Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,661 CVEs · Low severity

CVEs (15,661, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 15,661 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-22404 LOW 3.8 2026-01-22 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorrectly Configured Access Control Security Levels.This…
CVE-2026-22406 LOW 3.8 2026-01-22 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorrectly Configured Access Control Security Levels.This…
CVE-2026-22407 LOW 3.8 2026-01-22 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…
CVE-2026-22409 LOW 3.8 2026-01-22 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Incorrectly Configured Access Control Security Levels.Th…
CVE-2025-47555 LOW 3.8 2026-01-22 Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…
CVE-2026-22919 LOW Patched 3.8 2026-01-15 An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction …
CVE-2025-67685 LOW Patched 3.8 2026-01-13 A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all…
CVE-2026-0504 LOW 3.8 2026-01-13 Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests tha…
CVE-2025-69015 LOW 3.8 2025-12-30 Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…
CVE-2025-15187 LOW Patched 3.8 2025-12-29 A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of the component File Handler. Performing a manipulation…
CVE-2025-36228 LOW Patched 3.8 2025-12-26 IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disa…
CVE-2025-67742 LOW Patched 3.8 2025-12-11 In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
CVE-2025-54560 LOW Patched 3.8 2025-11-14 A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infr…
CVE-2025-64170 LOW 3.8 2025-11-12 sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does…
CVE-2025-30509 LOW Patched 3.8 2025-11-11 Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System …
CVE-2025-20622 LOW 3.8 2025-11-11 Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before version 32.0.100.4023 within Ring 3: User Applications…
CVE-2025-64350 LOW 3.8 2025-10-31 Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…
CVE-2025-10931 LOW Patched 3.8 2025-10-30 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analytics allows Cross-Site Scripting (XSS).This issue af…
CVE-2025-62794 LOW Patched 3.8 2025-10-28 GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token wou…
CVE-2025-61924 LOW Patched 3.8 2025-10-16 PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking…
CVE-2025-62412 LOW Patched 3.8 2025-10-16 LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to in…
CVE-2025-8594 LOW Patched 3.8 2025-10-14 The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perf…
CVE-2025-58578 LOW 3.8 2025-10-06 A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanis…
CVE-2025-10306 LOW 3.8 2025-10-03 The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup…
CVE-2025-10871 LOW Patched 3.8 2025-09-26 An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vuln…