Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,095 CVEs · Low severity

CVEs (15,095, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 15,095 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-5379 LOW Patched 3.0 2026-04-07 An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: In…
CVE-2026-53763 LOW Patched 3.8 2026-07-06 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting i…
CVE-2026-5375 LOW Patched 2.7 2026-04-07 An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of…
CVE-2026-5370 LOW 3.5 2026-04-02 A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts…
CVE-2026-53663 LOW Patched 3.1 2026-06-22 React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were byp…
CVE-2026-53607 LOW 3.7 2026-06-12 ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a do…
CVE-2026-5360 LOW 3.7 2026-04-02 A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack ma…
CVE-2026-53540 LOW Patched 3.7 2026-06-22 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked r…
CVE-2026-53538 LOW Patched 3.7 2026-06-22 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, …
CVE-2026-53537 LOW Patched 3.7 2026-06-22 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.…
CVE-2026-53480 LOW Patched 2.7 2026-07-08 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 rel…
CVE-2026-5332 LOW 3.5 2026-04-02 A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the a…
CVE-2026-5325 LOW 3.5 2026-04-02 A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.p…
CVE-2026-5310 LOW 2.5 2026-04-01 A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to us…
CVE-2026-52841 LOW 3.1 2026-07-14 Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `p…
CVE-2026-52840 LOW 2.7 2026-07-14 Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the reque…
CVE-2026-52839 LOW 3.3 2026-07-14 Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, provi…
CVE-2026-52838 LOW 2.6 2026-07-14 Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking set…
CVE-2026-52796 LOW Patched 3.5 2026-06-24 Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In …
CVE-2026-52686 LOW 3.7 2026-07-23 The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME o…
CVE-2026-52684 LOW 3.7 2026-07-23 If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then th…
CVE-2026-5254 LOW 3.5 2026-04-01 A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTr…
CVE-2026-5253 LOW 3.5 2026-04-01 A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageLi…
CVE-2026-5252 LOW 3.5 2026-04-01 A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint.…
CVE-2026-5249 LOW 3.5 2026-04-01 A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoin…