Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 15,635 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76042 | LOW | Patched | 3.1 | 2026-08-18 | Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the … |
| CVE-2026-76014 | LOW | 3.3 | 2026-08-19 | A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler.… | |
| CVE-2026-75904 | LOW | 3.3 | 2026-08-18 | libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXS… | |
| CVE-2026-75774 | LOW | 3.7 | 2026-08-18 | A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth… | |
| CVE-2026-75773 | LOW | 3.7 | 2026-08-18 | A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login E… | |
| CVE-2026-75587 | LOW | Patched | 3.6 | 2026-08-17 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's… |
| CVE-2026-75583 | LOW | 3.5 | 2026-08-19 | keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach p… | |
| CVE-2026-75483 | LOW | 3.3 | 2026-08-17 | powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in t… | |
| CVE-2026-75476 | LOW | 3.1 | 2026-08-19 | Tanium addressed a compression bomb vulnerability in Threat Response. | |
| CVE-2026-75052 | LOW | Patched | 3.6 | 2026-08-17 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects |
| CVE-2026-7501 | LOW | 3.5 | 2026-04-30 | A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a man… | |
| CVE-2026-74887 | LOW | Patched | 3.7 | 2026-08-17 | openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to ran… |
| CVE-2026-74885 | LOW | Patched | 3.6 | 2026-08-17 | openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and cor… |
| CVE-2026-74870 | LOW | Patched | 3.3 | 2026-08-17 | openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally … |
| CVE-2026-7487 | LOW | Patched | 3.5 | 2026-08-26 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an au… |
| CVE-2026-74797 | LOW | Patched | 3.1 | 2026-08-16 | OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module … |
| CVE-2026-7471 | LOW | Patched | 3.5 | 2026-05-14 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authen… |
| CVE-2026-73923 | LOW | 3.7 | 2026-08-18 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Difficult to ex… | |
| CVE-2026-7390 | LOW | 3.5 | 2026-04-29 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function Customer of the file /index.php?page=customer. … | |
| CVE-2026-73844 | LOW | Patched | 3.7 | 2026-08-14 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to th… |
| CVE-2026-73748 | LOW | Patched | 2.2 | 2026-09-01 | A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext… |
| CVE-2026-73747 | LOW | Patched | 2.5 | 2026-09-01 | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operato… |
| CVE-2026-73746 | LOW | Patched | 3.1 | 2026-09-01 | A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of ser… |
| CVE-2026-73745 | LOW | Patched | 3.1 | 2026-09-01 | A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system… |
| CVE-2026-73744 | LOW | Patched | 3.5 | 2026-09-01 | A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator us… |