Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 15,635 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14325 | LOW | Patched | 3.5 | 2026-08-21 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-e… |
| CVE-2026-16577 | LOW | Patched | 2.7 | 2026-08-21 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's a… |
| CVE-2026-76137 | LOW | 3.3 | 2026-08-21 | Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance… | |
| CVE-2026-43679 | LOW | Patched | 2.4 | 2026-08-21 | This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to vi… |
| CVE-2026-77648 | LOW | 2.2 | 2026-08-20 | In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance … | |
| CVE-2026-49245 | LOW | Patched | 3.7 | 2026-08-20 | SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-f… |
| CVE-2026-77640 | LOW | Patched | 3.7 | 2026-08-20 | tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib … |
| CVE-2026-77151 | LOW | 3.7 | 2026-08-20 | A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of the file internal/util/crypto/crypto.go. Performing a… | |
| CVE-2026-66785 | LOW | 2.5 | 2026-08-20 | A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishin… | |
| CVE-2026-66788 | LOW | 3.7 | 2026-08-20 | A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is de… | |
| CVE-2026-49996 | LOW | 3.7 | 2026-08-20 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a mali… | |
| CVE-2026-64846 | LOW | Patched | 2.8 | 2026-08-20 | Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-o… |
| CVE-2026-18278 | LOW | 3.5 | 2026-08-20 | Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive inf… | |
| CVE-2026-18280 | LOW | 3.9 | 2026-08-20 | Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected in… | |
| CVE-2026-18283 | LOW | 2.4 | 2026-08-20 | Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations … | |
| CVE-2026-19699 | LOW | Patched | 2.7 | 2026-08-20 | The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and abov… |
| CVE-2026-73542 | LOW | 3.7 | 2026-08-20 | Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by t… | |
| CVE-2026-76926 | LOW | Patched | 3.1 | 2026-08-19 | BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-76890 | LOW | Patched | 3.1 | 2026-08-19 | Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-76891 | LOW | Patched | 3.1 | 2026-08-19 | Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-76884 | LOW | Patched | 3.1 | 2026-08-19 | ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-76885 | LOW | Patched | 3.1 | 2026-08-19 | Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-76887 | LOW | Patched | 3.1 | 2026-08-19 | Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-76888 | LOW | Patched | 3.1 | 2026-08-19 | RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-76368 | LOW | Patched | 2.7 | 2026-08-19 | In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata about a playbook repository that they are not a… |