Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,095 CVEs · Low severity

CVEs (15,095, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 15,095 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-53540 LOW Patched 3.7 2026-06-22 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked r…
CVE-2026-49356 LOW Patched 3.2 2026-06-22 Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. U…
CVE-2026-9610 LOW 2.3 2026-06-22 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by di…
CVE-2026-8823 LOW Patched 3.8 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrad&hellip;
CVE-2026-8074 LOW Patched 3.8 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager wit&hellip;
CVE-2026-12823 LOW 3.3 2026-06-22 A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulat&hellip;
CVE-2026-12812 LOW 3.5 2026-06-21 A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of the component HTML Report Generation. The manipulation&hellip;
CVE-2026-56367 LOW Patched 3.7 2026-06-21 ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a &hellip;
CVE-2026-56378 LOW Patched 3.7 2026-06-21 ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte hea&hellip;
CVE-2026-56355 LOW 3.7 2026-06-20 GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
CVE-2026-56330 LOW Patched 3.5 2026-06-20 Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl &hellip;
CVE-2026-56325 LOW Patched 3.1 2026-06-20 Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to&hellip;
CVE-2026-56212 LOW Patched 3.8 2026-06-20 Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authent&hellip;
CVE-2026-49358 LOW 3.0 2026-06-19 PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `remo&hellip;
CVE-2026-9143 LOW Patched 3.7 2026-06-19 There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen.  This may silently discard high bits if a siz&hellip;
CVE-2026-12047 LOW Patched 3.5 2026-06-19 HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-leve&hellip;
CVE-2026-48617 LOW 1.8 2026-06-18 A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the&hellip;
CVE-2026-12102 LOW 2.7 2026-06-18 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference&hellip;
CVE-2026-50268 LOW 1.9 2026-06-17 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 thro&hellip;
CVE-2026-12566 LOW 3.1 2026-06-17 The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in &hellip;
CVE-2026-12567 LOW 2.2 2026-06-17 The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan direct&hellip;
CVE-2026-6733 LOW Patched 3.7 2026-06-17 Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HT&hellip;
CVE-2026-39199 LOW 2.9 2026-06-17 snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
CVE-2026-11525 LOW Patched 3.7 2026-06-17 Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive &hellip;
CVE-2026-35068 LOW Patched 3.5 2026-06-17 Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low&hellip;