Search
15,629 CVEs · Low severity
CVEs (15,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 15,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-48412 | LOW | 2.7 | 2026-08-11 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulner… | |
| CVE-2026-73071 | LOW | Patched | 3.3 | 2026-08-11 | Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invoke… |
| CVE-2026-11985 | LOW | 3.6 | 2026-08-11 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI p… | |
| CVE-2026-66774 | LOW | 3.7 | 2026-08-11 | SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploi… | |
| CVE-2026-58245 | LOW | 3.8 | 2026-08-11 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to acce… | |
| CVE-2026-58239 | LOW | 3.7 | 2026-08-11 | SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant conte… | |
| CVE-2026-44762 | LOW | 3.7 | 2026-08-11 | SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an… | |
| CVE-2026-11812 | LOW | 2.5 | 2026-08-10 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block con… | |
| CVE-2026-11811 | LOW | 3.7 | 2026-08-10 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure pa… | |
| CVE-2026-19411 | LOW | 3.9 | 2026-08-10 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack … | |
| CVE-2026-11809 | LOW | 3.7 | 2026-08-10 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the… | |
| CVE-2026-21062 | LOW | 3.3 | 2026-08-10 | Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. | |
| CVE-2026-17016 | LOW | 3.7 | 2026-08-10 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPa… | |
| CVE-2026-14211 | LOW | Patched | 3.8 | 2026-08-10 | The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose rec… |
| CVE-2026-12971 | LOW | Patched | 2.2 | 2026-08-10 | The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the serv… |
| CVE-2026-19382 | LOW | 2.3 | 2026-08-10 | A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a… | |
| CVE-2026-19380 | LOW | 2.3 | 2026-08-10 | A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to… | |
| CVE-2026-12372 | LOW | 3.7 | 2026-08-09 | A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, in… | |
| CVE-2026-19368 | LOW | 3.3 | 2026-08-09 | A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component ge… | |
| CVE-2026-19361 | LOW | 3.7 | 2026-08-09 | A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a mani… | |
| CVE-2026-19352 | LOW | 3.1 | 2026-08-09 | A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component B… | |
| CVE-2026-17011 | LOW | Patched | 3.8 | 2026-08-09 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor r… |
| CVE-2026-16957 | LOW | Patched | 2.7 | 2026-08-09 | The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users … |
| CVE-2026-19324 | LOW | 3.3 | 2026-08-09 | A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the… | |
| CVE-2026-11742 | LOW | 3.6 | 2026-08-07 | The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading the node's flag byte and, for items enqueued via… |