CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 7 of 500
CVE-2026-82760
HIGH

Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a...

CVSS 8.2 2026-09-17
CVE-2026-82685
HIGH

Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email addr...

CVSS 7.6 2026-09-17
CVE-2026-81632
HIGH

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to rec...

CVSS 7.2 2026-09-17
CVE-2026-81442
HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potent...

CVSS 8.1 2026-09-17
CVE-2026-80218
HIGH

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a dif...

CVSS 7.6 2026-09-17
CVE-2026-78295
HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.

CVSS 8.8 2026-09-17
CVE-2026-66631
HIGH

Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

CVSS 7.6 2026-09-17
CVE-2026-66630
HIGH

Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

CVSS 7.6 2026-09-17
CVE-2026-66628
HIGH

Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.

CVSS 7.6 2026-09-17
CVE-2026-66626
HIGH

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

CVSS 7.6 2026-09-17
CVE-2026-66625
HIGH

Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

CVSS 7.6 2026-09-17
CVE-2026-66624
HIGH

Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

CVSS 7.6 2026-09-17
CVE-2026-66619
HIGH

Administrator SQL Injection in Newsletters <= 4.18 versions.

CVSS 7.6 2026-09-17
CVE-2026-66618
HIGH

Administrator SQL Injection in WP Maps <= 4.9.9 versions.

CVSS 7.6 2026-09-17
CVE-2026-66580
HIGH

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

CVSS 8.5 2026-09-17
CVE-2026-66571
HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

CVSS 7.1 2026-09-17
CVE-2026-14850
HIGH

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable ...

CVSS 8.8 2026-09-17
CVE-2026-92919
HIGH

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments....

CVSS 8.1 2026-09-17
CVE-2026-92918
HIGH

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON respo...

CVSS 8.8 2026-09-17
CVE-2026-81481
HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unaut...

CVSS 7.5 2026-09-17
1 5 6 7 8 9 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.