CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 6 of 500
CVE-2026-81446
HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could ...

CVSS 7.4 2026-09-17
CVE-2026-81445
HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could poten...

CVSS 7.2 2026-09-17
CVE-2026-80356
HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker wi...

CVSS 7.3 2026-09-17
CVE-2026-77614
HIGH

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in et...

CVSS 8.8 2026-09-17
CVE-2026-71538
HIGH

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpa...

CVSS 8.5 2026-09-17
CVE-2026-63460
HIGH

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern...

CVSS 7.5 2026-09-17
CVE-2026-63459
HIGH

Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components...

CVSS 8.7 2026-09-17
CVE-2026-26950
HIGH

Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could pote...

CVSS 8.1 2026-09-17
CVE-2026-92972
HIGH

SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV ...

CVSS 8.6 2026-09-17
CVE-2026-92971
HIGH

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inferenc...

CVSS 7.5 2026-09-17
CVE-2026-92970
HIGH

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the pr...

CVSS 8.8 2026-09-17
CVE-2026-92961
HIGH

vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers ...

CVSS 7.5 2026-09-17
CVE-2026-92959
HIGH

vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not availabl...

CVSS 7.1 2026-09-17
CVE-2026-92958
HIGH

vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '...

CVSS 8.5 2026-09-17
CVE-2026-92954
HIGH

vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as ...

CVSS 8.6 2026-09-17
CVE-2026-92950
HIGH

vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malici...

CVSS 8.6 2026-09-17
CVE-2026-92942
HIGH

vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the singl...

CVSS 7.5 2026-09-17
CVE-2026-90986
HIGH

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.

CVSS 7.1 2026-09-17
CVE-2026-90887
HIGH

Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.

CVSS 7.1 2026-09-17
CVE-2026-89418
HIGH

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to ...

CVSS 8.7 2026-09-17
1 4 5 6 7 8 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.