Search
15,629 CVEs · Low severity
CVEs (15,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 15,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-19245 | LOW | 3.3 | 2026-08-07 | A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component… | |
| CVE-2026-71849 | LOW | Patched | 3.7 | 2026-08-07 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove… |
| CVE-2026-19230 | LOW | 3.5 | 2026-08-07 | A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comm… | |
| CVE-2026-17435 | LOW | Patched | 2.5 | 2026-08-07 | File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing… |
| CVE-2026-19209 | LOW | 3.5 | 2026-08-07 | A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file /social/index.php?page=home. This manipulation of t… | |
| CVE-2026-19208 | LOW | 3.7 | 2026-08-07 | A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src/TraderDD/TraderDD.cpp. The manipulation of the argu… | |
| CVE-2026-19207 | LOW | 2.4 | 2026-08-07 | A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.p… | |
| CVE-2026-61477 | LOW | 2.3 | 2026-08-07 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and … | |
| CVE-2026-49005 | LOW | 2.4 | 2026-08-07 | The root password hash of the device can be obtained through unencrypted information in the firmware. | |
| CVE-2026-64652 | LOW | Patched | 3.3 | 2026-08-06 | GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained… |
| CVE-2026-48082 | LOW | 3.7 | 2026-08-06 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/ap… | |
| CVE-2026-48074 | LOW | 2.7 | 2026-08-06 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing … | |
| CVE-2026-19167 | LOW | Patched | 3.1 | 2026-08-06 | Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted … |
| CVE-2026-19161 | LOW | Patched | 3.1 | 2026-08-06 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafte… |
| CVE-2026-19160 | LOW | Patched | 3.1 | 2026-08-06 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafte… |
| CVE-2026-19110 | LOW | 2.4 | 2026-08-06 | A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlRenderer of the file HtmlTplDashboardWidgetHtmlRender… | |
| CVE-2026-19061 | LOW | 3.7 | 2026-08-06 | A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Han… | |
| CVE-2026-19059 | LOW | 3.3 | 2026-08-06 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes pa… | |
| CVE-2026-14225 | LOW | Patched | 2.7 | 2026-08-06 | The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the … |
| CVE-2025-15674 | LOW | Patched | 2.7 | 2026-08-06 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through … |
| CVE-2026-19046 | LOW | 3.3 | 2026-08-06 | A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesS… | |
| CVE-2026-15599 | LOW | Patched | 3.3 | 2026-08-06 | Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain… |
| CVE-2025-14779 | LOW | Patched | 3.8 | 2026-08-06 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce or… |
| CVE-2025-13736 | LOW | Patched | 3.7 | 2026-08-06 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays thei… |
| CVE-2025-12627 | LOW | Patched | 2.4 | 2026-08-06 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained … |