Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-44459 LOW Patched 3.8 2026-05-13 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat …
CVE-2026-34094 LOW Patched 3.8 2026-05-11 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * be…
CVE-2026-44987 LOW Patched 3.8 2026-05-08 SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email addresses of users with "Su…
CVE-2026-31051 LOW 3.8 2026-04-24 An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component
CVE-2026-22014 LOW 3.8 2026-04-21 Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-1…
CVE-2026-3470 LOW Patched 3.8 2026-03-31 A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attack…
CVE-2025-66215 LOW Patched 3.8 2026-03-30 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a…
CVE-2025-49010 LOW Patched 3.8 2026-03-30 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a…
CVE-2026-2290 LOW 3.8 2026-03-21 The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.28.0. This makes it possible for authentica…
CVE-2026-26230 LOW Patched 3.8 2026-03-16 Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote m&hellip;
CVE-2026-4222 LOW 3.8 2026-03-16 A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/downl&hellip;
CVE-2026-32715 LOW Patched 3.8 2026-03-16 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-pr&hellip;
CVE-2026-0849 LOW 3.8 2026-03-16 Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to c&hellip;
CVE-2026-4044 LOW 3.8 2026-03-12 A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a ma&hellip;
CVE-2026-27150 LOW Patched 3.8 2026-02-26 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_before_create` authorization in Data Explorer's `Que&hellip;
CVE-2026-27152 LOW Patched 3.8 2026-02-26 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-preference bypass when adding members via `Chat::AddU&hellip;
CVE-2025-67860 LOW 3.8 2026-02-25 A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially ex&hellip;
CVE-2025-15589 LOW 3.8 2026-02-24 A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Mana&hellip;
CVE-2026-25423 LOW 3.8 2026-02-19 Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Level&hellip;
CVE-2026-2733 LOW 3.8 2026-02-19 A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively&hellip;
CVE-2025-36183 LOW Patched 3.8 2026-02-17 IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.
CVE-2025-14573 LOW Patched 3.8 2026-02-16 Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass&hellip;
CVE-2025-22873 LOW Patched 3.8 2026-02-04 It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory&hellip;
CVE-2026-22411 LOW 3.8 2026-01-22 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorrectly Configured Access Control Security Levels.This&hellip;
CVE-2026-22404 LOW 3.8 2026-01-22 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorrectly Configured Access Control Security Levels.This&hellip;