Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,661 CVEs · Low severity

CVEs (15,661, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 15,661 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-58009 LOW 3.8 2025-09-22 Missing Authorization vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Exploiting Incorrectly Configured Access Control Security Leve…
CVE-2025-56556 LOW 3.8 2025-09-11 An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin …
CVE-2025-8889 LOW Patched 3.8 2025-09-09 The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the …
CVE-2025-57807 LOW Patched 3.8 2025-09-05 ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(…
CVE-2025-8298 LOW Patched 3.8 2025-09-02 Realtek RTL8811AU rtwlanu.sys N6CQueryInformationHandleCustomized11nOids Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers …
CVE-2025-3456 LOW 3.8 2025-08-25 On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both …
CVE-2025-53971 LOW Patched 3.8 2025-08-21 Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team M&hellip;
CVE-2025-8013 LOW 3.8 2025-08-15 The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' f&hellip;
CVE-2025-36581 LOW Patched 3.8 2025-08-14 Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with&hellip;
CVE-2025-26863 LOW 3.8 2025-08-12 Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially&hellip;
CVE-2025-48709 LOW Patched 3.8 2025-08-07 BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentia&hellip;
CVE-2025-46094 LOW Patched 3.8 2025-08-04 LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.
CVE-2025-54085 LOW Patched 3.8 2025-07-31 CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who ha&hellip;
CVE-2024-36348 LOW 3.8 2025-07-08 A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentiall&hellip;
CVE-2024-36349 LOW 3.8 2025-07-08 A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information&hellip;
CVE-2025-6943 LOW Patched 3.8 2025-07-02 Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.
CVE-2025-6942 LOW 3.8 2025-07-02 The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow a&hellip;
CVE-2025-24388 LOW 3.8 2025-06-16 A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This i&hellip;
CVE-2025-5715 LOW 3.8 2025-06-06 A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentic&hellip;
CVE-2025-20276 LOW 3.8 2025-06-04 A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To&hellip;
CVE-2025-47938 LOW Patched 3.8 2025-05-20 TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and &hellip;
CVE-2025-27566 LOW Patched 3.8 2025-05-19 Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the&hellip;
CVE-2024-31150 LOW 3.8 2025-05-13 Out-of-bounds read for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2025-27132 LOW Patched 3.8 2025-05-06 in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploi&hellip;
CVE-2025-32971 LOW Patched 3.8 2025-04-30 XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Sol&hellip;