CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 8 of 500
CVE-2026-92789
MEDIUM

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or ev...

CVSS 6.5 2026-09-16
CVE-2026-92781
MEDIUM

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters ...

CVSS 6.3 2026-09-16
CVE-2026-92778
MEDIUM

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form e...

CVSS 5.4 2026-09-16
CVE-2026-92775
MEDIUM

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validatio...

CVSS 6.5 2026-09-16
CVE-2026-92771
MEDIUM

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers w...

CVSS 6.5 2026-09-16
CVE-2026-92770
MEDIUM

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on t...

CVSS 6.5 2026-09-16
CVE-2026-92765
MEDIUM

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizati...

CVSS 6.5 2026-09-16
CVE-2026-92760
MEDIUM

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author...

CVSS 6.5 2026-09-16
CVE-2026-92759
MEDIUM

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API confi...

CVSS 6.5 2026-09-16
CVE-2026-92750
MEDIUM

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces the...

CVSS 6.5 2026-09-16
CVE-2026-92527
MEDIUM

A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads...

CVSS 6.3 2026-09-16
CVE-2026-81872
MEDIUM

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker...

CVSS 6.3 2026-09-16
CVE-2026-81871
MEDIUM

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_...

CVSS 6.3 2026-09-16
CVE-2026-81869
MEDIUM

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLeng...

CVSS 5.1 2026-09-16
CVE-2026-76447
MEDIUM

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative...

CVSS 5.3 2026-09-16
CVE-2026-76444
MEDIUM

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affect...

CVSS 5.3 2026-09-16
CVE-2026-76439
MEDIUM

A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit fo...

CVSS 5.3 2026-09-16
CVE-2026-76438
MEDIUM

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter ...

CVSS 6.5 2026-09-16
CVE-2026-76433
MEDIUM

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected ...

CVSS 5.3 2026-09-16
CVE-2026-20309
MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scri...

CVSS 6.1 2026-09-16
1 6 7 8 9 10 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.