Search
15,661 CVEs · Low severity
CVEs (15,661, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 15,661 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22404 | LOW | 3.8 | 2026-01-22 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorrectly Configured Access Control Security Levels.This… | |
| CVE-2026-22406 | LOW | 3.8 | 2026-01-22 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorrectly Configured Access Control Security Levels.This… | |
| CVE-2026-22407 | LOW | 3.8 | 2026-01-22 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… | |
| CVE-2026-22409 | LOW | 3.8 | 2026-01-22 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Incorrectly Configured Access Control Security Levels.Th… | |
| CVE-2025-47555 | LOW | 3.8 | 2026-01-22 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… | |
| CVE-2026-22919 | LOW | Patched | 3.8 | 2026-01-15 | An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction … |
| CVE-2025-67685 | LOW | Patched | 3.8 | 2026-01-13 | A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all… |
| CVE-2026-0504 | LOW | 3.8 | 2026-01-13 | Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests tha… | |
| CVE-2025-69015 | LOW | 3.8 | 2025-12-30 | Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… | |
| CVE-2025-15187 | LOW | Patched | 3.8 | 2025-12-29 | A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of the component File Handler. Performing a manipulation… |
| CVE-2025-36228 | LOW | Patched | 3.8 | 2025-12-26 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disa… |
| CVE-2025-67742 | LOW | Patched | 3.8 | 2025-12-11 | In JetBrains TeamCity before 2025.11 path traversal was possible via file upload |
| CVE-2025-54560 | LOW | Patched | 3.8 | 2025-11-14 | A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infr… |
| CVE-2025-64170 | LOW | 3.8 | 2025-11-12 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does… | |
| CVE-2025-30509 | LOW | Patched | 3.8 | 2025-11-11 | Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System … |
| CVE-2025-20622 | LOW | 3.8 | 2025-11-11 | Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before version 32.0.100.4023 within Ring 3: User Applications… | |
| CVE-2025-64350 | LOW | 3.8 | 2025-10-31 | Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec… | |
| CVE-2025-10931 | LOW | Patched | 3.8 | 2025-10-30 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analytics allows Cross-Site Scripting (XSS).This issue af… |
| CVE-2025-62794 | LOW | Patched | 3.8 | 2025-10-28 | GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token wou… |
| CVE-2025-61924 | LOW | Patched | 3.8 | 2025-10-16 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking… |
| CVE-2025-62412 | LOW | Patched | 3.8 | 2025-10-16 | LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to in… |
| CVE-2025-8594 | LOW | Patched | 3.8 | 2025-10-14 | The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perf… |
| CVE-2025-58578 | LOW | 3.8 | 2025-10-06 | A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanis… | |
| CVE-2025-10306 | LOW | 3.8 | 2025-10-03 | The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup… | |
| CVE-2025-10871 | LOW | Patched | 3.8 | 2025-09-26 | An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vuln… |