Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-52651 LOW 3.5 2026-09-07 HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.
CVE-2026-86226 LOW 3.5 2026-09-06 A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipula…
CVE-2026-86181 LOW 3.5 2026-09-06 A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the c…
CVE-2025-15694 LOW Patched 3.5 2026-09-05 The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-p…
CVE-2026-85405 LOW 3.5 2026-09-04 A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument …
CVE-2026-85406 LOW 3.5 2026-09-04 A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to c…
CVE-2026-85207 LOW 3.5 2026-09-03 A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation…
CVE-2026-85022 LOW 3.5 2026-09-03 A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/comp…
CVE-2026-84653 LOW 3.5 2026-09-02 Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page…
CVE-2026-78600 LOW Patched 3.5 2026-09-02 Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after …
CVE-2026-19698 LOW Patched 3.5 2026-09-02 The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, a…
CVE-2025-15692 LOW Patched 3.5 2026-09-02 The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users…
CVE-2026-84437 LOW 3.5 2026-09-02 A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autoc…
CVE-2026-84438 LOW 3.5 2026-09-02 A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete W…
CVE-2026-73744 LOW Patched 3.5 2026-09-01 A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator us…
CVE-2026-81846 LOW Patched 3.5 2026-09-01 An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through Us…
CVE-2026-86486 LOW Patched 3.7 2026-09-07 In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
CVE-2026-86420 LOW Patched 3.7 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can …
CVE-2026-86421 LOW Patched 3.7 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allow…
CVE-2026-86231 LOW 3.7 2026-09-06 A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performi…
CVE-2026-81348 LOW Patched 3.7 2026-09-05 The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticat…
CVE-2026-85704 LOW 3.7 2026-09-04 A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file s…
CVE-2026-18540 LOW Patched 3.7 2026-09-04 undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original re…
CVE-2026-84947 LOW Patched 3.7 2026-09-04 undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the inte…
CVE-2026-85008 LOW Patched 3.7 2026-09-04 undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of sa…