Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

858 CVEs · Low severity

CVEs (858, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 858 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-0057 LOW 3.3 2026-06-17 In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local …
CVE-2025-62340 LOW 3.1 2026-06-17 HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate u…
CVE-2026-46977 LOW 3.2 2026-06-17 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable…
CVE-2026-46874 LOW 3.2 2026-06-17 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerab…
CVE-2026-46816 LOW 3.2 2026-06-17 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable…
CVE-2026-46815 LOW 3.2 2026-06-17 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable…
CVE-2026-0158 LOW 3.3 2026-06-16 In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execu…
CVE-2026-0145 LOW 3.3 2026-06-16 In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges …
CVE-2026-0142 LOW 3.3 2026-06-16 In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additi…
CVE-2026-0134 LOW 3.3 2026-06-16 In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information …
CVE-2026-0130 LOW 3.5 2026-06-16 In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional exe…
CVE-2026-0129 LOW 3.5 2026-06-16 In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privile…
CVE-2026-10636 LOW Patched 3.7 2026-06-16 In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the packet via net_pkt_iface(pkt) after the packet had been…
CVE-2026-48709 LOW Patched 3.7 2026-06-15 OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.g…
CVE-2026-12211 LOW 2.7 2026-06-15 A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web…
CVE-2026-12202 LOW 2.4 2026-06-15 A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulat…
CVE-2026-9062 LOW Patched 3.4 2026-06-13 The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read …
CVE-2026-9061 LOW Patched 3.5 2026-06-13 The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin b…
CVE-2026-53837 LOW Patched 3.7 2026-06-12 OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass i…
CVE-2026-53607 LOW 3.7 2026-06-12 ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a do…
CVE-2026-12130 LOW 3.5 2026-06-12 A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Proj…
CVE-2026-12129 LOW 3.5 2026-06-12 A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the…
CVE-2026-12065 LOW 1.8 2026-06-12 A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manip…
CVE-2026-9269 LOW Patched 3.5 2026-06-12 The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege use…
CVE-2026-12032 LOW Patched 3.1 2026-06-11 Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass s…