Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,629 CVEs · Low severity

EOL hidden · Show all products

CVEs (15,629, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 15,629 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-49262 LOW 3.0 2026-08-12 In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) a…
CVE-2026-70467 LOW 3.8 2026-08-12 A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, Fo…
CVE-2026-18044 LOW Patched 3.7 2026-08-12 The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property reques…
CVE-2026-64951 LOW 3.5 2026-08-12 A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The pro…
CVE-2026-73283 LOW Patched 2.5 2026-08-11 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
CVE-2026-73281 LOW Patched 3.5 2026-08-11 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is c…
CVE-2026-48412 LOW 2.7 2026-08-11 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulner…
CVE-2026-73071 LOW Patched 3.3 2026-08-11 Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invoke…
CVE-2026-11985 LOW 3.6 2026-08-11 On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI p…
CVE-2026-66774 LOW 3.7 2026-08-11 SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploi…
CVE-2026-58245 LOW 3.8 2026-08-11 SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to acce…
CVE-2026-58239 LOW 3.7 2026-08-11 SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant conte…
CVE-2026-44762 LOW 3.7 2026-08-11 SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an…
CVE-2026-11812 LOW 2.5 2026-08-10 The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block con…
CVE-2026-11811 LOW 3.7 2026-08-10 The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure pa…
CVE-2026-19411 LOW 3.9 2026-08-10 A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack …
CVE-2026-11809 LOW 3.7 2026-08-10 The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the…
CVE-2026-21062 LOW 3.3 2026-08-10 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
CVE-2026-17016 LOW 3.7 2026-08-10 The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPa…
CVE-2026-14211 LOW Patched 3.8 2026-08-10 The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose rec…
CVE-2026-12971 LOW Patched 2.2 2026-08-10 The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the serv…
CVE-2026-19382 LOW 2.3 2026-08-10 A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a…
CVE-2026-19380 LOW 2.3 2026-08-10 A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to…
CVE-2026-12372 LOW 3.7 2026-08-09 A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, in…
CVE-2026-19368 LOW 3.3 2026-08-09 A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component ge…