Search
15,661 CVEs · Low severity
CVEs (15,661, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 15,661 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58009 | LOW | 3.8 | 2025-09-22 | Missing Authorization vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Exploiting Incorrectly Configured Access Control Security Leve… | |
| CVE-2025-56556 | LOW | 3.8 | 2025-09-11 | An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin … | |
| CVE-2025-8889 | LOW | Patched | 3.8 | 2025-09-09 | The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the … |
| CVE-2025-57807 | LOW | Patched | 3.8 | 2025-09-05 | ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(… |
| CVE-2025-8298 | LOW | Patched | 3.8 | 2025-09-02 | Realtek RTL8811AU rtwlanu.sys N6CQueryInformationHandleCustomized11nOids Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers … |
| CVE-2025-3456 | LOW | 3.8 | 2025-08-25 | On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both … | |
| CVE-2025-53971 | LOW | Patched | 3.8 | 2025-08-21 | Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team M… |
| CVE-2025-8013 | LOW | 3.8 | 2025-08-15 | The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' f… | |
| CVE-2025-36581 | LOW | Patched | 3.8 | 2025-08-14 | Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with… |
| CVE-2025-26863 | LOW | 3.8 | 2025-08-12 | Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially… | |
| CVE-2025-48709 | LOW | Patched | 3.8 | 2025-08-07 | BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentia… |
| CVE-2025-46094 | LOW | Patched | 3.8 | 2025-08-04 | LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript. |
| CVE-2025-54085 | LOW | Patched | 3.8 | 2025-07-31 | CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who ha… |
| CVE-2024-36348 | LOW | 3.8 | 2025-07-08 | A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentiall… | |
| CVE-2024-36349 | LOW | 3.8 | 2025-07-08 | A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information… | |
| CVE-2025-6943 | LOW | Patched | 3.8 | 2025-07-02 | Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables. |
| CVE-2025-6942 | LOW | 3.8 | 2025-07-02 | The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow a… | |
| CVE-2025-24388 | LOW | 3.8 | 2025-06-16 | A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This i… | |
| CVE-2025-5715 | LOW | 3.8 | 2025-06-06 | A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentic… | |
| CVE-2025-20276 | LOW | 3.8 | 2025-06-04 | A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To… | |
| CVE-2025-47938 | LOW | Patched | 3.8 | 2025-05-20 | TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and … |
| CVE-2025-27566 | LOW | Patched | 3.8 | 2025-05-19 | Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the… |
| CVE-2024-31150 | LOW | 3.8 | 2025-05-13 | Out-of-bounds read for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable information disclosure via local access. | |
| CVE-2025-27132 | LOW | Patched | 3.8 | 2025-05-06 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploi… |
| CVE-2025-32971 | LOW | Patched | 3.8 | 2025-04-30 | XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Sol… |