CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 6 of 500
CVE-2026-66575
MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

CVSS 5.3 2026-09-17
CVE-2026-66574
MEDIUM

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

CVSS 6.5 2026-09-17
CVE-2026-66573
MEDIUM

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

CVSS 6.5 2026-09-17
CVE-2026-66572
MEDIUM

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

CVSS 6.5 2026-09-17
CVE-2026-92932
MEDIUM

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The ...

CVSS 5.1 2026-09-17
CVE-2026-92920
MEDIUM

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can...

CVSS 5.4 2026-09-17
CVE-2026-92912
MEDIUM

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately ...

CVSS 6.5 2026-09-17
CVE-2026-81479
MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially ...

CVSS 5.8 2026-09-17
CVE-2026-78296
MEDIUM

Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

CVSS 5.3 2026-09-17
CVE-2026-90982
MEDIUM

@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the de...

CVSS 5.3 2026-09-17
CVE-2026-44940
MEDIUM

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker...

CVSS 5.7 2026-09-17
CVE-2026-91016
MEDIUM

The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated att...

CVSS 5.3 2026-09-17
CVE-2026-91015
MEDIUM

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on...

CVSS 5.3 2026-09-17
CVE-2026-91011
MEDIUM

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level ...

CVSS 6.8 2026-09-17
CVE-2026-90923
MEDIUM

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment p...

CVSS 6.5 2026-09-17
CVE-2026-90922
MEDIUM

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before comp...

CVSS 5.3 2026-09-17
CVE-2026-86788
MEDIUM

The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a sa...

CVSS 6.8 2026-09-17
CVE-2026-25261
MEDIUM

Memory corruption while processing rear sensor IOCTL calls.

CVSS 6.7 2026-09-17
CVE-2026-86311
MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and...

CVSS 6.4 2026-09-17
CVE-2026-89064
MEDIUM

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_M...

CVSS 5.3 2026-09-17
1 4 5 6 7 8 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.