Search
2,585 CVEs · Low severity
CVEs (2,585, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 2,585 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-0057 | LOW | 3.3 | 2026-06-17 | In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local … | |
| CVE-2025-62340 | LOW | 3.1 | 2026-06-17 | HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate u… | |
| CVE-2026-46977 | LOW | 3.2 | 2026-06-17 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable… | |
| CVE-2026-46874 | LOW | 3.2 | 2026-06-17 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerab… | |
| CVE-2026-46816 | LOW | 3.2 | 2026-06-17 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable… | |
| CVE-2026-46815 | LOW | 3.2 | 2026-06-17 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable… | |
| CVE-2026-0158 | LOW | 3.3 | 2026-06-16 | In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execu… | |
| CVE-2026-0145 | LOW | 3.3 | 2026-06-16 | In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges … | |
| CVE-2026-0142 | LOW | 3.3 | 2026-06-16 | In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additi… | |
| CVE-2026-0134 | LOW | 3.3 | 2026-06-16 | In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information … | |
| CVE-2026-0130 | LOW | 3.5 | 2026-06-16 | In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional exe… | |
| CVE-2026-0129 | LOW | 3.5 | 2026-06-16 | In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privile… | |
| CVE-2026-10636 | LOW | Patched | 3.7 | 2026-06-16 | In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the packet via net_pkt_iface(pkt) after the packet had been… |
| CVE-2026-48709 | LOW | Patched | 3.7 | 2026-06-15 | OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.g… |
| CVE-2026-12211 | LOW | 2.7 | 2026-06-15 | A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web… | |
| CVE-2026-12202 | LOW | 2.4 | 2026-06-15 | A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulat… | |
| CVE-2026-9062 | LOW | Patched | 3.4 | 2026-06-13 | The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read … |
| CVE-2026-9061 | LOW | Patched | 3.5 | 2026-06-13 | The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin b… |
| CVE-2026-53837 | LOW | Patched | 3.7 | 2026-06-12 | OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass i… |
| CVE-2026-53607 | LOW | 3.7 | 2026-06-12 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a do… | |
| CVE-2026-12130 | LOW | 3.5 | 2026-06-12 | A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Proj… | |
| CVE-2026-12129 | LOW | 3.5 | 2026-06-12 | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the… | |
| CVE-2026-12065 | LOW | 1.8 | 2026-06-12 | A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manip… | |
| CVE-2026-9269 | LOW | Patched | 3.5 | 2026-06-12 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege use… |
| CVE-2026-12032 | LOW | Patched | 3.1 | 2026-06-11 | Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass s… |