Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 15,095 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5379 | LOW | Patched | 3.0 | 2026-04-07 | An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: In… |
| CVE-2026-53763 | LOW | Patched | 3.8 | 2026-07-06 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting i… |
| CVE-2026-5375 | LOW | Patched | 2.7 | 2026-04-07 | An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of… |
| CVE-2026-5370 | LOW | 3.5 | 2026-04-02 | A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts… | |
| CVE-2026-53663 | LOW | Patched | 3.1 | 2026-06-22 | React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were byp… |
| CVE-2026-53607 | LOW | 3.7 | 2026-06-12 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a do… | |
| CVE-2026-5360 | LOW | 3.7 | 2026-04-02 | A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack ma… | |
| CVE-2026-53540 | LOW | Patched | 3.7 | 2026-06-22 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked r… |
| CVE-2026-53538 | LOW | Patched | 3.7 | 2026-06-22 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, … |
| CVE-2026-53537 | LOW | Patched | 3.7 | 2026-06-22 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.… |
| CVE-2026-53480 | LOW | Patched | 2.7 | 2026-07-08 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 rel… |
| CVE-2026-5332 | LOW | 3.5 | 2026-04-02 | A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the a… | |
| CVE-2026-5325 | LOW | 3.5 | 2026-04-02 | A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.p… | |
| CVE-2026-5310 | LOW | 2.5 | 2026-04-01 | A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to us… | |
| CVE-2026-52841 | LOW | 3.1 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `p… | |
| CVE-2026-52840 | LOW | 2.7 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the reque… | |
| CVE-2026-52839 | LOW | 3.3 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, provi… | |
| CVE-2026-52838 | LOW | 2.6 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking set… | |
| CVE-2026-52796 | LOW | Patched | 3.5 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In … |
| CVE-2026-52686 | LOW | 3.7 | 2026-07-23 | The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME o… | |
| CVE-2026-52684 | LOW | 3.7 | 2026-07-23 | If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then th… | |
| CVE-2026-5254 | LOW | 3.5 | 2026-04-01 | A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTr… | |
| CVE-2026-5253 | LOW | 3.5 | 2026-04-01 | A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageLi… | |
| CVE-2026-5252 | LOW | 3.5 | 2026-04-01 | A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint.… | |
| CVE-2026-5249 | LOW | 3.5 | 2026-04-01 | A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoin… |