CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 1 of 500
CVE-2026-92991
MEDIUM

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes i...

CVSS 5.4 2026-09-18
CVE-2026-15650
MEDIUM

The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all vers...

CVSS 6.4 2026-09-18
CVE-2026-14855
MEDIUM

The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient inp...

CVSS 6.4 2026-09-18
CVE-2026-93455
MEDIUM

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. ...

CVSS 6.5 2026-09-18
CVE-2026-93314
MEDIUM

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of th...

CVSS 6.3 2026-09-18
CVE-2026-93313
MEDIUM

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipu...

CVSS 6.3 2026-09-18
CVE-2026-82985
MEDIUM

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owne...

CVSS 6.5 2026-09-18
CVE-2026-82980
MEDIUM

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI witho...

CVSS 6.3 2026-09-18
CVE-2026-77169
MEDIUM

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-lev...

CVSS 6.5 2026-09-18
CVE-2026-77164
MEDIUM

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addr...

CVSS 6.2 2026-09-18
CVE-2026-93310
MEDIUM

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remot...

CVSS 5.3 2026-09-18
CVE-2026-93454
MEDIUM

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission...

CVSS 5.4 2026-09-18
CVE-2026-93451
MEDIUM

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by elemen...

CVSS 6.5 2026-09-18
CVE-2026-2585
MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to in...

CVSS 6.4 2026-09-18
CVE-2026-55946
MEDIUM

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 6.1 2026-09-17
CVE-2026-54648
MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM...

CVSS 6.5 2026-09-17
CVE-2026-54644
MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and w...

CVSS 6.1 2026-09-17
CVE-2026-54643
MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note par...

CVSS 5.4 2026-09-17
CVE-2026-54642
MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php us...

CVSS 5.3 2026-09-17
CVE-2026-54633
MEDIUM

PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfCol...

CVSS 6.9 2026-09-17
1 2 3 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.