Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,095 CVEs · Low severity

CVEs (15,095, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 15,095 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-40208 LOW 3.7 2026-06-25 An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.
CVE-2026-3176 LOW Patched 3.1 2026-06-25 GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could …
CVE-2026-0934 LOW Patched 3.8 2026-06-25 GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could …
CVE-2026-8662 LOW Patched 3.3 2026-06-25 Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file …
CVE-2026-49979 LOW Patched 2.7 2026-06-24 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smt…
CVE-2026-39894 LOW Patched 2.9 2026-06-24 Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can c…
CVE-2026-52796 LOW Patched 3.5 2026-06-24 Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In …
CVE-2026-57288 LOW Patched 3.7 2026-06-24 Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, al…
CVE-2026-56368 LOW Patched 3.7 2026-06-24 ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can …
CVE-2026-56370 LOW Patched 3.3 2026-06-24 ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices…
CVE-2026-10753 LOW Patched 2.7 2026-06-24 The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have bee…
CVE-2026-46549 LOW Patched 2.0 2026-06-23 NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user…
CVE-2026-54326 LOW Patched 2.5 2026-06-23 Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Ma…
CVE-2026-54327 LOW Patched 2.2 2026-06-23 Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the file write path could brie…
CVE-2026-57062 LOW 2.9 2026-06-23 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes …
CVE-2026-56968 LOW Patched 3.7 2026-06-23 GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
CVE-2025-15619 LOW 3.5 2026-06-23 HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.
CVE-2026-56376 LOW Patched 3.7 2026-06-23 ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remot…
CVE-2026-55654 LOW 3.7 2026-06-23 A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface)…
CVE-2026-49460 LOW Patched 3.3 2026-06-22 pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This require…
CVE-2026-48931 LOW 3.7 2026-06-22 A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all support…
CVE-2026-53663 LOW Patched 3.1 2026-06-22 React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were byp…
CVE-2026-54282 LOW Patched 3.7 2026-06-22 Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url …
CVE-2026-53537 LOW Patched 3.7 2026-06-22 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.…
CVE-2026-53538 LOW Patched 3.7 2026-06-22 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, …