CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 9 of 500
CVE-2026-50605
HIGH

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may all...

CVSS 7.4 2026-09-17
CVE-2026-87963
HIGH

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applie...

CVSS 8.6 2026-09-17
CVE-2026-86801
HIGH

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce c...

CVSS 8.8 2026-09-17
CVE-2026-91014
HIGH

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowin...

CVSS 7.1 2026-09-17
CVE-2026-88904
HIGH

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, ...

CVSS 8.8 2026-09-17
CVE-2026-88792
HIGH

The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated user...

CVSS 8.8 2026-09-17
CVE-2026-87786
HIGH

The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated u...

CVSS 8.8 2026-09-17
CVE-2026-85130
HIGH

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administra...

CVSS 8.8 2026-09-17
CVE-2026-85128
HIGH

The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing ...

CVSS 7.5 2026-09-17
CVE-2025-15697
HIGH

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated a...

CVSS 7.1 2026-09-17
CVE-2026-87935
HIGH

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to mis...

CVSS 8.1 2026-09-17
CVE-2026-25294
HIGH

Transient DOS while parsing frame during channel usage.

CVSS 7.4 2026-09-17
CVE-2026-25290
HIGH

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

CVSS 7.8 2026-09-17
CVE-2026-25284
HIGH

Information Disclosure when a pointer is reused after being deallocated.

CVSS 7.3 2026-09-17
CVE-2026-25283
HIGH

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

CVSS 8.8 2026-09-17
CVE-2026-25282
HIGH

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

CVSS 7.9 2026-09-17
CVE-2026-25281
HIGH

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

CVSS 7.4 2026-09-17
CVE-2026-25280
HIGH

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

CVSS 7.8 2026-09-17
CVE-2026-25278
HIGH

Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

CVSS 7.8 2026-09-17
CVE-2026-25275
HIGH

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

CVSS 7.5 2026-09-17
1 7 8 9 10 11 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.