5 2026-09-21
CVE-2026-94625
MEDIUM

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaime...

CVSS 5.3 2026-09-21
CVE-2026-94624
HIGH

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary t...

CVSS 7.5 2026-09-21
CVE-2026-94623
HIGH

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-promp...

CVSS 7.5 2026-09-21
CVE-2026-94622
HIGH

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send re...

CVSS 7.5 2026-09-21
CVE-2026-94540
HIGH

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selecte...

CVSS 7.7 2026-09-21
CVE-2026-94535
HIGH

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attack...

CVSS 7.1 2026-09-21
CVE-2026-94534
HIGH

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profil...

CVSS 7.1 2026-09-21
CVE-2026-94533
MEDIUM

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can re...

CVSS 6.5 2026-09-21
CVE-2026-94532
MEDIUM

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Atta...

CVSS 6.5 2026-09-21
CVE-2026-93340
MEDIUM

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any acco...

CVSS 6.8 2026-09-21
CVE-2026-65980
HIGH

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's ClickHouse protocol in se...

CVSS 7.9 2026-09-21
CVE-2026-61852
MEDIUM

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation...

CVSS 5.8 2026-09-21
CVE-2026-61851
MEDIUM

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation...

CVSS 6.5 2026-09-21
1 57 58 59 60 61 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.