Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 15,635 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78587 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctl… |
| CVE-2026-7847 | LOW | 2.6 | 2026-05-05 | A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/se… | |
| CVE-2026-7846 | LOW | 2.6 | 2026-05-05 | A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_serve… | |
| CVE-2026-7845 | LOW | 2.6 | 2026-05-05 | A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_… | |
| CVE-2026-78435 | LOW | 3.8 | 2026-08-24 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the … | |
| CVE-2026-7837 | LOW | 3.7 | 2026-05-21 | A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote a… | |
| CVE-2026-78364 | LOW | Patched | 3.5 | 2026-08-30 | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allo… |
| CVE-2026-7836 | LOW | 3.1 | 2026-05-21 | An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause … | |
| CVE-2026-7835 | LOW | 3.1 | 2026-05-21 | A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers … | |
| CVE-2026-78187 | LOW | 3.1 | 2026-08-24 | A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads … | |
| CVE-2026-78150 | LOW | Patched | 2.7 | 2026-09-05 | The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges … |
| CVE-2026-78049 | LOW | 3.7 | 2026-08-22 | A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes of the file src/ClientServer/add… | |
| CVE-2026-77787 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object iden… |
| CVE-2026-77785 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning … |
| CVE-2026-77784 | LOW | Patched | 2.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allow… |
| CVE-2026-77783 | LOW | Patched | 3.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated vis… |
| CVE-2026-77704 | LOW | Patched | 2.7 | 2026-08-29 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appoi… |
| CVE-2026-77648 | LOW | 2.2 | 2026-08-20 | In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance … | |
| CVE-2026-77640 | LOW | Patched | 3.7 | 2026-08-20 | tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib … |
| CVE-2026-77573 | LOW | Patched | 3.5 | 2026-08-26 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository U… |
| CVE-2026-77508 | LOW | Patched | 3.5 | 2026-08-26 | Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{usernam… |
| CVE-2026-7740 | LOW | 3.3 | 2026-05-04 | A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit::setFPS of the file tsMuxer/vvc.cpp. Such manipulati… | |
| CVE-2026-7739 | LOW | 3.3 | 2026-05-04 | A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::setFPS of the file /AFLplusplus/tsMuxer_prev/tsMuxer/h… | |
| CVE-2026-77351 | LOW | Patched | 3.5 | 2026-08-31 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including p… |
| CVE-2026-77151 | LOW | 3.7 | 2026-08-20 | A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of the file internal/util/crypto/crypto.go. Performing a… |