Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46897 | LOW | Patched | 3.8 | 2024-10-18 | Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in user with the permission of tabl… |
| CVE-2024-21247 | LOW | Patched | 3.8 | 2024-10-15 | Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9… |
| CVE-2024-45599 | LOW | 3.8 | 2024-09-25 | Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run… | |
| CVE-2024-8612 | LOW | 3.8 | 2024-09-20 | A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complet… | |
| CVE-2024-8694 | LOW | Patched | 3.8 | 2024-09-11 | A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the comp… |
| CVE-2024-42425 | LOW | Patched | 3.8 | 2024-09-10 | Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local … |
| CVE-2024-38304 | LOW | Patched | 3.8 | 2024-08-29 | Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with … |
| CVE-2024-5445 | LOW | 3.8 | 2024-08-12 | Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to per… | |
| CVE-2024-41960 | LOW | Patched | 3.8 | 2024-08-05 | mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration.… |
| CVE-2024-39837 | LOW | Patched | 3.8 | 2024-08-01 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared chan… |
| CVE-2024-5470 | LOW | Patched | 3.8 | 2024-07-11 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` p… |
| CVE-2024-37442 | LOW | Patched | 3.8 | 2024-07-09 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Inje… |
| CVE-2024-39324 | LOW | Patched | 3.8 | 2024-07-02 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access … |
| CVE-2024-37137 | LOW | Patched | 3.8 | 2024-06-28 | Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentiall… |
| CVE-2024-39156 | LOW | 3.8 | 2024-06-27 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add. | |
| CVE-2024-39157 | LOW | 3.8 | 2024-06-27 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1. | |
| CVE-2024-32855 | LOW | Patched | 3.8 | 2024-06-25 | Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker with local access could potentially… |
| CVE-2024-37885 | LOW | Patched | 3.8 | 2024-06-14 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load… |
| CVE-2024-36287 | LOW | Patched | 3.8 | 2024-06-14 | Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS. |
| CVE-2023-38420 | LOW | 3.8 | 2024-05-16 | Improper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable information disclosure via local access. | |
| CVE-2024-35039 | LOW | 3.8 | 2024-05-16 | idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area. | |
| CVE-2023-5937 | LOW | 3.8 | 2024-05-15 | On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive … | |
| CVE-2024-34218 | LOW | 3.8 | 2024-05-14 | TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. | |
| CVE-2024-34203 | LOW | 3.8 | 2024-05-14 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function. | |
| CVE-2024-3628 | LOW | 3.8 | 2024-05-07 | The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site S… |