Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 15,095 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49381 | LOW | Patched | 3.4 | 2026-05-29 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
| CVE-2026-49380 | LOW | Patched | 3.1 | 2026-05-29 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
| CVE-2026-49370 | LOW | Patched | 3.4 | 2026-05-29 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests |
| CVE-2026-49358 | LOW | 3.0 | 2026-06-19 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `remo… | |
| CVE-2026-49356 | LOW | Patched | 3.2 | 2026-06-22 | Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. U… |
| CVE-2026-49318 | LOW | 2.4 | 2026-05-29 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to byp… | |
| CVE-2026-49317 | LOW | 2.4 | 2026-05-29 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to byp… | |
| CVE-2026-4916 | LOW | Patched | 2.7 | 2026-04-08 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authe… |
| CVE-2026-4909 | LOW | 2.4 | 2026-03-27 | A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s7.php. This manipulation of the argume… | |
| CVE-2026-49009 | LOW | Patched | 3.1 | 2026-05-27 | Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. |
| CVE-2026-4899 | LOW | 2.4 | 2026-03-26 | A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The… | |
| CVE-2026-48940 | LOW | Patched | 3.4 | 2026-06-25 | A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim… |
| CVE-2026-48936 | LOW | 3.3 | 2026-06-26 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects… | |
| CVE-2026-48935 | LOW | 3.3 | 2026-06-26 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affect… | |
| CVE-2026-48931 | LOW | 3.7 | 2026-06-22 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all support… | |
| CVE-2026-48852 | LOW | Patched | 3.7 | 2026-05-25 | PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification. |
| CVE-2026-48851 | LOW | Patched | 3.1 | 2026-05-25 | PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session. |
| CVE-2026-48850 | LOW | Patched | 3.7 | 2026-05-25 | PuTTY 0.72 before 0.84 has a double free in RSA KEX. |
| CVE-2026-48847 | LOW | Patched | 3.7 | 2026-05-25 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. |
| CVE-2026-48832 | LOW | Patched | 3.5 | 2026-05-24 | action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability. |
| CVE-2026-4874 | LOW | 3.1 | 2026-03-26 | A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh to… | |
| CVE-2026-48709 | LOW | Patched | 3.7 | 2026-06-15 | OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.g… |
| CVE-2026-48617 | LOW | 1.8 | 2026-06-18 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the… | |
| CVE-2026-48588 | LOW | Patched | 3.1 | 2026-07-07 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when… |
| CVE-2026-48587 | LOW | Patched | 3.1 | 2026-06-03 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace fro… |