Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 15,635 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19749 | LOW | 3.7 | 2026-08-13 | A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown… | |
| CVE-2026-17071 | LOW | 2.7 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal. | |
| CVE-2026-17074 | LOW | 3.1 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper privilege management. | |
| CVE-2026-17043 | LOW | Patched | 3.8 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. |
| CVE-2026-58445 | LOW | 2.7 | 2026-08-13 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | |
| CVE-2026-58511 | LOW | 2.7 | 2026-08-13 | Webhook Authorization Header Returned in Plaintext via API | |
| CVE-2026-55984 | LOW | 2.7 | 2026-08-13 | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | |
| CVE-2026-23603 | LOW | 3.1 | 2026-08-13 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | |
| CVE-2026-73571 | LOW | Patched | 3.1 | 2026-08-13 | An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality.… |
| CVE-2026-73573 | LOW | Patched | 3.1 | 2026-08-13 | In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the… |
| CVE-2026-73574 | LOW | Patched | 3.1 | 2026-08-13 | In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request para… |
| CVE-2026-73575 | LOW | Patched | 3.1 | 2026-08-13 | In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (… |
| CVE-2025-62315 | LOW | 3.4 | 2026-08-13 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by th… | |
| CVE-2025-62318 | LOW | 3.7 | 2026-08-13 | HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be c… | |
| CVE-2026-6469 | LOW | Patched | 3.8 | 2026-08-13 | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows th… |
| CVE-2026-16241 | LOW | Patched | 3.8 | 2026-08-13 | Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking… |
| CVE-2026-14673 | LOW | Patched | 3.8 | 2026-08-13 | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that d… |
| CVE-2026-14213 | LOW | Patched | 3.7 | 2026-08-13 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment bei… |
| CVE-2026-48791 | LOW | Patched | 2.0 | 2026-08-13 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) a… |
| CVE-2026-73425 | LOW | Patched | 3.7 | 2026-08-12 | Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written t… |
| CVE-2026-18096 | LOW | 3.3 | 2026-08-12 | IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak. | |
| CVE-2025-9486 | LOW | Patched | 3.3 | 2026-08-12 | GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could h… |
| CVE-2026-11937 | LOW | Patched | 3.1 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Sec… |
| CVE-2026-18246 | LOW | 3.0 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an interpretation conflict in the multipart parser. | |
| CVE-2026-65926 | LOW | 3.1 | 2026-08-12 | An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known. |