Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 15,095 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53540 | LOW | Patched | 3.7 | 2026-06-22 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked r… |
| CVE-2026-49356 | LOW | Patched | 3.2 | 2026-06-22 | Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. U… |
| CVE-2026-9610 | LOW | 2.3 | 2026-06-22 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by di… | |
| CVE-2026-8823 | LOW | Patched | 3.8 | 2026-06-22 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrad… |
| CVE-2026-8074 | LOW | Patched | 3.8 | 2026-06-22 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager wit… |
| CVE-2026-12823 | LOW | 3.3 | 2026-06-22 | A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulat… | |
| CVE-2026-12812 | LOW | 3.5 | 2026-06-21 | A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of the component HTML Report Generation. The manipulation… | |
| CVE-2026-56367 | LOW | Patched | 3.7 | 2026-06-21 | ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a … |
| CVE-2026-56378 | LOW | Patched | 3.7 | 2026-06-21 | ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte hea… |
| CVE-2026-56355 | LOW | 3.7 | 2026-06-20 | GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization. | |
| CVE-2026-56330 | LOW | Patched | 3.5 | 2026-06-20 | Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl … |
| CVE-2026-56325 | LOW | Patched | 3.1 | 2026-06-20 | Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to… |
| CVE-2026-56212 | LOW | Patched | 3.8 | 2026-06-20 | Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authent… |
| CVE-2026-49358 | LOW | 3.0 | 2026-06-19 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `remo… | |
| CVE-2026-9143 | LOW | Patched | 3.7 | 2026-06-19 | There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen. This may silently discard high bits if a siz… |
| CVE-2026-12047 | LOW | Patched | 3.5 | 2026-06-19 | HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-leve… |
| CVE-2026-48617 | LOW | 1.8 | 2026-06-18 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the… | |
| CVE-2026-12102 | LOW | 2.7 | 2026-06-18 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference… | |
| CVE-2026-50268 | LOW | 1.9 | 2026-06-17 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 thro… | |
| CVE-2026-12566 | LOW | 3.1 | 2026-06-17 | The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in … | |
| CVE-2026-12567 | LOW | 2.2 | 2026-06-17 | The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan direct… | |
| CVE-2026-6733 | LOW | Patched | 3.7 | 2026-06-17 | Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HT… |
| CVE-2026-39199 | LOW | 2.9 | 2026-06-17 | snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file. | |
| CVE-2026-11525 | LOW | Patched | 3.7 | 2026-06-17 | Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive … |
| CVE-2026-35068 | LOW | Patched | 3.5 | 2026-06-17 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low… |