Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,661 CVEs · Low severity

CVEs (15,661, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 15,661 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-65068 LOW Patched 3.8 2026-07-21 Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphas…
CVE-2026-64614 LOW Patched 3.8 2026-07-21 Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h wit…
CVE-2026-64617 LOW Patched 3.8 2026-07-21 Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h w…
CVE-2026-9820 LOW Patched 3.8 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager rol&hellip;
CVE-2026-56281 LOW Patched 3.8 2026-07-12 Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request bo&hellip;
CVE-2026-15326 LOW 3.8 2026-07-10 A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installat&hellip;
CVE-2026-59269 LOW Patched 3.8 2026-07-09 A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions w&hellip;
CVE-2026-42148 LOW Patched 3.8 2026-07-06 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Set&hellip;
CVE-2026-53763 LOW Patched 3.8 2026-07-06 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting i&hellip;
CVE-2026-42546 LOW Patched 3.8 2026-07-06 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting i&hellip;
CVE-2026-13322 LOW Patched 3.8 2026-06-26 A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely un&hellip;
CVE-2026-0934 LOW Patched 3.8 2026-06-25 GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could &hellip;
CVE-2026-8823 LOW Patched 3.8 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrad&hellip;
CVE-2026-8074 LOW Patched 3.8 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager wit&hellip;
CVE-2026-56212 LOW Patched 3.8 2026-06-20 Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authent&hellip;
CVE-2026-53809 LOW Patched 3.8 2026-06-11 OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of&hellip;
CVE-2025-12656 LOW 3.8 2026-06-06 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in t&hellip;
CVE-2026-45683 LOW Patched 3.8 2026-06-02 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled&hellip;
CVE-2026-10299 LOW 3.8 2026-06-01 A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This ma&hellip;
CVE-2026-40510 LOW Patched 3.8 2026-05-29 OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physicall&hellip;
CVE-2026-40528 LOW Patched 3.8 2026-05-29 OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows&hellip;
CVE-2026-6816 LOW Patched 3.8 2026-05-28 An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issu&hellip;
CVE-2026-44410 LOW 3.8 2026-05-26 This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's ex&hellip;
CVE-2026-3495 LOW Patched 3.8 2026-05-18 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an a&hellip;
CVE-2026-6923 LOW 3.8 2026-05-14 A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.