Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-6990 LOW 3.5 2026-04-25 A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of…
CVE-2026-6986 LOW Patched 3.7 2026-04-25 A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component…
CVE-2026-6976 LOW Patched 3.7 2026-06-11 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions c…
CVE-2026-69238 LOW Patched 3.5 2026-08-21 There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into th…
CVE-2026-69237 LOW Patched 3.8 2026-08-21 There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary …
CVE-2026-6923 LOW 3.8 2026-05-14 A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.
CVE-2026-68927 LOW Patched 3.0 2026-08-18 MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only…
CVE-2026-6883 LOW Patched 2.6 2026-05-14 GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authen…
CVE-2026-68744 LOW 3.3 2026-08-04 A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet wh…
CVE-2026-6873 LOW Patched 3.1 2026-06-03 An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concat…
CVE-2026-6842 LOW 2.5 2026-04-22 A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.lo…
CVE-2026-6830 LOW 3.3 2026-04-21 nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile…
CVE-2026-6816 LOW Patched 3.8 2026-05-28 An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issu…
CVE-2026-6745 LOW 3.5 2026-04-21 A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulatio…
CVE-2026-67442 LOW Patched 2.0 2026-08-18 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage…
CVE-2026-6743 LOW 3.5 2026-04-21 A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The …
CVE-2026-67334 LOW Patched 3.8 2026-08-01 better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeS…
CVE-2026-6733 LOW Patched 3.7 2026-06-17 Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HT…
CVE-2026-67319 LOW Patched 3.7 2026-08-01 axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already b…
CVE-2026-66788 LOW 3.7 2026-08-20 A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is de…
CVE-2026-66785 LOW 2.5 2026-08-20 A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishin…
CVE-2026-66774 LOW 3.7 2026-08-11 SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploi…
CVE-2026-66753 LOW 3.7 2026-07-28 tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header …
CVE-2026-66721 LOW Patched 2.7 2026-08-21 Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, …
CVE-2026-6651 LOW 2.4 2026-04-20 A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipula…