Search
978 CVEs · Low severity
CVEs (978, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 978 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-49262 | LOW | 3.0 | 2026-08-12 | In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) a… | |
| CVE-2026-70467 | LOW | 3.8 | 2026-08-12 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, Fo… | |
| CVE-2026-18044 | LOW | Patched | 3.7 | 2026-08-12 | The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property reques… |
| CVE-2026-64951 | LOW | 3.5 | 2026-08-12 | A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The pro… | |
| CVE-2026-73283 | LOW | Patched | 2.5 | 2026-08-11 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. |
| CVE-2026-73281 | LOW | Patched | 3.5 | 2026-08-11 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is c… |
| CVE-2026-48412 | LOW | 2.7 | 2026-08-11 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulner… | |
| CVE-2026-73071 | LOW | Patched | 3.3 | 2026-08-11 | Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invoke… |
| CVE-2026-11985 | LOW | 3.6 | 2026-08-11 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to CONFIG_FP_HARDABI. Both FP_HARDABI and FP_SOFTABI p… | |
| CVE-2026-66774 | LOW | 3.7 | 2026-08-11 | SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploi… | |
| CVE-2026-58245 | LOW | 3.8 | 2026-08-11 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to acce… | |
| CVE-2026-58239 | LOW | 3.7 | 2026-08-11 | SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant conte… | |
| CVE-2026-44762 | LOW | 3.7 | 2026-08-11 | SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an… | |
| CVE-2026-11812 | LOW | 2.5 | 2026-08-10 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block con… | |
| CVE-2026-11811 | LOW | 3.7 | 2026-08-10 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure pa… | |
| CVE-2026-19411 | LOW | 3.9 | 2026-08-10 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack … | |
| CVE-2026-11809 | LOW | 3.7 | 2026-08-10 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the… | |
| CVE-2026-21062 | LOW | 3.3 | 2026-08-10 | Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. | |
| CVE-2026-17016 | LOW | 3.7 | 2026-08-10 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPa… | |
| CVE-2026-14211 | LOW | Patched | 3.8 | 2026-08-10 | The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose rec… |
| CVE-2026-12971 | LOW | Patched | 2.2 | 2026-08-10 | The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the serv… |
| CVE-2026-19382 | LOW | 2.3 | 2026-08-10 | A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a… | |
| CVE-2026-19380 | LOW | 2.3 | 2026-08-10 | A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to… | |
| CVE-2026-12372 | LOW | 3.7 | 2026-08-09 | A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, in… | |
| CVE-2026-19368 | LOW | 3.3 | 2026-08-09 | A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component ge… |