Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-78587 LOW Patched 3.1 2026-09-02 Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctl…
CVE-2026-7847 LOW 2.6 2026-05-05 A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/se…
CVE-2026-7846 LOW 2.6 2026-05-05 A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_serve…
CVE-2026-7845 LOW 2.6 2026-05-05 A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_…
CVE-2026-78435 LOW 3.8 2026-08-24 A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the …
CVE-2026-7837 LOW 3.7 2026-05-21 A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote a…
CVE-2026-78364 LOW Patched 3.5 2026-08-30 The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allo…
CVE-2026-7836 LOW 3.1 2026-05-21 An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause …
CVE-2026-7835 LOW 3.1 2026-05-21 A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers …
CVE-2026-78187 LOW 3.1 2026-08-24 A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads …
CVE-2026-78150 LOW Patched 2.7 2026-09-05 The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges …
CVE-2026-78049 LOW 3.7 2026-08-22 A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes of the file src/ClientServer/add…
CVE-2026-77787 LOW Patched 2.7 2026-09-02 The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object iden…
CVE-2026-77785 LOW Patched 2.7 2026-09-02 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning …
CVE-2026-77784 LOW Patched 2.7 2026-09-02 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allow…
CVE-2026-77783 LOW Patched 3.7 2026-09-02 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated vis…
CVE-2026-77704 LOW Patched 2.7 2026-08-29 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appoi…
CVE-2026-77648 LOW 2.2 2026-08-20 In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance …
CVE-2026-77640 LOW Patched 3.7 2026-08-20 tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib …
CVE-2026-77573 LOW Patched 3.5 2026-08-26 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository U…
CVE-2026-77508 LOW Patched 3.5 2026-08-26 Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{usernam…
CVE-2026-7740 LOW 3.3 2026-05-04 A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit::setFPS of the file tsMuxer/vvc.cpp. Such manipulati…
CVE-2026-7739 LOW 3.3 2026-05-04 A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::setFPS of the file /AFLplusplus/tsMuxer_prev/tsMuxer/h…
CVE-2026-77351 LOW Patched 3.5 2026-08-31 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including p…
CVE-2026-77151 LOW 3.7 2026-08-20 A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of the file internal/util/crypto/crypto.go. Performing a…