Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 15,635 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73743 | LOW | Patched | 3.7 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handle… |
| CVE-2026-7364 | LOW | Patched | 3.1 | 2026-07-17 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Sec… |
| CVE-2026-7360 | LOW | Patched | 3.1 | 2026-04-28 | Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to by… |
| CVE-2026-73575 | LOW | Patched | 3.1 | 2026-08-13 | In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (… |
| CVE-2026-73574 | LOW | Patched | 3.1 | 2026-08-13 | In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request para… |
| CVE-2026-73573 | LOW | Patched | 3.1 | 2026-08-13 | In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the… |
| CVE-2026-73571 | LOW | Patched | 3.1 | 2026-08-13 | An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality.… |
| CVE-2026-73542 | LOW | 3.7 | 2026-08-20 | Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by t… | |
| CVE-2026-7351 | LOW | Patched | 3.1 | 2026-04-28 | Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chr… |
| CVE-2026-73425 | LOW | Patched | 3.7 | 2026-08-12 | Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written t… |
| CVE-2026-73318 | LOW | Patched | 3.8 | 2026-09-08 | XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreemen… |
| CVE-2026-73317 | LOW | Patched | 2.7 | 2026-09-08 | XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permi… |
| CVE-2026-73283 | LOW | Patched | 2.5 | 2026-08-11 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. |
| CVE-2026-73281 | LOW | Patched | 3.5 | 2026-08-11 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is c… |
| CVE-2026-73071 | LOW | Patched | 3.3 | 2026-08-11 | Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invoke… |
| CVE-2026-7303 | LOW | 3.7 | 2026-04-28 | A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controll… | |
| CVE-2026-7297 | LOW | 2.4 | 2026-04-28 | A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_use… | |
| CVE-2026-7296 | LOW | 2.4 | 2026-04-28 | A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a m… | |
| CVE-2026-7295 | LOW | 2.4 | 2026-04-28 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu… | |
| CVE-2026-7294 | LOW | 2.4 | 2026-04-28 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_se… | |
| CVE-2026-7281 | LOW | 2.4 | 2026-04-28 | A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier… | |
| CVE-2026-72701 | LOW | Patched | 3.7 | 2026-08-25 | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() … |
| CVE-2026-7269 | LOW | 2.4 | 2026-04-28 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /index.php?page=product. Performing a manip… | |
| CVE-2026-7233 | LOW | Patched | 3.3 | 2026-04-28 | A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Inde… |
| CVE-2026-7222 | LOW | 3.5 | 2026-04-28 | A vulnerability was determined in code-projects Coaching Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /cims/modules/student… |