CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 7 of 500
CVE-2026-61589
MEDIUM

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime...

CVSS 6.3 2026-09-16
CVE-2026-61588
MEDIUM

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to...

CVSS 6.5 2026-09-16
CVE-2026-92598
MEDIUM

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than stand...

CVSS 6.5 2026-09-16
CVE-2026-92597
MEDIUM

Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the...

CVSS 6.5 2026-09-16
CVE-2026-92595
MEDIUM

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved throug...

CVSS 5.9 2026-09-16
CVE-2026-92591
MEDIUM

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-si...

CVSS 5.9 2026-09-16
CVE-2026-92590
MEDIUM

Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode...

CVSS 5.4 2026-09-16
CVE-2026-92587
MEDIUM

n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then ...

CVSS 5 2026-09-16
CVE-2026-92584
MEDIUM

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php ...

CVSS 6.1 2026-09-16
CVE-2026-92583
MEDIUM

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limit...

CVSS 6.5 2026-09-16
CVE-2026-92579
MEDIUM

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filen...

CVSS 5.4 2026-09-16
CVE-2026-89034
MEDIUM

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to...

CVSS 6.5 2026-09-16
CVE-2026-64684
MEDIUM

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_h...

CVSS 6.8 2026-09-16
CVE-2026-61597
MEDIUM

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (...

CVSS 5.1 2026-09-16
CVE-2026-92812
MEDIUM

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can ...

CVSS 6.8 2026-09-16
CVE-2026-92811
MEDIUM

browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary file...

CVSS 6.5 2026-09-16
CVE-2026-92803
MEDIUM

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requir...

CVSS 5.3 2026-09-16
CVE-2026-92800
MEDIUM

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read a...

CVSS 6.8 2026-09-16
CVE-2026-92795
MEDIUM

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attacke...

CVSS 6.5 2026-09-16
CVE-2026-92790
MEDIUM

Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI toke...

CVSS 6.5 2026-09-16
1 5 6 7 8 9 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.