Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 15,095 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40208 | LOW | 3.7 | 2026-06-25 | An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame. | |
| CVE-2026-3176 | LOW | Patched | 3.1 | 2026-06-25 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could … |
| CVE-2026-0934 | LOW | Patched | 3.8 | 2026-06-25 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could … |
| CVE-2026-8662 | LOW | Patched | 3.3 | 2026-06-25 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file … |
| CVE-2026-49979 | LOW | Patched | 2.7 | 2026-06-24 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smt… |
| CVE-2026-39894 | LOW | Patched | 2.9 | 2026-06-24 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can c… |
| CVE-2026-52796 | LOW | Patched | 3.5 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In … |
| CVE-2026-57288 | LOW | Patched | 3.7 | 2026-06-24 | Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, al… |
| CVE-2026-56368 | LOW | Patched | 3.7 | 2026-06-24 | ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can … |
| CVE-2026-56370 | LOW | Patched | 3.3 | 2026-06-24 | ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices… |
| CVE-2026-10753 | LOW | Patched | 2.7 | 2026-06-24 | The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have bee… |
| CVE-2026-46549 | LOW | Patched | 2.0 | 2026-06-23 | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user… |
| CVE-2026-54326 | LOW | Patched | 2.5 | 2026-06-23 | Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Ma… |
| CVE-2026-54327 | LOW | Patched | 2.2 | 2026-06-23 | Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the file write path could brie… |
| CVE-2026-57062 | LOW | 2.9 | 2026-06-23 | CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes … | |
| CVE-2026-56968 | LOW | Patched | 3.7 | 2026-06-23 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server. |
| CVE-2025-15619 | LOW | 3.5 | 2026-06-23 | HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario. | |
| CVE-2026-56376 | LOW | Patched | 3.7 | 2026-06-23 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remot… |
| CVE-2026-55654 | LOW | 3.7 | 2026-06-23 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface)… | |
| CVE-2026-49460 | LOW | Patched | 3.3 | 2026-06-22 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This require… |
| CVE-2026-48931 | LOW | 3.7 | 2026-06-22 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all support… | |
| CVE-2026-53663 | LOW | Patched | 3.1 | 2026-06-22 | React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were byp… |
| CVE-2026-54282 | LOW | Patched | 3.7 | 2026-06-22 | Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url … |
| CVE-2026-53537 | LOW | Patched | 3.7 | 2026-06-22 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.… |
| CVE-2026-53538 | LOW | Patched | 3.7 | 2026-06-22 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, … |