Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13116 | LOW | Patched | 3.8 | 2025-01-27 | The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cr… |
| CVE-2024-13450 | LOW | Patched | 3.8 | 2025-01-25 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Sid… |
| CVE-2025-21546 | LOW | Patched | 3.8 | 2025-01-21 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and p… |
| CVE-2023-42238 | LOW | Patched | 3.8 | 2025-01-13 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php. |
| CVE-2023-42239 | LOW | Patched | 3.8 | 2025-01-13 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_ep.php. |
| CVE-2023-42240 | LOW | Patched | 3.8 | 2025-01-13 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/… |
| CVE-2023-42241 | LOW | Patched | 3.8 | 2025-01-13 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_… |
| CVE-2023-42242 | LOW | Patched | 3.8 | 2025-01-13 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php. |
| CVE-2023-42235 | LOW | Patched | 3.8 | 2025-01-13 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_nor… |
| CVE-2023-42236 | LOW | Patched | 3.8 | 2025-01-13 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php. |
| CVE-2023-42237 | LOW | Patched | 3.8 | 2025-01-13 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i… |
| CVE-2024-13308 | LOW | Patched | 3.8 | 2025-01-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issu… |
| CVE-2025-22449 | LOW | Patched | 3.8 | 2025-01-09 | Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by upda… |
| CVE-2024-56321 | LOW | Patched | 3.8 | 2025-01-03 | GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to… |
| CVE-2023-23814 | LOW | 3.8 | 2024-12-09 | Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects C… | |
| CVE-2024-6156 | LOW | Patched | 3.8 | 2024-12-06 | Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store. |
| CVE-2024-6219 | LOW | Patched | 3.8 | 2024-12-06 | Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured. |
| CVE-2024-53502 | LOW | 3.8 | 2024-12-03 | Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page. | |
| CVE-2024-8160 | LOW | Patched | 3.8 | 2024-11-26 | Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command … |
| CVE-2024-5030 | LOW | Patched | 3.8 | 2024-11-18 | The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin… |
| CVE-2024-38660 | LOW | 3.8 | 2024-11-13 | Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated user to potentially enable escalation of privilege vi… | |
| CVE-2024-25565 | LOW | 3.8 | 2024-11-13 | Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access. | |
| CVE-2024-30142 | LOW | 3.8 | 2024-11-07 | HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthori… | |
| CVE-2024-20528 | LOW | Patched | 3.8 | 2024-11-06 | A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system of an affect… |
| CVE-2024-10228 | LOW | Patched | 3.8 | 2024-10-29 | The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for … |